Document Purpose
Scope: this diagnostic standard specifies requirement, covering 1 Scope; 1.1 Summary; 2 Abbrevations; 3 subFunctions; 3.1 verifyCertificateBidirectional; 3.1.1 Request.
CVS31.pdf · Diagnostic Standard · Key / Certificate Handling
CVS31.pdf · Diagnostic Standard · Key / Certificate Handling
Systems-engineering read of what this document defines for the system - scope, boundaries, interfaces, obligations, and what is still open.
Scope: this diagnostic standard specifies requirement, covering 1 Scope; 1.1 Summary; 2 Abbrevations; 3 subFunctions; 3.1 verifyCertificateBidirectional; 3.1.1 Request.
System boundary and interfaces: the document constrains 1 interface(s) - OEM/Customer Review Interface; principal functions in scope are Secure communication and freshness protection; Security evidence and traceability.
Design and security impact: affects Secure communication and freshness protection; Security evidence and traceability; security capabilities touched: Authentication; Certificate handling; Key management; 18 supplier system requirement(s) were derived from this document.
Open for the customer: 5 document-linked open point(s) - mainly Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. (sample: 3 of 5) - plus 12 unidentified requirement-like statement(s). Do not baseline these until the customer confirms.
Confidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.
| Theme | Engineering Meaning | Requirement Count | Representative Requirements |
|---|---|---|---|
| Requirement | Groups related document requirements into a single engineering theme. | 163 | RFQX-CVS31-0006; RFQX-CVS31-0012; RFQX-CVS31-0014 |
| System architecture design | Groups related document requirements into a single engineering theme. | 148 | RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004 |
| System | Groups related document requirements into a single engineering theme. | 138 | RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004 |
| Cybersecurity concept and evidence | Drives cybersecurity concept, risk treatment, verification evidence, and traceability obligations. | 106 | RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006 |
| Responsibility and customer approval model | Creates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk. | 85 | RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006 |
| Information | Groups related document requirements into a single engineering theme. | 77 | RFQX-CVS31-0011; RFQX-CVS31-0013; RFQX-CVS31-0018 |
| Key, certificate, and PKI handling | Affects ECU trust material storage, provisioning, lifecycle ownership, and customer PKI dependencies. | 72 | RFQX-CVS31-0006; RFQX-CVS31-0016; RFQX-CVS31-0017 |
| Cybersecurity | Groups related document requirements into a single engineering theme. | 41 | RFQX-CVS31-0006; RFQX-CVS31-0017; RFQX-CVS31-0021 |
| Section | Requirements | Information | Unknown / Review Needed | Total Items | Critical | Open Points | SSR Links |
|---|---|---|---|---|---|---|---|
| 1 Scope | 1 | 0 | 0 | 2 | 1 | 1 | 1 |
| -- 1.1 Summary | 1 | 0 | 0 | 2 | 1 | 1 | 1 |
| 2 Abbrevations | 0 | 0 | 0 | 3 | 3 | 1 | 0 |
| 3 subFunctions | 41 | 17 | 0 | 60 | 29 | 4 | 14 |
| -- 3.1 verifyCertificateBidirectional | 13 | 3 | 0 | 16 | 8 | 2 | 7 |
| -- -- 3.1.1 Request | 4 | 2 | 0 | 6 | 3 | 2 | 3 |
| -- -- 3.1.2 Response | 9 | 1 | 0 | 10 | 5 | 1 | 6 |
| -- 3.2 proofOfOwnership | 21 | 10 | 0 | 32 | 17 | 4 | 9 |
| -- -- 3.2.1 Request | 8 | 1 | 0 | 9 | 7 | 1 | 6 |
| -- -- 3.2.2 Response | 2 | 3 | 0 | 6 | 1 | 1 | 1 |
| -- -- 3.2.3 Negative Response | 7 | 2 | 0 | 9 | 6 | 1 | 4 |
| -- 3.3 deAuthenticate | 5 | 2 | 0 | 7 | 2 | 1 | 4 |
| -- -- 3.3.3 Negative Response | 5 | 2 | 0 | 7 | 2 | 1 | 4 |
| 4 General | 62 | 27 | 0 | 91 | 26 | 2 | 12 |
| -- 4.1 Certificate | 24 | 11 | 0 | 37 | 12 | 1 | 7 |
| -- -- 4.1.3 D-RBACC extension | 7 | 6 | 0 | 13 | 2 | 1 | 3 |
| -- -- 4.1.8 Certificate Validity Time | 9 | 2 | 0 | 13 | 5 | 1 | 4 |
| -- 4.2 State-keeping | 23 | 4 | 0 | 27 | 7 | 1 | 2 |
| -- 4.5 CRNG | 4 | 4 | 0 | 8 | 1 | 0 | 3 |
| -- 4.7 PassiveDeAuthentication | 6 | 5 | 0 | 11 | 3 | 1 | 3 |
| -- -- 4.7.1 TimeBasedPassiveDeAuthentication | 6 | 5 | 0 | 11 | 3 | 1 | 3 |
| -- 4.9 Authentication completion timer | 5 | 3 | 0 | 8 | 3 | 1 | 3 |
| 6 Normative references | 59 | 33 | 0 | 93 | 0 | 0 | 0 |
Tables are reconstructed column-correct from the document text layer (no OCR). Diagrams are linked from converted image assets.
| Abbreviation | Description | ||
|---|---|---|---|
| ECU | Electronic Control Unit | ||
| ID, id, Id | Identifier | ||
| N/A, NA, N.A | Not Applicable | ||
| MAC | Message Authentication Code | ||
| PKI | Public key infrastructure | ||
| SDT | Secured Data Transmission | ||
| SID | Service Identifier | ||
| CRNG / | Cryptographically Random Number Generator |
| Abbreviation | Description | ||
|---|---|---|---|
| ECU | Electronic Control Unit | ||
| ID, id, Id | Identifier | ||
| N/A, NA, N.A | Not Applicable | ||
| MAC | Message Authentication Code | ||
| PKI | Public key infrastructure | ||
| SDT | Secured Data Transmission | ||
| SID | Service Identifier | ||
| CRNG / | Cryptographically Random Number Generator | ||
| CSPRNG / | Cryptographically Secure Pseudorandom Number Generator | ||
| CPRNG | Cryptographic Pseudorandom Number Generator | ||
| RBAC | Role based access control | ||
| RBACC | Role based access control configuration | ||
| D-RBACC | Diagnostics RBACC |
Diagnostic parameter or service behavior
| Abbreviation | Description | ||
|---|---|---|---|
| ECU | Electronic Control Unit | ||
| ID, id, Id | Identifier | ||
| N/A, NA, N.A | Not Applicable | ||
| MAC | Message Authentication Code | ||
| PKI | Public key infrastructure | ||
| SDT | Secured Data Transmission | ||
| SID | Service Identifier | ||
| CRNG / | Cryptographically Random Number Generator |
| Abbreviation | Description | ||
|---|---|---|---|
| ECU | Electronic Control Unit | ||
| ID, id, Id | Identifier | ||
| N/A, NA, N.A | Not Applicable | ||
| MAC | Message Authentication Code | ||
| PKI | Public key infrastructure | ||
| SDT | Secured Data Transmission | ||
| SID | Service Identifier | ||
| CRNG / | Cryptographically Random Number Generator | ||
| CSPRNG / | Cryptographically Secure Pseudorandom Number Generator | ||
| CPRNG | Cryptographic Pseudorandom Number Generator | ||
| RBAC | Role based access control | ||
| RBACC | Role based access control configuration | ||
| D-RBACC | Diagnostics RBACC |
Table source context
| Abbreviation | Description | ||
|---|---|---|---|
| ECU | Electronic Control Unit | ||
| ID, id, Id | Identifier | ||
| N/A, NA, N.A | Not Applicable | ||
| MAC | Message Authentication Code | ||
| PKI | Public key infrastructure | ||
| SDT | Secured Data Transmission | ||
| SID | Service Identifier | ||
| CRNG / | Cryptographically Random Number Generator |
| Abbreviation | Description | ||
|---|---|---|---|
| ECU | Electronic Control Unit | ||
| ID, id, Id | Identifier | ||
| N/A, NA, N.A | Not Applicable | ||
| MAC | Message Authentication Code | ||
| PKI | Public key infrastructure | ||
| SDT | Secured Data Transmission | ||
| SID | Service Identifier | ||
| CRNG / | Cryptographically Random Number Generator | ||
| CSPRNG / | Cryptographically Secure Pseudorandom Number Generator | ||
| CPRNG | Cryptographic Pseudorandom Number Generator | ||
| RBAC | Role based access control | ||
| RBACC | Role based access control configuration | ||
| D-RBACC | Diagnostics RBACC |
Security protocol or cryptographic context
| Name |
|---|
| verifyCertificateBidirectional |
| proofOfOwnership |
| deAuthenticate |
Security protocol or cryptographic context
Wide table - scrolls horizontally inside this card.
| Field | Description | Type/Value | Cvt | Included in proofOfOwnershipServer |
|---|---|---|---|---|
| Authentication Request SID | Service ID for Authentication service Initiate request Authentication by | 0x29 | M | Yes |
| SubFunction = | verifying the | |||
| [AuthenticationTask = | Certificate and | 0x02 | M | Yes |
| verifyCertificateBidirectional] | generating a Proof of Ownership from the server | |||
| communicationConfiguration | NOT USED | 0x00 | M | Yes |
| lengthOfCertificateClient | Length parameter for certificateClient | uint16 | M | Yes |
| certificateClient | The Certificate to verify | uint8[] | M | Yes |
| lengthOfChallengeClient | Length parameter for challengeClient | uint16 | M | Yes |
| Field | Description | Type/Value | Cvt | Included in proofOfOwnershipServer |
|---|---|---|---|---|
| Authentication Request SID | Service ID for Authentication service Initiate request Authentication by | 0x29 | M | Yes |
| SubFunction = | verifying the | |||
| [AuthenticationTask = | Certificate and | 0x02 | M | Yes |
| verifyCertificateBidirectional] | generating a Proof of Ownership from the server | |||
| communicationConfiguration | NOT USED | 0x00 | M | Yes |
| lengthOfCertificateClient | Length parameter for certificateClient | uint16 | M | Yes |
| certificateClient | The Certificate to verify | uint8[] | M | Yes |
| lengthOfChallengeClient | Length parameter for challengeClient | uint16 | M | Yes |
| challengeClient | See 3.1.1.1 | uint8[] | M | Yes |
Security protocol or cryptographic context
Wide table - scrolls horizontally inside this card.
| Field | Description | Type/ Value | Cvt | Included in proofOfOwnershipServer |
|---|---|---|---|---|
| Authentication Response SID | Service ID for Authentication service Initiate request Authentication | 0x69 | M | Yes |
| SubFunction = | by verifying the | |||
| [AuthenticationTask = | Certificate and | 0x02 | M | Yes |
| verifyCertificateBidirectional] | generating a Proof of Ownership from the server This parameter returns | |||
| authenticationReturnParameter | the result of the procedure on the server. | uint8 | M | Yes |
| lengthOfChallengeServer | Length parameter for the following challenge | uint16 | M | Yes |
| challengeServer | See 3.1.2.1 | uint8[] | M | Yes |
| lengthOfCertificateServer | Length parameter for the following | uint16 | M | Yes |
| Field | Description | Type/ Value | Cvt | Included in proofOfOwnershipServer |
|---|---|---|---|---|
| Authentication Response SID | Service ID for Authentication service Initiate request Authentication | 0x69 | M | Yes |
| SubFunction = | by verifying the | |||
| [AuthenticationTask = | Certificate and | 0x02 | M | Yes |
| verifyCertificateBidirectional] | generating a Proof of Ownership from the server This parameter returns | |||
| authenticationReturnParameter | the result of the procedure on the server. | uint8 | M | Yes |
| lengthOfChallengeServer | Length parameter for the following challenge | uint16 | M | Yes |
| challengeServer | See 3.1.2.1 | uint8[] | M | Yes |
| lengthOfCertificateServer | Length parameter for the following | uint16 | M | Yes |
| certificateServer | The Certificate Certificate to verify | uint8[] | M | Yes |
| lengthOfProofOfOwnershipSer | Length parameter for | |||
| ver | the following Proof of Ownership | uint16 | M | Yes |
| proofOfOwnershipServer | See 3.1.2.2 | uint8[] | M | No |
| lengthOfEphemeralPublicKeyS | Length parameter for | |||
| erver | ephemeralPublicKeyS erver. | uint16 | M | Yes |
| ephemeralPublicKeyServer | See 3.1.2.3 | uint8[] | M | Yes |
Security protocol or cryptographic context
Wide table - scrolls horizontally inside this card.
| Field | Description | Type/Value | Cvt | Included in proofOfOwnershipClient |
|---|---|---|---|---|
| Authentication Request SID | Service ID for Authentication service | 0x29 | M | Yes |
| SubFunction = | Verify request the Proof of | |||
| [AuthenticationTask = | Ownership from the | 0x03 | M | Yes |
| proofOfOwnership] | client This field indicates the | |||
| lengthOfProofOfOwnershipClient | length (in octets) of the proofOfOwnershipClient field | uint16 | M | Yes |
| proofOfOwnershipClient | See 3.2.1.1 | uint8[] | M | No |
| lengthOfEphemeralPublicKey | Length parameter for | |||
| Client | ephemeralPublicKey Client | uint16 | M | Yes |
| Field | Description | Type/Value | Cvt | Included in proofOfOwnershipClient |
|---|---|---|---|---|
| Authentication Request SID | Service ID for Authentication service | 0x29 | M | Yes |
| SubFunction = | Verify request the Proof of | |||
| [AuthenticationTask = | Ownership from the | 0x03 | M | Yes |
| proofOfOwnership] | client This field indicates the | |||
| lengthOfProofOfOwnershipClient | length (in octets) of the proofOfOwnershipClient field | uint16 | M | Yes |
| proofOfOwnershipClient | See 3.2.1.1 | uint8[] | M | No |
| lengthOfEphemeralPublicKey | Length parameter for | |||
| Client | ephemeralPublicKey Client | uint16 | M | Yes |
| ephemeralPublicKeyClient | See 3.2.1.2 | uint16 | M | Yes |
Security protocol or cryptographic context
Wide table - scrolls horizontally inside this card.
| Field | Description | Type/Value | Cvt | Included in sessionKeyInfo |
|---|---|---|---|---|
| Authentication Response SID | Service ID for Authentication service | 0x69 | M | Yes |
| SubFunction = | Verify request the Proof of | |||
| [AuthenticationTask = | Ownership from the | 0x03 | M | Yes |
| proofOfOwnership] | client. This parameter returns | |||
| authenticationReturnParameter | the result of the procedure on the server. | uint8 | M | Yes |
| lengthOfSessionKeyInfo | Specifies the length of the field (in octets) | uint16 | M | Yes |
| sessionKeyInfo | See 3.2.2.1.1 | uint8[] | M | No |
Diagnostic parameter or service behavior
| Field | Description | Type/Value | Cvt |
|---|---|---|---|
| Authentication Request SID | Service ID for Authentication service | 0x29 | M |
| SubFunction = [AuthenticationTask = | Subfunction request for request | 0x00 | M |
| deAuthenticate] | to leave the |
State-machine or transition behavior
| Field | Description | Type/Value | Cvt |
|---|---|---|---|
| Authentication Response SID | Service ID for Authentication service | 0x69 | M |
| SubFunction = | Subfunction response for request | ||
| [AuthenticationTask = | to leave the | 0x00 | M |
| deAuthenticate] | authenticated state | ||
| returnValue [] = | This parameter returns | 0x00 – | |
| [authenticationReturnParameter] | the result of the procedure on the server. | 0xFF | M |
State-machine or transition behavior
| Document designation | Title |
|---|---|
| CVS30 | X.509 |
| CVS32 | 0x84 SecuredDataTranmission |
| CVS33 | Entity Management Protocol |
| CVS34 | EMP – Basic Entity Definitions Specification |
| CVS124 | Traton Specification on Unified diagnostic Services (UDS) requirements |
| CVS150 | Requirements on using cryptographic algorithms in the vehicle |
| CVS151 | RBAC v2 for diagnostic |
| ISO 14229-1:2020 | Road vehicles – Unified diagnostic services (UDS) –Part 1: Application layer |
| Document designation | Title |
|---|---|
| CVS30 | X.509 |
| CVS32 | 0x84 SecuredDataTranmission |
| CVS33 | Entity Management Protocol |
| CVS34 | EMP – Basic Entity Definitions Specification |
| CVS124 | Traton Specification on Unified diagnostic Services (UDS) requirements |
| CVS150 | Requirements on using cryptographic algorithms in the vehicle |
| CVS151 | RBAC v2 for diagnostic |
| ISO 14229-1:2020 | Road vehicles – Unified diagnostic services (UDS) –Part 1: Application layer |
| RFC 5280 | Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile https://datatracker.ietf.org/doc/html/rfc5280 |
| RFC 7748 | Elliptic Curves for Security |
Diagnostic parameter or service behavior
Diagnostic parameter or service behavior
Security protocol or cryptographic context
Security protocol or cryptographic context
Diagnostic parameter or service behavior
Diagnostic parameter or service behavior
Security protocol or cryptographic context
State-machine or transition behavior
| Field | Value |
|---|---|
| Source PDF | CVS31.pdf |
| Document Type | Diagnostic Standard |
| Domain | Key / Certificate Handling |
| Scope Summary | 163 confirmed requirements, 12 needing clarification, 77 information, 2 reference items; 18 linked SSRs; 5 linked open points. |
| Main Themes | Requirement; System architecture design; System; Cybersecurity concept and evidence; Responsibility and customer approval model (sample: 5 of 8) |
| Does Not Confirm | Customer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed. |
| Confidence | High |
| Evidence Basis | Markdown-derived requirements and generated RFQX registers; no downstream PDF analysis. |
This table is horizontally scrollable. Use the bottom scrollbar to view all columns.
| ID | Score | Category | Requirement / Reason | Supplier Position |
|---|---|---|---|---|
| RFQX-CVS31-0049 | 95 | High risk due to unclear OEM/supplier responsibility | If an active authentication state already exists, the server shall replace the existing state with the newly established one.security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivation | Needs Customer Clarification |
| RFQX-CVS31-0096 | 95 | High risk due to unclear OEM/supplier responsibility | If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivation | Needs Customer Clarification |
| RFQX-CVS31-0099 | 95 | High risk due to unclear OEM/supplier responsibility | If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivation | Needs Customer Clarification |
| RFQX-CVS31-0008 | 81 | High risk due to unclear OEM/supplier responsibility | Shall be agreed between the supplier and the vehicle manufacturer.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | Needs Customer Clarification |
| RFQX-CVS31-0009 | 81 | High risk due to unclear OEM/supplier responsibility | It contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | Needs Customer Clarification |
| RFQX-CVS31-0010 | 81 | High risk due to unclear OEM/supplier responsibility | It contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | Needs Customer Clarification |
| RFQX-CVS31-0015 | 81 | High risk due to unclear OEM/supplier responsibility | If such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | Needs Customer Clarification |
| AUTH_REQ 155 | 77 | High risk due to unclear OEM/supplier responsibility | The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | Partially Accept |
| AUTH_REQ 117 | 77 | High risk due to unclear OEM/supplier responsibility | Table 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | Partially Accept |
| AUTH_REQ 118 | 77 | High risk due to unclear OEM/supplier responsibility | If upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | Partially Accept |
| AUTH_REQ 45 | 77 | High risk due to unclear OEM/supplier responsibility | If the server verifies the client certificate as valid, the server shall create the requested client authentication pending state.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | Partially Accept |
| AUTH_REQ 173 | 77 | High risk due to unclear OEM/supplier responsibility | The server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | Partially Accept |
Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.
Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.
Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.
Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.
Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.
This table is horizontally scrollable. Use the bottom scrollbar to view all columns.
| Open Point | Priority | Question / Impact | Required Customer Decision | Recommended Supplier Position | Owner | Status |
|---|---|---|---|---|---|---|
| OP-002 | Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service. | Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy. | Implement configurable session/security-access on the ECU and request the customer-confirmed service-to-role table. | Shared (OEM policy / Supplier ECU) | Open | |
| OP-003 | Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open. | Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. | Provide ECU-side secure storage and provisioning hooks; require OEM confirmation of PKI ownership and the provisioning interface. | OEM / Customer (PKI) + Supplier (ECU) | Open | |
| OP-004 | Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.Update-control scope and evidence ownership stay open; risk of an unprotected update path. | Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. | Implement authenticated, integrity-protected ECU programming with controlled boot/app state; require OEM update-chain definition. | Shared (OEM backend / Supplier ECU) | Open | |
| OP-009 | Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case. | Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed. | Deliver supplier-owned work products per concept; require a signed DIA/RASIC before treating shared items as supplier scope. | OEM / Customer + Supplier (DIA) | Open | |
| OP-011 | Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements. | Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context. | Carry the items as customer-confirmation dependencies and review them in the next clarification workshop. | OEM / Customer | Open |
Items carrying a customer requirement ID and a normative (shall/must) statement.
The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message. Details & reviewer feedbackSection Table 4 – Supported subFunctions (ISO 14229-1:2020) Name verifyCertificateBidirectional proofOfOwnership deAuthenticate Page page 7 Feature / Interface Secure communication and freshness protection / None Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Table 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running. Details & reviewer feedbackSection 3.1.1 Request Page page 8 Security capability Authentication Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request. Details & reviewer feedbackSection 3.1.1 Request Page page 8 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the server verifies the client certificate as valid, the server shall create the requested client authentication pending state. Details & reviewer feedbackSection 3.1.1 Request Page page 8 Security capability Authentication Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request. Details & reviewer feedbackSection 3.1.2 Response Page page 9 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
If the lengthOfCertificateClient value is not within the expected range, the server shall send negative response code 0x13 (incorrectMessageLengthOrInvalidFormat). Details & reviewer feedbackSection 3.1.2 Response Page page 9 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If upon reception of verifyCertificateBidirectional request the Authentication delay timer is running, the server shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x37, indicating requiredTimeDelayNotExpired. Details & reviewer feedbackSection 3.1.3 Negative Response Page page 11 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
If the server verifies the client certificate as invalid, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x10, indicating generalReject. Details & reviewer feedbackSection 3.2 proofOfOwnership Page page 11 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
If the server fails or cannot determine that the authentication pending state was stored, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. Details & reviewer feedbackSection 3.2 proofOfOwnership Page page 11 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
Table 7 – proofOfOwnership Request Field Description Type/Value Cvt Included in proofOfOwnershipClient Authentication Request SID Service ID for 0x29 M Yes proofOfOwnership] Verify the Proof of Ownership from the client 0x03 M Yes lengthOfProofOfOwnershipClient This field indicates the length (in octets) of the proofOfOwnershipClient field proofOfOwnershipClient See 3.2.1.1 uint8[] M No lengthOfEphemeralPublicKey Client Length parameter for ephemeralPublicKey Client ephemeralPublicKeyClient See 3.2.1.2 uint16 M Yes The server shall verify whether any existing authentication pending state corresponds to the client submitting the proofOfOwnership request. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Supplier proposal Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the server cannot determine if the client does have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. Details & reviewer feedbackSection 3.2.3 Negative Response Page page 14 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server cannot determine that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. Details & reviewer feedbackSection 3.2.3 Negative Response Page page 14 Feature / Interface Security evidence and traceability / OEM/Customer Review Interface Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If the server is deleting the authentication pending state as consequence of failure to store the authentication state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. Details & reviewer feedbackSection 3.2.3 Negative Response Page page 14 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
The server shall use the private key corresponding to the server certificate to generate the signatures. Details & reviewer feedbackSection 4.1 Certificate Page page 16 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The server shall reject a received client’s certificate, sent using the verifyCertificateBidirectional subFunction, if it matches the server’s own certificate. Details & reviewer feedbackSection 4.1 Certificate Page page 16 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The server shall verify the client certificate, sent using the verifyCertificateBidirectional subFunction, according to Figure 3. Details & reviewer feedbackSection 4.1 Certificate Page page 16 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The server shall verify the Signature of the Client certificate using the AUTH-CA EMP entity public key. Details & reviewer feedbackSection 4.1 Certificate Page page 16 Security capability Authentication Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
• If the server NodeUID is not found in the NodeUID extension, the server shall reject the certificate and generate NRC 0x10 (generalReject). Details & reviewer feedbackSection 4.1.3 D-RBACC extension Page page 18 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The server shall validate the certificate so that: 𝑛𝑜𝑡𝐵𝑒𝑓𝑜𝑟𝑒 ≤ 𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒-𝑡𝑖𝑚𝑒 ≤ 𝑛𝑜𝑡𝐴𝑓𝑡𝑒𝑟 Details & reviewer feedbackSection 4.1.8 Certificate Validity Time Page page 19 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication pending state. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. |
If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication state. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. |
The server shall always allow the Authentication 0x29 service (ISO 14229-1:2020) regardless of Details & reviewer feedbackSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 Supplier proposal Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. |
If the delay timer is not running, the server shall start it as part of verifyCertificateBidirectional request. Details & reviewer feedbackSection 4.9 Authentication completion timer Page page 24 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
If the server cannot determine that the client is currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x94, indicating a ResourceTemporarilyNotAvailable. Details & reviewer feedbackSection 3.3.3 Negative Response Page page 15 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If an authentication pending state already exists, the server shall replace the existing Details & reviewer feedbackSection 3.1.2 Response Page page 9 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Upon positively responding, the server shall start the Authentication completion timer. Details & reviewer feedbackSection 3.1.2 Response Page page 9 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The challengeServer field shall consists of 32 octets generated using a CRNG. Details & reviewer feedbackSection ephemeralPublicKeyServer See 3.1.2.3 uint8[] M Yes 3.1.2.1 challengeServer Page page 10 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If an existing authentication pending state is found, the server shall verify if the Authentication completion timer is currently running. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the Authentication completion timer is currently running, the server shall continue to process the client’s proofOfOwnership request. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If the client proofOfOwnership signature verification fails, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Feature / Interface Security evidence and traceability / OEM/Customer Review Interface Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the server fails or cannot determine that the authentication state was stored, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the server determines that the client does not have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError. Details & reviewer feedbackSection 3.2.3 Negative Response Page page 14 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the server determines that the client have an existing authentication pending state and the Authentication completion timer is expired, the server shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError. Details & reviewer feedbackSection 3.2.3 Negative Response Page page 14 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server determines that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x10, indicating generalReject. Details & reviewer feedbackSection 3.2.3 Negative Response Page page 14 Feature / Interface Security evidence and traceability / OEM/Customer Review Interface Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
The server shall delete/invalidate the client’s authentication prior to positively responding to the deAuthenticate request. Details & reviewer feedbackSection 0x00 – 0xFF M Page page 15 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the server is unable to delete the client's authentication state or cannot verify its presence, it shall respond to the deAuthenticate request with Negative Response Code (NRC) 0x94, Details & reviewer feedbackSection 4.1 Certificate Page page 16 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If a client and server have successfully completed the authentication process, the server shall invalidate the authentication state in the event of: • The server is reset (i.e server is power cycled). Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
The server’s authentication pending state shall contain the minimum of (non-exhaustive list): • Client address that issued the authentication request. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
The server’s authentication state shall contain the minimum of (non-exhaustive list): • SessionKey. Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. |
The server shall support only one authentication state. Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
The server shall support only one authentication pending state. Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
The server shall ensure that the sessionKey is exclusively used for the application responsible for communication over securedDataTransmission (CVS32). Details & reviewer feedbackSection 4.5 CRNG Page page 22 Supplier proposal Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The server shall start the timer (A3) after a valid proofOfOwnership has been received. Details & reviewer feedbackSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If the A3 timer timeouts before a new request is received (from the same client), the server shall invalidate the authentication state. Details & reviewer feedbackSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If the server can determine that a delay is not running after reset, it shall accept a subsequent authentication request without any delay. Details & reviewer feedbackSection 4.9 Authentication completion timer Page page 24 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If the server cannot determine that a delay is not running after reset, it shall not accept a subsequent authentication request without any delay. Details & reviewer feedbackSection 4.9 Authentication completion timer Page page 24 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
If D-RBACC extension is detected, the server shall overrule the RBACC with the D-RBACC permissions. Details & reviewer feedbackSection 4.1.3 D-RBACC extension Page page 18 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
• The server shall validate the D-RBACC by parsing all its content. If content is invalid, Details & reviewer feedbackSection 4.1.8 Certificate Validity Time Page page 19 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
• The server shall verify that the D-RBACC version provided by the client is compatible with the server’s supported D-RBACC version. Details & reviewer feedbackSection 4.1.8 Certificate Validity Time Page page 19 Supplier proposal Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. |
Summary The purpose of this document is to clarify vehicle manufacture specific extensions and exceptions to the Authentication 0x29 service specified in ISO 14229-1:2020. CVS150 Cryptographic Specification CVS32 SecuredDataTransmis sion 0x84 CVS151 RBAC CVS33 Entity Management Protocol (EMP) CVS31 Authenticate 0x29 CVS124 Traton Specification on Unified diagnostic services (UDS) CVS30 X.509 Specification CVS34 EMP – Basic Entities Figure 1 – Overview of relation between specifications The following documents are normative and indispensable for the application of this document: • Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) • ISO 14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements Whenever a requirement in this specification or the Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) is non-compliant with one or more requirements in ISO 14229-1:2020 the requirements in this specification and (CVS124) take precedence. Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer. It is the vehicle manufacturer that decides if a deviation can be accepted or not. Multiple security concepts are available in the Authentication (ISO 14229-1:2020) service, however, only APCE (ISO 14229-1:2020) is supported by the concept described in this document, see Figure 2. Details & reviewer feedbackSection 1.1 Summary Page page 4 Feature / Interface None / OEM/Customer Review Interface Security capability Authentication Supplier proposal Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The request for verifyCertificateBidirectional subfunction shall be formatted according to Details & reviewer feedbackSection 3.1.1 Request Page page 8 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 1
|
The expected range values of lengthOfCertificateClient shall be from 0x00C8 to 0x0800. Details & reviewer feedbackSection 3.1.1.2 lengthOfCertificateClient Page page 9 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The response for verifyCertificateBidirectional subfunction shall be formatted according to Table 6. Details & reviewer feedbackSection 3.1.2 Response Page page 9 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Table 9 – deAuthenticate request message layout Field Description Type/Value Cvt Authentication Request SID Service ID for 0x29 M SubFunction = [AuthenticationTask = deAuthenticate] Subfunction for request to leave the authenticated state 0x00 M 3.3.2 Response The response for deAuthenticate subfunction shall be formatted according to Table 10. Details & reviewer feedbackSection 3.3.3 Negative Response Page page 15 Supplier proposal Accept with assumption. Implement the ECU-side diagnostic behavior with configurable authorization and verification evidence, subject to customer-confirmed UDS service allocation and role model. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 0
|
The signature algorithm used throughout the authentication process shall be ED25519. Details & reviewer feedbackSection 4 General 4.1 Certificate Page page 16 Security capability Authentication Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The client shall use the private key corresponding to the client certificate to generate the signatures. Details & reviewer feedbackSection 4.1 Certificate Page page 16 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The format and the structure of the certificates shall be based on (CVS30). Details & reviewer feedbackSection 4.1 Certificate Page page 16 Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The ECU-Diagnostic role extension shall be included in the client certificate. Details & reviewer feedbackSection 4.1.2 ECU-Diagnostic Role extension Page page 18 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The Key Usage extension (RFC 5280) shall be included in the client certificate. Details & reviewer feedbackSection 4.1.5 Key Usage extension Page page 19 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The Key Usage extension shall contain DigitalSignature. Details & reviewer feedbackSection 4.1.8 Certificate Validity Time Page page 19 Security capability Key management Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. |
The Extended Key Usage extension (RFC 5280) shall be included in the client certificate. Details & reviewer feedbackSection 4.1.6 Extended Key Usage extension Page page 19 Security capability Certificate handling Supplier proposal Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. |
The extension ExtendedKeyUsage shall contain clientAuth (1.3.6.1.5.5.7.3.2). Details & reviewer feedbackSection 4.1.8 Certificate Validity Time Page page 19 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. |
The private keys shall be generated using a CRNG. Details & reviewer feedbackSection 4.5 CRNG Page page 22 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The sessionKey shall be generated according to the pseudo code below. Details & reviewer feedbackSection 4.5 CRNG Page page 22 Supplier proposal Accept with assumption. Implement the ECU-side diagnostic behavior with configurable authorization and verification evidence, subject to customer-confirmed UDS service allocation and role model. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
Only Passive time-based de-authentication shall be supported. Details & reviewer feedbackSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. |
The Authentication completion timer shall be set to 1 minute. Details & reviewer feedbackSection 4.9 Authentication completion timer Page page 24 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. |
• A new successful authentication is established. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• By passive de-authentication, see 4.7. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Authentication completion timer. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Client’s certificate public key Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Client D-RBACC, if provided in the client’s certificate Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Server ephemeral private key Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• A3 Timer for passive de-authentication information. Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Client address that issued the authentication request. Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Client roles (ECU diagnostic Role extension in client’s certificate) Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Client D-RBACC, if provided in the client’s certificate Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added chapter for Certificate validity Added Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
(fails -> failure) Changed Table 7 (EphemeralPublicKeyClient -> ephemeralPublicKeyClient) Removed ambiguity Changed Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed Table 3 (Authentication pending state and authentication state) Changed Table 5 (Changed column name POO -> proofOfOwnershipServer) Changed Table 6 (Changed column name POO -> proofOfOwnershipServer) Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
(Maximum size of elements is to be defined by max size of certificate) Added Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Chapter 2.1.1.2 lengthOfCertificateClient Added Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Clarified the signature algorithm to be used over the authentication process Removed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
The proof/signature shall be generated according to the pseudo code below. Details & reviewer feedbackSection 3.2 proofOfOwnership Page page 11 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The signature shall be generated according to the pseudo code below. Details & reviewer feedbackSection 3.2.3 Negative Response Page page 14 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The roles shall correspond to a bit pattern-octet string. Details & reviewer feedbackSection 4.1.3 D-RBACC extension Page page 18 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. |
The extension SignatureAlgorithm shall contain ED25519 (1.3.101.112). Details & reviewer feedbackSection 4.1.7 SignatureAlgorithm Page page 19 Supplier proposal Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. |
• The server is reset (i.e server is power cycled). Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
The server shall only support subfunctions in Table 4. Details & reviewer feedbackSection 3 subFunctions Page page 7 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 1
|
This field shall consists of 32 octets. Details & reviewer feedbackSection 3.1.1.1 challengeClient Page page 9 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. |
The challengeClient (ISO 14229-1:2020) shall be generated using a CRNG. Details & reviewer feedbackSection 3.1.2 Response Page page 9 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. |
The request for proofOfOwnership subfunction shall be defined according to Table 7. Details & reviewer feedbackSection 3.2.1 Request Page page 12 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The proofOfOwnershipClient shall be generated according to the pseudo code below. Details & reviewer feedbackSection 3.2.2 Response Page page 13 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The response for proofOfOwnership subfunction shall be according to Table 8. Details & reviewer feedbackSection 3.2.2 Response Page page 13 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The request for deAuthenticate subfunction shall be formatted according to Table 9. Details & reviewer feedbackSection 3.3.1 Request Page page 15 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 0
|
If the server determines that the client is not currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x24, indicating a requestSequenceError. Details & reviewer feedbackSection 3.3.3 Negative Response Page page 15 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the NodeUID extension is not detected, the operation shall continue as in Details & reviewer feedbackSection 4.1.3 D-RBACC extension Page page 18 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The basicConstraints extension CA field shall be False. Details & reviewer feedbackSection 4.1.4 basicContraints extension Page page 19 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. |
Solution for a CRNG shall be according to (CVS150). Details & reviewer feedbackSection 4.5 CRNG Page page 22 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The server shall restart the timer (A3) every time a request is received by the same client. Details & reviewer feedbackSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. |
The parameter for passive timeout based deAuthenticate shall be decided in the project. Details & reviewer feedbackSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. |
The delay timer shall be set to 1 second. Details & reviewer feedbackSection 4.9 Authentication completion timer Page page 24 Supplier proposal Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. |
• Check if the NodeUID of the server is present in the NodeUIDs extension. Details & reviewer feedbackSection 4.1.3 D-RBACC extension Page page 18 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
For the length of NodeUID see (CVS124). Details & reviewer feedbackSection 4.1.3 D-RBACC extension Page page 18 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
State-keeping Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Power failure. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Power failure. Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• Successful deAuthenticate (see 3.3) subFunction (ISO 14229-1:2020). Details & reviewer feedbackSection 4.2 State-keeping Page page 20 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
• H0 hash value Details & reviewer feedbackSection 4.2 State-keeping Page page 21 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Migrated Req. into Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
Details & reviewer feedbackSection Added Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 1
|
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 1
|
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 1
|
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed tag Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
to Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Duplicated AUTH_INFO due to typo. Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Fixed typo Changed Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
(fails -> failure) Changed Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
since it is covered by Details & reviewer feedbackSection 6 Normative references Page page 29 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Changed Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Changed Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Changed Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Changed Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Changed Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Changed Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Changed Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Added Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Added Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Added Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Added Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Details & reviewer feedbackSection Added Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Reformulation for clarity improvement Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs. Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Changed Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Added Details & reviewer feedbackSection 6 Normative references Page page 30 Supplier proposal Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. |
Reads like a requirement but no customer requirement ID was identified in the source. Confirm with the customer before baselining — not counted as a confirmed requirement.
If an active authentication state already exists, the server shall replace the existing state with the newly established one. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection 3.2.2 Response Page page 13 |
If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject. Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. DetailsSection 4.1.8 Certificate Validity Time Page page 19 Security capability Certificate handling |
If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject. Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. DetailsSection 4.1.8 Certificate Validity Time Page page 19 Security capability Certificate handling |
Shall be agreed between the supplier and the vehicle manufacturer. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection 2 Abbrevations Page page 6 Feature / Interface None / OEM/Customer Review Interface |
It contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection 2 Abbrevations Page page 6 |
It contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection 2 Abbrevations Page page 6 |
If such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response. Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy. DetailsSection 3 subFunctions Page page 7 Feature / Interface Secure communication and freshness protection / None |
The User shall apply the latest version of this CVS31. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection page-1 Page 1 Page page 1 |
Any review of CVS31 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”. Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed. DetailsSection page-3 Page 3 Page page 3 |
The whole standard has been reworked and shall be read in its entirety. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection page-3 Page 3 Page page 3 |
• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection page-3 Page 3 Page page 3 |
Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer. Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. DetailsSection 1.1 Summary Page page 4 Feature / Interface None / OEM/Customer Review Interface |
Descriptive or contextual statements with a customer ID but no binding (shall/must) wording.
While the ECU-Diagnostic Role extension specifies the roles assigned to a client, the D-RBACC extension may both grant additional permissions and restrict permissions beyond those derived from the client’s roles. DetailsSection 4.1.3 D-RBACC extension Page page 18 |
The column “Included in proofOfOwnershipServer”, present in several message-definition tables, indicates whether the corresponding field shall be covered by the proofOfOwnershipServer signature computed by the server and included in its response. DetailsSection 3.1.1 Request Page page 8 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
It should not be possible to “unlock” the server using its own key/certificate. DetailsSection 4.1 Certificate Page page 16 Security capability Certificate handling |
The interpretation of the roles should follow as the example below: • Role 1 -> 0000 0000 0000 0000 0000 0000 0000 0001 – 00 00 00 01 • Role 32 -> 1000 0000 0000 0000 0000 0000 0000 0000 – 80 00 00 00 • Role 2 and 4 -> 0000 0000 0000 0000 0000 0000 0000 1010 – 00 00 00 0A. DetailsSection 4.1.3 D-RBACC extension Page page 18 |
This means that if D-RBACC logic denies/permits certain access, the server shall deny/permit the access regardless of what RBACC logic permits/denies. DetailsSection 4.1.3 D-RBACC extension Page page 18 |
The delay timer represents the required minimum time between verifyCertificateBidirectional DetailsSection 4.9 Authentication completion timer Page page 24 |
For details on Authentication delay timer, refer to chapter 4.8. DetailsSection 3.1.1 Request Page page 8 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
For details in how to validate a client certificate, refer to chapter 4.1. DetailsSection 3.1.2 Response Page page 9 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
This field consists of a signature that proves to the client that the server has access to the private key of the provided certificateServer (ISO 14229-1:2020). Additionally, the field proves that the same message sent by the client has been received by the server and vice-versa. DetailsSection 3.2 proofOfOwnership Page page 11 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
For obvious reasons, the proofOfOwnershipServer in the VerifyCertificates is not included, in the “concatenation” (see pseudo code above) when the signature/proof is being calculated. DetailsSection 𝐻0 ∶= 𝑆𝐻𝐴512_ℎ𝑎𝑠ℎ(𝑉𝑒𝑟𝑖𝑓𝑦𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒𝑟𝑒𝑞|| 𝑉𝑒𝑟𝑖𝑓𝑦𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒𝑟𝑒𝑠) 𝑃𝑟𝑜𝑜𝑓𝑂𝑓𝑂𝑤𝑛𝑒𝑟𝑠ℎ𝑖𝑝𝑆𝑒𝑟𝑣𝑒𝑟 ∶= 𝑆𝑖𝑔𝑛(𝑆𝑒𝑟𝑣𝑒𝑟𝑃𝑟𝑖𝑣𝑎𝑡𝑒𝐾𝑒𝑦, 𝐻0) Page page 11 |
This field provides the client with the necessary server-side data for the chosen key-exchange scheme/algorithm. DetailsSection 3.1.2.3 ephemeralPublicKeyServer Page page 11 |
This subfunction (ISO 14229-1:2020) serves several purposes – it proves to the server that the client owns the private key of the provided certificateClient (ISO 14229-1:2020). DetailsSection 3.2 proofOfOwnership Page page 11 |
For details on Authentication completion timer, refer to chapter 4.9. DetailsSection 3.2.1 Request Page page 12 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The field proofOfOwnershipClient is a signature that proves to the server that the client has access to the private key of the certificateClient (ISO 14229-1:2020). DetailsSection 3.2.1.1 proofOfOwnershipClient Page page 13 |
The reason for the concatenation, is to ensure that the full communication (all sent and received requests and responses) has integrity. DetailsSection 3.2.2 Response Page page 13 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
This field provides the server with the necessary client-side data for the chosen key-exchange scheme/algorithm. DetailsSection 3.2.1.2 ephemeralPublicKeyClient Page page 13 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The sessionKeyInfo includes a signature that proves to the client that the server has accepted the proofOfOwnership (ISO 14229-1:2020). DetailsSection 3.2.3 Negative Response Page page 14 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
For obvious reasons, the sessionKeyInfo in the ProofOfOwnershipres is not included, in the “concatenation” (see pseudo code above) when the signature is being calculated. DetailsSection 3.2.3 Negative Response Page page 14 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
The server only responds NRC 0x24 in the case that it can confirm that there is no authentication state connected to the client requesting to deAuthenticate. DetailsSection 3.3.3 Negative Response Page page 15 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
If the server is unable to delete the client’s authentication state or cannot retrieve it due to internal errors, the server responds NRC 0x94.This informs the client that the authentication state may still exist on the server. DetailsSection 4.1 Certificate Page page 16 |
The signature algorithm in the client, server and authentication CA certificates are ED25519 (1.3.101.112). DetailsSection 4.1 Certificate Page page 16 |
A certificate without NodeUID extension implies that the certificate is applicable for any NodeUID. DetailsSection 4.1.3 D-RBACC extension Page page 18 |
The maximum number of elements in the list (number of ids) is limited by the maximum size of the certificate. DetailsSection 4.1.3 D-RBACC extension Page page 18 |
The D-RBACC extension defines client-specific rules that override the role-based access control configuration in the server. DetailsSection 4.1.3 D-RBACC extension Page page 18 |
• Parsing means that the server tries to decode the DER encoded D-RBACC structure, which includes checking the decoded results against the server’s supported/known ASN.1 definition. DetailsSection 4.1.8 Certificate Validity Time Page page 19 |
The notBefore and notAfter are received as fields in the certificate while Certificate-Time is the EMP entity defined in CVS34. DetailsSection 4.1.8 Certificate Validity Time Page page 19 |
If a request to reset (e.g service 0x11) is received over the service 0x84 (securedDataTransmission) it permits the server to respond before the sessionKey is locked/invalidated. DetailsSection 4.2 State-keeping Page page 20 |
Authentication state invalidated by the server implies that any unlocked services and sessionKey is locked/invalidated. DetailsSection 4.2 State-keeping Page page 20 |
The server ephemeral private key is the pair of the public key (ephemeralPublicKeyServer) sent as verifyCertificateBidirectional response. DetailsSection 4.2 State-keeping Page page 21 |
H0 hash value is calculated as part of proofOfOwnershipServer in verifyCertificateBidirectional response. DetailsSection 4.2 State-keeping Page page 21 |
The ephemeralPublicKeyClient in the proofOfOwnership-request (from the client) and the ephemeralPublicKeyClient in the verifyCertificate-response (from the server) consists of a Curve25519 [RFC 7748] public key. DetailsSection 4.5 CRNG Page page 22 |
An overview of the key-exchange process is shown in Figure 4. DetailsSection 4.5 CRNG Page page 22 |
ephemeralPublicKeyServer) ephemeralPublicKeyServer, ephemeralPrivateKeyServer:= Curve25519() sessionKey := X25519(ephemeralPrivateKeyServer, ephemeralPublicKeyClient) sessionKey := X25519(ephemeralPrivateKeyClient , ephemeralPublicKeyServer) ephemeralPublicKeyClient, ephemeralPrivateKeyClient := Curve25519() ProofOfOwnership(...) VerifyCertificate(...) Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange 4.4 External usage of the sessionKey The sessionKey is used outside the Authentication (ISO 14229-1:2020) service and is run through a key derivation function defined in (CVS32) to derive a key that can be used for securedDataTransmission communication. DetailsSection 4.5 CRNG Page page 22 Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The SessionKey is referred as SecuredDataTransmissionKey in (CVS32). DetailsSection 4.5 CRNG Page page 22 Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
Example: If the server’s RBACC is for some reason corrupt or misconfigured this would lock out the client from doing diagnostics (the server will refuse all diagnostics). DetailsSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 |
Two passive de-authentication mechanisms are described in (ISO 14229-1:2020). DetailsSection 4.7 PassiveDeAuthentication Page page 23 |
For this requirement, “same client” refers to a request that originates from the same tester address as the tester currently authenticated by the server. DetailsSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 |
When a request is received, authenticated or not, the server upon verifying it is from the same client will restart the timer (A3). DetailsSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 |
The Authentication completion timer represents the timeframe that the client is allowed to perform proofOfOwnership request after a verifyCertificateBidirectional request. DetailsSection 4.9 Authentication completion timer Page page 24 Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
The Authentication completion timer is started upon positive response for verifyCertificateBidirectional request. DetailsSection 4.9 Authentication completion timer Page page 24 |
Removed AUTH_REQ 137 since it is covered by AUTH_REQ 135 Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported DetailsSection 6 Normative references Page page 29 |
Removed Unused reference Fixed wrong cross reference Migrated Annex A “ephemeralPublicKey” into new chapter 3.3 “SessionKey” and added pseudo code for sessionKey Migrated Info into DetailsSection 6 Normative references Page page 29 Related Tables / DiagramsLinked tables: 0 | Linked diagrams: 1
|
Added OID for client authentication Changed DetailsSection 6 Normative references Page page 29 |
(VerifyCertificateres -> VerifyCertificates) Changed Table 5 (lengthofCertificateClient -> lengthOfCertificateClient) Changed Table 6 (lengthOfCertitifacteServer -> lengthOfCertificateServer) Changed DetailsSection 6 Normative references Page page 29 |
Updated document quirks chapter Removed the information that italic terms are often clickable. DetailsSection 6 Normative references Page page 30 |
(Maximum size of elements is to be defined by max size of certificate) Updated Figure 3 Reformulation requirements over the length of client certificate Removed DetailsSection 6 Normative references Page page 30 |
2025-08 CVS31 First edition 2025-05-30 RFQ 2517 Delivery Added authentication delay timer Added Authentication Completion timer Clarified negative responses cases for each subfunction DetailsSection 6 Normative references Page page 30 |
The A3 timer differs from S3 timer in terms of expected behavior during timeout and should not be implemented as a single timer. DetailsSection 4.7.1 TimeBasedPassiveDeAuthentication Page page 23 |
This section of the document describes vehicle manufacturer specific requirements regarding the behaviour and content of the subFunctions (ISO 14229-1:2020) found in Table 4. DetailsSection 3 subFunctions Page page 7 Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 0
|
In this document, each subFunction (ISO 14229-1:2020) is described in its own sub-section. DetailsSection 3 subFunctions Page page 7 Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 0
|
This chapter specifies the behaviour of the deAuthenticate subfunction. DetailsSection 3.3.3 Negative Response Page page 15 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
to DetailsSection 6 Normative references Page page 29 Related Tables / DiagramsLinked tables: 2 | Linked diagrams: 0
|
Changed tag DetailsSection 6 Normative references Page page 29 |
to DetailsSection 6 Normative references Page page 29 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Changed tag DetailsSection 6 Normative references Page page 29 |
to DetailsSection 6 Normative references Page page 29 |
Changed tag DetailsSection 6 Normative references Page page 29 |
to DetailsSection 6 Normative references Page page 29 |
Changed tag DetailsSection 6 Normative references Page page 29 |
to DetailsSection 6 Normative references Page page 29 |
Changed tag DetailsSection 6 Normative references Page page 29 |
to DetailsSection 6 Normative references Page page 29 Related Tables / DiagramsLinked tables: 1 | Linked diagrams: 0
|
Migrated Info into DetailsSection 6 Normative references Page page 29 |
Migrated Req. DetailsSection 6 Normative references Page page 29 |
(Removed “shown in only”) Changed DetailsSection 6 Normative references Page page 29 |
Removed DetailsSection 6 Normative references Page page 29 |
DetailsSection Changed Page page 30 |
DetailsSection Changed Page page 30 |
DetailsSection Changed Page page 30 |
DetailsSection Removed Page page 30 |
and DetailsSection 6 Normative references Page page 30 |
Changed DetailsSection 6 Normative references Page page 30 |
Changed DetailsSection 6 Normative references Page page 30 |
Changed DetailsSection 6 Normative references Page page 30 |
Changed DetailsSection 6 Normative references Page page 30 |
(Changed POO -> proofOfOwnershipServer) Removed DetailsSection 6 Normative references Page page 30 |
Added DetailsSection 6 Normative references Page page 30 |
Definitions, abbreviations, document history, scope and other boilerplate. Not customer requirements.
Normative references Annex B (informative) Change history Release Date Changes The whole standard has been reworked and shall be read in its entirety. DetailsSection 6 Normative references Page page 29 |
Page 3 Foreword This CVS31 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable. DetailsSection page-3 Page 3 Page page 3 |
This table is horizontally scrollable. Use the bottom scrollbar to view all columns.
| SSR | Statement / Trace | Feature | Security Capability | Interface | Responsibility | Status | Verification |
|---|---|---|---|---|---|---|---|
| SSR-COM-004 | Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0047; RFQX-CVS31-0060; RFQX-CVS31-0070; RFQX-CVS31-0071; RFQX-CVS31-0157; RFQX-CVS31-0158. | Secure Communication and Boundary Control | None | None | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-COM-006 | Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0141. | Secure Communication and Boundary Control | None | None | Shared | Ready for Customer Alignment | Review + Test + table/diagram context review |
| SSR-DAI-001 | Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (Cybersecurity domain; allocated to Security Services; security capability: Authentication; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0017; RFQX-CVS31-0021; RFQX-CVS31-0073; RFQX-CVS31-0081. | Data Authenticity and Integrity Verification | Authentication | OEM/Customer Review Interface | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-DAI-003 | Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0041; RFQX-CVS31-0048. | Data Authenticity and Integrity Verification | None | None | Shared | Ready for Customer Alignment | Review + Test + table/diagram context review |
| SSR-DAI-006 | Security evidence and traceability — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Security evidence and traceability data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0046; RFQX-CVS31-0061; RFQX-CVS31-0062. | Security evidence and traceability | None | OEM/Customer Review Interface | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-DAI-008 | Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (System domain; allocated to System Core).From this PDF: RFQX-CVS31-0033; RFQX-CVS31-0056; RFQX-CVS31-0105. | Data Authenticity and Integrity Verification | None | None | Supplier-Owned | Candidate | Review + Test + table/diagram context review |
| SSR-DIAG-006 | Diagnostic Services — Diagnostic ServicesThe ECU shall provide the diagnostic services for Diagnostic Services required by the allocated customer requirements, including the specified services, sessions and data identifiers (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0111; RFQX-CVS31-0119. | Diagnostic Services | None | None | Shared | Blocked by Customer Clarification | Test + table/diagram context review |
| SSR-KEY-001 | Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (Cybersecurity domain; allocated to Security Services; security capability: Certificate handling; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0037; RFQX-CVS31-0074; RFQX-CVS31-0075; RFQX-CVS31-0078; RFQX-CVS31-0080; RFQX-CVS31-0083; RFQX-CVS31-0088; RFQX-CVS31-0101; RFQX-CVS31-0102; RFQX-CVS31-0103; RFQX-CVS31-0106. | Key and Certificate Handling | Certificate handling | OEM/Customer Review Interface | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-KEY-002 | Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (System domain; allocated to System Core).From this PDF: RFQX-CVS31-0016; RFQX-CVS31-0026; RFQX-CVS31-0029; RFQX-CVS31-0077; RFQX-CVS31-0137. | Key and Certificate Handling | None | None | Supplier-Owned | Candidate | Review + Test + table/diagram context review |
| SSR-KEY-003 | Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0019; RFQX-CVS31-0027; RFQX-CVS31-0028; RFQX-CVS31-0036; RFQX-CVS31-0038; RFQX-CVS31-0156. | Key and Certificate Handling | None | None | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-RBAC-001 | Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Cybersecurity domain; allocated to Security Services; security capability: Diagnostic security; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0006. | Secure Diagnostics / RBAC | Diagnostic security | OEM/Customer Review Interface | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-RBAC-003 | Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0093; RFQX-CVS31-0095; RFQX-CVS31-0098. | Secure Diagnostics / RBAC | None | None | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-RBAC-004 | Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0042; RFQX-CVS31-0066; RFQX-CVS31-0143. | Secure Diagnostics / RBAC | None | None | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-RBAC-006 | Secure communication and freshness protection — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure communication and freshness protection, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0014. | Secure communication and freshness protection | None | None | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-SYS-001 | System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (System domain; allocated to System Core; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0024; RFQX-CVS31-0040; RFQX-CVS31-0051; RFQX-CVS31-0054; RFQX-CVS31-0065; RFQX-CVS31-0084; RFQX-CVS31-0089; RFQX-CVS31-0100; RFQX-CVS31-0104; RFQX-CVS31-0138; RFQX-CVS31-0142; RFQX-CVS31-0146; RFQX-CVS31-0152; RFQX-CVS31-0155; RFQX-CVS31-0160. | System Function | None | OEM/Customer Review Interface | Supplier-Owned | Candidate | Test + table/diagram context review |
| SSR-SYS-002 | System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (Process / compliance domain; allocated to Compliance Process; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0025. | System Function | None | OEM/Customer Review Interface | Supplier-Owned | Candidate | Test + table/diagram context review |
| SSR-TOOL-002 | Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0012; RFQX-CVS31-0022; RFQX-CVS31-0030; RFQX-CVS31-0043; RFQX-CVS31-0045; RFQX-CVS31-0058; RFQX-CVS31-0059; RFQX-CVS31-0063; RFQX-CVS31-0067; RFQX-CVS31-0068; RFQX-CVS31-0113; RFQX-CVS31-0120; RFQX-CVS31-0128; RFQX-CVS31-0133; RFQX-CVS31-0134; RFQX-CVS31-0147; RFQX-CVS31-0148; RFQX-CVS31-0151. | Tooling / IT / Evidence Storage | None | OEM/Customer Review Interface | Shared | Blocked by Customer Clarification | Review + Test + table/diagram context review |
| SSR-TOOL-004 | Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (System domain; allocated to System Core; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0031. | Tooling / IT / Evidence Storage | None | OEM/Customer Review Interface | Shared | Ready for Customer Alignment | Review + Test + table/diagram context review |
| Impact Area | Evidence From This PDF |
|---|---|
| Impacted system features | Secure communication and freshness protection; Security evidence and traceability |
| Impacted interfaces | OEM/Customer Review Interface |
| Impacted security capabilities | Authentication; Certificate handling; Key management |
| Impacted architecture elements | Application Software; Backend and IT Systems; Backend and IT Systems; OEM/Customer Review Interface; Compliance Process; Security Services; Security Services; OEM/Customer Review Interface; System Core; System Core; OEM/Customer Review Interface |
| Impacted work products | Cybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; Requirement traceability record; System/architecture design |
| Tools / IT / hardware / test | High/High/Low; High/High/Medium; High/Low/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium; Medium/High/Low; Medium/High/Medium; Medium/Low/Low; Medium/Low/Medium |
| Design assumptions introduced | Security-relevant requirement the ECU can own once responsibility/method is confirmed. Linked source table/diagram context was considered for interpretation.; Security-relevant requirement the ECU can own once responsibility/method is confirmed. |
| Design decisions required | Confirm with customer whether this is a binding requirement and assign a customer ID. |
| Impact | Status |
|---|---|
| Estimation impact | yes |
| Resource/tool/IT/HW/test impact | High/High/Low; High/High/Medium; High/Low/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium; Medium/High/Low; Medium/High/Medium; Medium/Low/Low; Medium/Low/Medium |
Generated from document-specific requirement, traceability, SSR, and open-point evidence.
flowchart LR
doc["CVS31.pdf"]
d0["Authentication"]
doc --> d0
d1["Certificate handling"]
doc --> d1
d2["Key management"]
doc --> d2
f0["Feature: Secure communication and freshness protection"]
doc --> f0
f1["Feature: Security evidence and traceability"]
doc --> f1
i0["Interface: OEM/Customer Review Interface"]
doc --> i0
s0["SSR: SSR-COM-004"]
doc --> s0
s1["SSR: SSR-COM-006"]
doc --> s1
s2["SSR: SSR-DAI-001"]
doc --> s2
o0["Open point: OP-002"]
doc --> o0
o1["Open point: OP-003"]
doc --> o1
o2["Open point: OP-004"]
doc --> o2
CVS31.pdf
Diagnostic Standard
Key / Certificate Handling
163 requirements, 77 information, 18 SSRs
11 tables, 7 diagrams
Markdown-derived requirements and registers; OCR disabled; no downstream PDF analysis
This table is horizontally scrollable. Use the bottom scrollbar to view all columns.
| Customer Requirement | SSR | Disposition | Confidence | Reason |
|---|---|---|---|---|
| RFQX-CVS31-0001 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0002 | None | Covered by Existing Supplier System Requirement | n/a | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0003 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0004 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0005 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0006 | SSR-RBAC-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0007 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0008 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0009 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0010 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0011 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0012 | SSR-TOOL-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0013 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0014 | SSR-RBAC-006 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0015 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0016 | SSR-KEY-002 | Derive Supplier System Requirement | Medium | Accepted requirement; seed of its SSR cluster. |
| RFQX-CVS31-0017 | SSR-DAI-001 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0018 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0019 | SSR-KEY-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0020 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0021 | SSR-DAI-001 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0022 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0023 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0024 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0025 | SSR-SYS-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0026 | SSR-KEY-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0027 | SSR-KEY-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0028 | SSR-KEY-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0029 | SSR-KEY-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0030 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0031 | SSR-TOOL-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0032 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0033 | SSR-DAI-008 | Derive Supplier System Requirement | Medium | Accepted requirement; seed of its SSR cluster. |
| RFQX-CVS31-0034 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0035 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0036 | SSR-KEY-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0037 | SSR-KEY-001 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0038 | SSR-KEY-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0039 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0040 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0041 | SSR-DAI-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0042 | SSR-RBAC-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0043 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0044 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0045 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0046 | SSR-DAI-006 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0047 | SSR-COM-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0048 | SSR-DAI-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0049 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0050 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0051 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0052 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0053 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0054 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0055 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0056 | SSR-DAI-008 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0057 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0058 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0059 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0060 | SSR-COM-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0061 | SSR-DAI-006 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0062 | SSR-DAI-006 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0063 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0064 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0065 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0066 | SSR-RBAC-004 | Covered by Existing Supplier System Requirement | Low | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0067 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0068 | SSR-TOOL-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0069 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0070 | SSR-COM-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0071 | SSR-COM-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0072 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0073 | SSR-DAI-001 | Covered by Existing Supplier System Requirement | Low | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0074 | SSR-KEY-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0075 | SSR-KEY-001 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0076 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0077 | SSR-KEY-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0078 | SSR-KEY-001 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0079 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0080 | SSR-KEY-001 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0081 | SSR-DAI-001 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0082 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0083 | SSR-KEY-001 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0084 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0085 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0086 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0087 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0088 | SSR-KEY-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0089 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0090 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0091 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0092 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0093 | SSR-RBAC-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0094 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0095 | SSR-RBAC-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0096 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0097 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0098 | SSR-RBAC-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0099 | None | Blocked by Customer Clarification | n/a | Needs customer clarification before derivation. |
| RFQX-CVS31-0100 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0101 | SSR-KEY-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0102 | SSR-KEY-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0103 | SSR-KEY-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0104 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0105 | SSR-DAI-008 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0106 | SSR-KEY-001 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0107 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0108 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0109 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0110 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0111 | SSR-DIAG-006 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0112 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0113 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0114 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0115 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0116 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0117 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0118 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0119 | SSR-DIAG-006 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0120 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0121 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0122 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0123 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0124 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0125 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0126 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0127 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0128 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0129 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0130 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0131 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0132 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0133 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0134 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0135 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0136 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0137 | SSR-KEY-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0138 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0139 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0140 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0141 | SSR-COM-006 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0142 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0143 | SSR-RBAC-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0144 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0145 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0146 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0147 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0148 | SSR-TOOL-002 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0149 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0150 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0151 | SSR-TOOL-002 | Shared Responsibility / CIA Needed | Medium | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0152 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0153 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0154 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0155 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0156 | SSR-KEY-003 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0157 | SSR-COM-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0158 | SSR-COM-004 | Shared Responsibility / CIA Needed | Low | Partially accepted; ECU portion mapped, OEM portion needs CIA/RASIC. |
| RFQX-CVS31-0159 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0160 | SSR-SYS-001 | Covered by Existing Supplier System Requirement | Medium | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0161 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0162 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0163 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0164 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0165 | None | Covered by Existing Supplier System Requirement | n/a | Accepted requirement; covered by a clustered SSR. |
| RFQX-CVS31-0166 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0167 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0168 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0169 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0170 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0171 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0172 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0173 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0174 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0175 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0176 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0177 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0178 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0179 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0180 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0181 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0182 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0183 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0184 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0185 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0186 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0187 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0188 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0189 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0190 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0191 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0192 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0193 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0194 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0195 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0196 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0197 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0198 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0199 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0200 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0201 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0202 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0203 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0204 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0205 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0206 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0207 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0208 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0209 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0210 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0211 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0212 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0213 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0214 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0215 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0216 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0217 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0218 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0219 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0220 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0221 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0222 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0223 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0224 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0225 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0226 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0227 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0228 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0229 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0230 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0231 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0232 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0233 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0234 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0235 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0236 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0237 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0238 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0239 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0240 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0241 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0242 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0243 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0244 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0245 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0246 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0247 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0248 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0249 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0250 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0251 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0252 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0253 | None | Informational Only | n/a | Non-binding; not derived. |
| RFQX-CVS31-0254 | None | Informational Only | n/a | Non-binding; not derived. |
CVS31.pdfconverted/markdown/source documentScope: this diagnostic standard specifies requirement, covering 1 Scope; 1.1 Summary; 2 Abbrevations; 3 subFunctions; 3.1 verifyCertificateBidirectional; 3.1.1 Request. System boundary and interfaces: the document constrains 1 interface(s) - OEM/Customer Review Interface; principal functions in scope are Secure communication and freshness protection; Security evidence and traceability.
Engineering obligations: 163 confirmed customer requirement(s) carry an explicit ID and normative wording and must be implemented and verified; 12 further requirement-like statement(s) have no customer ID and must be clarified before they can be baselined; 77 informational and 2 reference item(s) were separated out as non-binding. Design and security impact: affects Secure communication and freshness protection; Security evidence and traceability; security capabilities touched: Authentication; Certificate handling; Key management; 18 supplier system requirement(s) were derived from this document.
Open for the customer: 5 document-linked open point(s) - mainly Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. (sample: 3 of 5) - plus 12 unidentified requirement-like statement(s). Do not baseline these until the customer confirms. Confidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.
| Field | Interpretation |
|---|---|
| Document Purpose | Scope: this diagnostic standard specifies requirement, covering 1 Scope; 1.1 Summary; 2 Abbrevations; 3 subFunctions; 3.1 verifyCertificateBidirectional; 3.1.1 Request. |
| Engineering Interpretation | System boundary and interfaces: the document constrains 1 interface(s) - OEM/Customer Review Interface; principal functions in scope are Secure communication and freshness protection; Security evidence and traceability. |
| Supplier Proposal Impact | Engineering obligations: 163 confirmed customer requirement(s) carry an explicit ID and normative wording and must be implemented and verified; 12 further requirement-like statement(s) have no customer ID and must be clarified before they can be baselined; 77 informational and 2 reference item(s) were separated out as non-binding. |
| System / Security Impact | Design and security impact: affects Secure communication and freshness protection; Security evidence and traceability; security capabilities touched: Authentication; Certificate handling; Key management; 18 supplier system requirement(s) were derived from this document. |
| Customer Clarification Impact | Open for the customer: 5 document-linked open point(s) - mainly Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. (sample: 3 of 5) - plus 12 unidentified requirement-like statement(s). Do not baseline these until the customer confirms. |
| Confidence and Limits | Confidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used. |
| Theme | Summary | Requirement Count | Representative Requirements |
|---|---|---|---|
| Requirement | Groups related document requirements into a single engineering theme. | 163 | RFQX-CVS31-0006; RFQX-CVS31-0012; RFQX-CVS31-0014 |
| System architecture design | Groups related document requirements into a single engineering theme. | 148 | RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004 |
| System | Groups related document requirements into a single engineering theme. | 138 | RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004 |
| Cybersecurity concept and evidence | Drives cybersecurity concept, risk treatment, verification evidence, and traceability obligations. | 106 | RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006 |
| Responsibility and customer approval model | Creates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk. | 85 | RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006 |
| Information | Groups related document requirements into a single engineering theme. | 77 | RFQX-CVS31-0011; RFQX-CVS31-0013; RFQX-CVS31-0018 |
| Key, certificate, and PKI handling | Affects ECU trust material storage, provisioning, lifecycle ownership, and customer PKI dependencies. | 72 | RFQX-CVS31-0006; RFQX-CVS31-0016; RFQX-CVS31-0017 |
| Cybersecurity | Groups related document requirements into a single engineering theme. | 41 | RFQX-CVS31-0006; RFQX-CVS31-0017; RFQX-CVS31-0021 |
| Section | Requirements | Information | Unknown | Excluded | Total Items | Critical | Open Points | SSR Links |
|---|---|---|---|---|---|---|---|---|
| 1 Scope | 1 | 0 | 0 | 0 | 2 | 1 | 1 | 1 |
| -- 1.1 Summary | 1 | 0 | 0 | 0 | 2 | 1 | 1 | 1 |
| 2 Abbrevations | 0 | 0 | 0 | 0 | 3 | 3 | 1 | 0 |
| 3 subFunctions | 41 | 17 | 0 | 0 | 60 | 29 | 4 | 14 |
| -- 3.1 verifyCertificateBidirectional | 13 | 3 | 0 | 0 | 16 | 8 | 2 | 7 |
| -- -- 3.1.1 Request | 4 | 2 | 0 | 0 | 6 | 3 | 2 | 3 |
| -- -- 3.1.2 Response | 9 | 1 | 0 | 0 | 10 | 5 | 1 | 6 |
| -- 3.2 proofOfOwnership | 21 | 10 | 0 | 0 | 32 | 17 | 4 | 9 |
| -- -- 3.2.1 Request | 8 | 1 | 0 | 0 | 9 | 7 | 1 | 6 |
| -- -- 3.2.2 Response | 2 | 3 | 0 | 0 | 6 | 1 | 1 | 1 |
| -- -- 3.2.3 Negative Response | 7 | 2 | 0 | 0 | 9 | 6 | 1 | 4 |
| -- 3.3 deAuthenticate | 5 | 2 | 0 | 0 | 7 | 2 | 1 | 4 |
| -- -- 3.3.3 Negative Response | 5 | 2 | 0 | 0 | 7 | 2 | 1 | 4 |
| 4 General | 62 | 27 | 0 | 0 | 91 | 26 | 2 | 12 |
| -- 4.1 Certificate | 24 | 11 | 0 | 0 | 37 | 12 | 1 | 7 |
| -- -- 4.1.3 D-RBACC extension | 7 | 6 | 0 | 0 | 13 | 2 | 1 | 3 |
| -- -- 4.1.8 Certificate Validity Time | 9 | 2 | 0 | 0 | 13 | 5 | 1 | 4 |
| -- 4.2 State-keeping | 23 | 4 | 0 | 0 | 27 | 7 | 1 | 2 |
| -- 4.5 CRNG | 4 | 4 | 0 | 0 | 8 | 1 | 0 | 3 |
| -- 4.7 PassiveDeAuthentication | 6 | 5 | 0 | 0 | 11 | 3 | 1 | 3 |
| -- -- 4.7.1 TimeBasedPassiveDeAuthentication | 6 | 5 | 0 | 0 | 11 | 3 | 1 | 3 |
| -- 4.9 Authentication completion timer | 5 | 3 | 0 | 0 | 8 | 3 | 1 | 3 |
| 6 Normative references | 59 | 33 | 0 | 0 | 93 | 0 | 0 | 0 |
| Artifact | Type | Caption | Page | Related Requirements | Impact |
|---|---|---|---|---|---|
| TABLE-CVS31-0001 | Table | Table 1 – Abbreviations | page 6 | None | Diagnostic parameter or service behavior |
| TABLE-CVS31-0002 | Table | Table 2 – Conventions | page 6 | None | Table source context |
| TABLE-CVS31-0003 | Table | Table 3 – Terms and Definitions | page 6 | RFQX-CVS31-0011; RFQX-CVS31-0012; RFQX-CVS31-0013; RFQX-CVS31-0168; RFQX-CVS31-0186; RFQX-CVS31-0188; RFQX-CVS31-0230 | Security protocol or cryptographic context |
| TABLE-CVS31-0004 | Table | Table 4 – Supported subFunctions (ISO 14229-1:2020) | page 7 | RFQX-CVS31-0014; RFQX-CVS31-0011; RFQX-CVS31-0012; RFQX-CVS31-0013; RFQX-CVS31-0016; RFQX-CVS31-0168; RFQX-CVS31-0170; RFQX-CVS31-0186 | Security protocol or cryptographic context |
| TABLE-CVS31-0005 | Table | Table 5 – verifyCertificateBidirectional Request | page 8 | RFQX-CVS31-0017; RFQX-CVS31-0021; RFQX-CVS31-0016; RFQX-CVS31-0018; RFQX-CVS31-0019; RFQX-CVS31-0020; RFQX-CVS31-0022; RFQX-CVS31-0023 | Security protocol or cryptographic context |
| TABLE-CVS31-0006 | Table | Table 6 – verifyCertificateBidirectional Response | page 10 | RFQX-CVS31-0029; RFQX-CVS31-0031; RFQX-CVS31-0028; RFQX-CVS31-0030; RFQX-CVS31-0032; RFQX-CVS31-0033; RFQX-CVS31-0174; RFQX-CVS31-0176 | Security protocol or cryptographic context |
| TABLE-CVS31-0007 | Table | Table 7 – proofOfOwnership Request | page 12 | RFQX-CVS31-0042; RFQX-CVS31-0041; RFQX-CVS31-0043; RFQX-CVS31-0046; RFQX-CVS31-0047; RFQX-CVS31-0048; RFQX-CVS31-0040; RFQX-CVS31-0044 | Security protocol or cryptographic context |
| TABLE-CVS31-0008 | Table | Table 8 – proofOfOwnership Response | page 13 | RFQX-CVS31-0054; RFQX-CVS31-0051; RFQX-CVS31-0052; RFQX-CVS31-0053; RFQX-CVS31-0055; RFQX-CVS31-0056; RFQX-CVS31-0057; RFQX-CVS31-0058 | Diagnostic parameter or service behavior |
| TABLE-CVS31-0009 | Table | Table 9 – deAuthenticate request message layout | page 15 | RFQX-CVS31-0066; RFQX-CVS31-0065; RFQX-CVS31-0064; RFQX-CVS31-0167; RFQX-CVS31-0196 | State-machine or transition behavior |
| TABLE-CVS31-0010 | Table | Table 10 – deAuthenticate response message layout | page 15 | RFQX-CVS31-0066; RFQX-CVS31-0069; RFQX-CVS31-0065; RFQX-CVS31-0067; RFQX-CVS31-0068; RFQX-CVS31-0070; RFQX-CVS31-0167 | State-machine or transition behavior |
| TABLE-CVS31-0011 | Table | Table 11 – References | page 27 | None | Diagnostic parameter or service behavior |
| DIAGRAM-CVS31-0001 | Diagram | Figure 1 – Overview of relation between specifications | page 4 | RFQX-CVS31-0006 | Diagnostic parameter or service behavior |
| DIAGRAM-CVS31-0002 | Diagram | Figure 2 – Security concepts (ISO 14229-1:2020) | page 5 | None | Security protocol or cryptographic context |
| DIAGRAM-CVS31-0003 | Diagram | Figure 3 – Client certificate validation logic | page 17 | RFQX-CVS31-0083; RFQX-CVS31-0082; RFQX-CVS31-0084; RFQX-CVS31-0181 | Security protocol or cryptographic context |
| DIAGRAM-CVS31-0004 | Diagram | Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange | page 22 | RFQX-CVS31-0139; RFQX-CVS31-0137; RFQX-CVS31-0138; RFQX-CVS31-0140; RFQX-CVS31-0141; RFQX-CVS31-0142; RFQX-CVS31-0162; RFQX-CVS31-0197 | Diagnostic parameter or service behavior |
| DIAGRAM-CVS31-0005 | Diagram | Figure 5 – Overview | page 25 | RFQX-CVS31-0159 | Diagnostic parameter or service behavior |
| DIAGRAM-CVS31-0006 | Diagram | Figure 6 – Server Handling of Signature | page 26 | None | Security protocol or cryptographic context |
| DIAGRAM-CVS31-0007 | Diagram | Figure 7 – Authentication State Transition | page 28 | RFQX-CVS31-0166; RFQX-CVS31-0167; RFQX-CVS31-0168; RFQX-CVS31-0169; RFQX-CVS31-0170; RFQX-CVS31-0171; RFQX-CVS31-0012; RFQX-CVS31-0016 | State-machine or transition behavior |
Customer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.
| ID | Score | Category | Reason | Statement |
|---|---|---|---|---|
| RFQX-CVS31-0049 | 95 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivation | If an active authentication state already exists, the server shall replace the existing state with the newly established one. |
| RFQX-CVS31-0096 | 95 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivation | If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject. |
| RFQX-CVS31-0099 | 95 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivation | If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject. |
| RFQX-CVS31-0008 | 81 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | Shall be agreed between the supplier and the vehicle manufacturer. |
| RFQX-CVS31-0009 | 81 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | It contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response. |
| RFQX-CVS31-0010 | 81 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | It contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses. |
| RFQX-CVS31-0015 | 81 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivation | If such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response. |
| RFQX-CVS31-0014 | 77 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message. |
| RFQX-CVS31-0017 | 77 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | Table 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running. |
| RFQX-CVS31-0019 | 77 | High risk due to unclear OEM/supplier responsibility | security relevant; architecture relevant; Partially Accept; linked open point; High estimation impact | If upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request. |
| Open Point | Priority | Question | Impact | Status |
|---|---|---|---|---|
| OP-002 | Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy. | Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service. | Open | |
| OP-003 | Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. | ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open. | Open | |
| OP-004 | Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. | Update-control scope and evidence ownership stay open; risk of an unprotected update path. | Open | |
| OP-009 | Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed. | Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case. | Open | |
| OP-011 | Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. | Supplier position, estimation, and affected design allocation remain conditional for the listed requirements. | Open |
| SSR | Title | Statement | Reqs From This PDF | Other PDFs | Status |
|---|---|---|---|---|---|
| SSR-COM-004 | Secure Communication and Boundary Control — Secure Communication and Boundary Control | The ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (IT / backend domain; allocated to Backend and IT Systems). | RFQX-CVS31-0047; RFQX-CVS31-0060; RFQX-CVS31-0070; RFQX-CVS31-0071; RFQX-CVS31-0157; RFQX-CVS31-0158 | no | Blocked by Customer Clarification |
| SSR-COM-006 | Secure Communication and Boundary Control — Secure Communication and Boundary Control | The ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (Software domain; allocated to Application Software). | RFQX-CVS31-0141 | no | Ready for Customer Alignment |
| SSR-DAI-001 | Data Authenticity and Integrity Verification — Data Authenticity and Integrity Verification | The ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (Cybersecurity domain; allocated to Security Services; security capability: Authentication; interface: OEM/Customer Review Interface). | RFQX-CVS31-0017; RFQX-CVS31-0021; RFQX-CVS31-0073; RFQX-CVS31-0081 | no | Blocked by Customer Clarification |
| SSR-DAI-003 | Data Authenticity and Integrity Verification — Data Authenticity and Integrity Verification | The ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems). | RFQX-CVS31-0041; RFQX-CVS31-0048 | no | Ready for Customer Alignment |
| SSR-DAI-006 | Security evidence and traceability — Data Authenticity and Integrity Verification | The ECU shall verify the authenticity and integrity of Security evidence and traceability data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface). | RFQX-CVS31-0046; RFQX-CVS31-0061; RFQX-CVS31-0062 | no | Blocked by Customer Clarification |
| SSR-DAI-008 | Data Authenticity and Integrity Verification — Data Authenticity and Integrity Verification | The ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (System domain; allocated to System Core). | RFQX-CVS31-0033; RFQX-CVS31-0056; RFQX-CVS31-0105 | no | Candidate |
| SSR-DIAG-006 | Diagnostic Services — Diagnostic Services | The ECU shall provide the diagnostic services for Diagnostic Services required by the allocated customer requirements, including the specified services, sessions and data identifiers (Software domain; allocated to Application Software). | RFQX-CVS31-0111; RFQX-CVS31-0119 | no | Blocked by Customer Clarification |
| SSR-KEY-001 | Key and Certificate Handling — Key and Certificate Handling | The ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (Cybersecurity domain; allocated to Security Services; security capability: Certificate handling; interface: OEM/Customer Review Interface). | RFQX-CVS31-0037; RFQX-CVS31-0074; RFQX-CVS31-0075; RFQX-CVS31-0078; RFQX-CVS31-0080; RFQX-CVS31-0083; RFQX-CVS31-0088; RFQX-CVS31-0101; RFQX-CVS31-0102; RFQX-CVS31-0103; RFQX-CVS31-0106 | no | Blocked by Customer Clarification |
| SSR-KEY-002 | Key and Certificate Handling — Key and Certificate Handling | The ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (System domain; allocated to System Core). | RFQX-CVS31-0016; RFQX-CVS31-0026; RFQX-CVS31-0029; RFQX-CVS31-0077; RFQX-CVS31-0137 | no | Candidate |
| SSR-KEY-003 | Key and Certificate Handling — Key and Certificate Handling | The ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (IT / backend domain; allocated to Backend and IT Systems). | RFQX-CVS31-0019; RFQX-CVS31-0027; RFQX-CVS31-0028; RFQX-CVS31-0036; RFQX-CVS31-0038; RFQX-CVS31-0156 | no | Blocked by Customer Clarification |
| SSR-RBAC-001 | Secure Diagnostics / RBAC — Secure Diagnostics / RBAC | The ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Cybersecurity domain; allocated to Security Services; security capability: Diagnostic security; interface: OEM/Customer Review Interface). | RFQX-CVS31-0006 | no | Blocked by Customer Clarification |
| SSR-RBAC-003 | Secure Diagnostics / RBAC — Secure Diagnostics / RBAC | The ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (IT / backend domain; allocated to Backend and IT Systems). | RFQX-CVS31-0093; RFQX-CVS31-0095; RFQX-CVS31-0098 | no | Blocked by Customer Clarification |
| SSR-RBAC-004 | Secure Diagnostics / RBAC — Secure Diagnostics / RBAC | The ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software). | RFQX-CVS31-0042; RFQX-CVS31-0066; RFQX-CVS31-0143 | no | Blocked by Customer Clarification |
| SSR-RBAC-006 | Secure communication and freshness protection — Secure Diagnostics / RBAC | The ECU shall enforce authenticated, role-authorised access for Secure communication and freshness protection, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software). | RFQX-CVS31-0014 | no | Blocked by Customer Clarification |
| SSR-SYS-001 | System Function — System Function | The ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (System domain; allocated to System Core; interface: OEM/Customer Review Interface). | RFQX-CVS31-0024; RFQX-CVS31-0040; RFQX-CVS31-0051; RFQX-CVS31-0054; RFQX-CVS31-0065; RFQX-CVS31-0084; RFQX-CVS31-0089; RFQX-CVS31-0100; RFQX-CVS31-0104; RFQX-CVS31-0138; RFQX-CVS31-0142; RFQX-CVS31-0146; RFQX-CVS31-0152; RFQX-CVS31-0155; RFQX-CVS31-0160 | no | Candidate |
| SSR-SYS-002 | System Function — System Function | The ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (Process / compliance domain; allocated to Compliance Process; interface: OEM/Customer Review Interface). | RFQX-CVS31-0025 | no | Candidate |
| SSR-TOOL-002 | Tooling / IT / Evidence Storage — Tooling / IT / Evidence Storage | The supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface). | RFQX-CVS31-0012; RFQX-CVS31-0022; RFQX-CVS31-0030; RFQX-CVS31-0043; RFQX-CVS31-0045; RFQX-CVS31-0058; RFQX-CVS31-0059; RFQX-CVS31-0063; RFQX-CVS31-0067; RFQX-CVS31-0068; RFQX-CVS31-0113; RFQX-CVS31-0120; RFQX-CVS31-0128; RFQX-CVS31-0133; RFQX-CVS31-0134; RFQX-CVS31-0147; RFQX-CVS31-0148; RFQX-CVS31-0151 | no | Blocked by Customer Clarification |
| SSR-TOOL-004 | Tooling / IT / Evidence Storage — Tooling / IT / Evidence Storage | The supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (System domain; allocated to System Core; interface: OEM/Customer Review Interface). | RFQX-CVS31-0031 | no | Ready for Customer Alignment |