CVS31

CVS31.pdf · Diagnostic Standard · Key / Certificate Handling

Last updated: 2026-06-29 11:50
RTRFQX Review TeamWorkspace

CVS31

CVS31.pdf · Diagnostic Standard · Key / Certificate Handling

Markdown-derived onlyOCR: falseLast generated 2026-06-29 11:50

What this document contains

Confirmed Requirements163customer ID + normative
Needs Clarification12no customer ID
Information77descriptive
Reference2definitions, scope
Critical63ranked impact
Open Points5linked
Tables / Diagrams11 / 7extracted
Derived SSRs18linked

Executive Takeaway

Systems-engineering read of what this document defines for the system - scope, boundaries, interfaces, obligations, and what is still open.

Document Purpose

Scope: this diagnostic standard specifies requirement, covering 1 Scope; 1.1 Summary; 2 Abbrevations; 3 subFunctions; 3.1 verifyCertificateBidirectional; 3.1.1 Request.

System Boundary & Interfaces

System boundary and interfaces: the document constrains 1 interface(s) - OEM/Customer Review Interface; principal functions in scope are Secure communication and freshness protection; Security evidence and traceability.

Design / Security Impact

Design and security impact: affects Secure communication and freshness protection; Security evidence and traceability; security capabilities touched: Authentication; Certificate handling; Key management; 18 supplier system requirement(s) were derived from this document.

Open For Customer

Open for the customer: 5 document-linked open point(s) - mainly Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. (sample: 3 of 5) - plus 12 unidentified requirement-like statement(s). Do not baseline these until the customer confirms.

Confidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.

Main Requirement Themes

ThemeEngineering MeaningRequirement CountRepresentative Requirements
RequirementGroups related document requirements into a single engineering theme.163RFQX-CVS31-0006; RFQX-CVS31-0012; RFQX-CVS31-0014
System architecture designGroups related document requirements into a single engineering theme.148RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004
SystemGroups related document requirements into a single engineering theme.138RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.106RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.85RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006
InformationGroups related document requirements into a single engineering theme.77RFQX-CVS31-0011; RFQX-CVS31-0013; RFQX-CVS31-0018
Key, certificate, and PKI handlingAffects ECU trust material storage, provisioning, lifecycle ownership, and customer PKI dependencies.72RFQX-CVS31-0006; RFQX-CVS31-0016; RFQX-CVS31-0017
CybersecurityGroups related document requirements into a single engineering theme.41RFQX-CVS31-0006; RFQX-CVS31-0017; RFQX-CVS31-0021

Document Content Structure

SectionRequirementsInformationUnknown / Review NeededTotal ItemsCriticalOpen PointsSSR Links
1 Scope1002111
-- 1.1 Summary1002111
2 Abbrevations0003310
3 subFunctions411706029414
-- 3.1 verifyCertificateBidirectional133016827
-- -- 3.1.1 Request4206323
-- -- 3.1.2 Response91010516
-- 3.2 proofOfOwnership21100321749
-- -- 3.2.1 Request8109716
-- -- 3.2.2 Response2306111
-- -- 3.2.3 Negative Response7209614
-- 3.3 deAuthenticate5207214
-- -- 3.3.3 Negative Response5207214
4 General622709126212
-- 4.1 Certificate24110371217
-- -- 4.1.3 D-RBACC extension76013213
-- -- 4.1.8 Certificate Validity Time92013514
-- 4.2 State-keeping234027712
-- 4.5 CRNG4408103
-- 4.7 PassiveDeAuthentication65011313
-- -- 4.7.1 TimeBasedPassiveDeAuthentication65011313
-- 4.9 Authentication completion timer5308313
6 Normative references5933093000

Tables and Diagrams

Tables are reconstructed column-correct from the document text layer (no OCR). Diagrams are linked from converted image assets.

Tables11column-correct
Diagrams7image-linked
Linked Artifacts13requirement-linked

Tables (11)

TableTable 1 – Abbreviations

1.3 Document quirks · page 6 · Linked: None

AbbreviationDescription
ECUElectronic Control Unit
ID, id, IdIdentifier
N/A, NA, N.ANot Applicable
MACMessage Authentication Code
PKIPublic key infrastructure
SDTSecured Data Transmission
SIDService Identifier
CRNG /Cryptographically Random Number Generator
View all 13 rows
AbbreviationDescription
ECUElectronic Control Unit
ID, id, IdIdentifier
N/A, NA, N.ANot Applicable
MACMessage Authentication Code
PKIPublic key infrastructure
SDTSecured Data Transmission
SIDService Identifier
CRNG /Cryptographically Random Number Generator
CSPRNG /Cryptographically Secure Pseudorandom Number Generator
CPRNGCryptographic Pseudorandom Number Generator
RBACRole based access control
RBACCRole based access control configuration
D-RBACCDiagnostics RBACC

Diagnostic parameter or service behavior

TableTable 2 – Conventions

1.3 Document quirks · page 6 · Linked: None

AbbreviationDescription
ECUElectronic Control Unit
ID, id, IdIdentifier
N/A, NA, N.ANot Applicable
MACMessage Authentication Code
PKIPublic key infrastructure
SDTSecured Data Transmission
SIDService Identifier
CRNG /Cryptographically Random Number Generator
View all 13 rows
AbbreviationDescription
ECUElectronic Control Unit
ID, id, IdIdentifier
N/A, NA, N.ANot Applicable
MACMessage Authentication Code
PKIPublic key infrastructure
SDTSecured Data Transmission
SIDService Identifier
CRNG /Cryptographically Random Number Generator
CSPRNG /Cryptographically Secure Pseudorandom Number Generator
CPRNGCryptographic Pseudorandom Number Generator
RBACRole based access control
RBACCRole based access control configuration
D-RBACCDiagnostics RBACC

Table source context

TableTable 3 – Terms and Definitions

1.3 Document quirks · page 6 · Linked: AUTH_INFO 1; AUTH_REQ 1; AUTH_INFO 2

AbbreviationDescription
ECUElectronic Control Unit
ID, id, IdIdentifier
N/A, NA, N.ANot Applicable
MACMessage Authentication Code
PKIPublic key infrastructure
SDTSecured Data Transmission
SIDService Identifier
CRNG /Cryptographically Random Number Generator
View all 13 rows
AbbreviationDescription
ECUElectronic Control Unit
ID, id, IdIdentifier
N/A, NA, N.ANot Applicable
MACMessage Authentication Code
PKIPublic key infrastructure
SDTSecured Data Transmission
SIDService Identifier
CRNG /Cryptographically Random Number Generator
CSPRNG /Cryptographically Secure Pseudorandom Number Generator
CPRNGCryptographic Pseudorandom Number Generator
RBACRole based access control
RBACCRole based access control configuration
D-RBACCDiagnostics RBACC

Security protocol or cryptographic context

TableTable 4 – Supported subFunctions (ISO 14229-1:2020)

1.3 Document quirks · page 7 · Linked: AUTH_REQ 155; AUTH_INFO 1; AUTH_REQ 1; AUTH_INFO 2; AUTH_REQ 2

Name
verifyCertificateBidirectional
proofOfOwnership
deAuthenticate

Security protocol or cryptographic context

TableTable 5 – verifyCertificateBidirectional Request

3.1.1 Request · page 8 · Linked: AUTH_REQ 117; AUTH_REQ 45; AUTH_REQ 2; AUTH_INFO 30; AUTH_REQ 118; AUTH_INFO 24 (sample: 6 of 8)

Wide table - scrolls horizontally inside this card.

FieldDescriptionType/ValueCvtIncluded in proofOfOwnershipServer
Authentication Request SIDService ID for Authentication service Initiate request Authentication by0x29MYes
SubFunction =verifying the
[AuthenticationTask =Certificate and0x02MYes
verifyCertificateBidirectional]generating a Proof of Ownership from the server
communicationConfigurationNOT USED0x00MYes
lengthOfCertificateClientLength parameter for certificateClientuint16MYes
certificateClientThe Certificate to verifyuint8[]MYes
lengthOfChallengeClientLength parameter for challengeClientuint16MYes
View all 9 rows
FieldDescriptionType/ValueCvtIncluded in proofOfOwnershipServer
Authentication Request SIDService ID for Authentication service Initiate request Authentication by0x29MYes
SubFunction =verifying the
[AuthenticationTask =Certificate and0x02MYes
verifyCertificateBidirectional]generating a Proof of Ownership from the server
communicationConfigurationNOT USED0x00MYes
lengthOfCertificateClientLength parameter for certificateClientuint16MYes
certificateClientThe Certificate to verifyuint8[]MYes
lengthOfChallengeClientLength parameter for challengeClientuint16MYes
challengeClientSee 3.1.1.1uint8[]MYes

Security protocol or cryptographic context

TableTable 6 – verifyCertificateBidirectional Response

3.1.2 Response · page 10 · Linked: AUTH_REQ 5; AUTH_REQ 6; AUTH_REQ 174; AUTH_REQ 120; AUTH_INFO 143; AUTH_REQ 7

Wide table - scrolls horizontally inside this card.

FieldDescriptionType/ ValueCvtIncluded in proofOfOwnershipServer
Authentication Response SIDService ID for Authentication service Initiate request Authentication0x69MYes
SubFunction =by verifying the
[AuthenticationTask =Certificate and0x02MYes
verifyCertificateBidirectional]generating a Proof of Ownership from the server This parameter returns
authenticationReturnParameterthe result of the procedure on the server.uint8MYes
lengthOfChallengeServerLength parameter for the following challengeuint16MYes
challengeServerSee 3.1.2.1uint8[]MYes
lengthOfCertificateServerLength parameter for the followinguint16MYes
View all 15 rows
FieldDescriptionType/ ValueCvtIncluded in proofOfOwnershipServer
Authentication Response SIDService ID for Authentication service Initiate request Authentication0x69MYes
SubFunction =by verifying the
[AuthenticationTask =Certificate and0x02MYes
verifyCertificateBidirectional]generating a Proof of Ownership from the server This parameter returns
authenticationReturnParameterthe result of the procedure on the server.uint8MYes
lengthOfChallengeServerLength parameter for the following challengeuint16MYes
challengeServerSee 3.1.2.1uint8[]MYes
lengthOfCertificateServerLength parameter for the followinguint16MYes
certificateServerThe Certificate Certificate to verifyuint8[]MYes
lengthOfProofOfOwnershipSerLength parameter for
verthe following Proof of Ownershipuint16MYes
proofOfOwnershipServerSee 3.1.2.2uint8[]MNo
lengthOfEphemeralPublicKeySLength parameter for
erverephemeralPublicKeyS erver.uint16MYes
ephemeralPublicKeyServerSee 3.1.2.3uint8[]MYes

Security protocol or cryptographic context

TableTable 7 – proofOfOwnership Request

3.2.1 Request · page 12 · Linked: AUTH_REQ 110; AUTH_REQ 116; AUTH_REQ 111; AUTH_REQ 113; AUTH_REQ 114; AUTH_REQ 115 (sample: 6 of 8)

Wide table - scrolls horizontally inside this card.

FieldDescriptionType/ValueCvtIncluded in proofOfOwnershipClient
Authentication Request SIDService ID for Authentication service0x29MYes
SubFunction =Verify request the Proof of
[AuthenticationTask =Ownership from the0x03MYes
proofOfOwnership]client This field indicates the
lengthOfProofOfOwnershipClientlength (in octets) of the proofOfOwnershipClient fielduint16MYes
proofOfOwnershipClientSee 3.2.1.1uint8[]MNo
lengthOfEphemeralPublicKeyLength parameter for
ClientephemeralPublicKey Clientuint16MYes
View all 9 rows
FieldDescriptionType/ValueCvtIncluded in proofOfOwnershipClient
Authentication Request SIDService ID for Authentication service0x29MYes
SubFunction =Verify request the Proof of
[AuthenticationTask =Ownership from the0x03MYes
proofOfOwnership]client This field indicates the
lengthOfProofOfOwnershipClientlength (in octets) of the proofOfOwnershipClient fielduint16MYes
proofOfOwnershipClientSee 3.2.1.1uint8[]MNo
lengthOfEphemeralPublicKeyLength parameter for
ClientephemeralPublicKey Clientuint16MYes
ephemeralPublicKeyClientSee 3.2.1.2uint16MYes

Security protocol or cryptographic context

TableTable 8 – proofOfOwnership Response

3.2.2 Response · page 13 · Linked: AUTH_REQ 161; AUTH_REQ 160; AUTH_INFO 142; AUTH_INFO 3; AUTH_INFO 140; AUTH_REQ 162 (sample: 6 of 8)

Wide table - scrolls horizontally inside this card.

FieldDescriptionType/ValueCvtIncluded in sessionKeyInfo
Authentication Response SIDService ID for Authentication service0x69MYes
SubFunction =Verify request the Proof of
[AuthenticationTask =Ownership from the0x03MYes
proofOfOwnership]client. This parameter returns
authenticationReturnParameterthe result of the procedure on the server.uint8MYes
lengthOfSessionKeyInfoSpecifies the length of the field (in octets)uint16MYes
sessionKeyInfoSee 3.2.2.1.1uint8[]MNo

Diagnostic parameter or service behavior

TableTable 9 – deAuthenticate request message layout

3.3.1 Request · page 15 · Linked: AUTH_REQ 96; AUTH_REQ 159; AUTH_INFO 11

FieldDescriptionType/ValueCvt
Authentication Request SIDService ID for Authentication service0x29M
SubFunction = [AuthenticationTask =Subfunction request for request0x00M
deAuthenticate]to leave the

State-machine or transition behavior

TableTable 10 – deAuthenticate response message layout

3.3.2 Response · page 15 · Linked: AUTH_REQ 96; AUTH_INFO 32; AUTH_REQ 159; AUTH_REQ 158; AUTH_REQ 130; AUTH_REQ 131

FieldDescriptionType/ValueCvt
Authentication Response SIDService ID for Authentication service0x69M
SubFunction =Subfunction response for request
[AuthenticationTask =to leave the0x00M
deAuthenticate]authenticated state
returnValue [] =This parameter returns0x00 –
[authenticationReturnParameter]the result of the procedure on the server.0xFFM

State-machine or transition behavior

TableTable 11 – References

4.9 Authentication completion timer · page 27 · Linked: None

Document designationTitle
CVS30X.509
CVS320x84 SecuredDataTranmission
CVS33Entity Management Protocol
CVS34EMP – Basic Entity Definitions Specification
CVS124Traton Specification on Unified diagnostic Services (UDS) requirements
CVS150Requirements on using cryptographic algorithms in the vehicle
CVS151RBAC v2 for diagnostic
ISO 14229-1:2020Road vehicles – Unified diagnostic services (UDS) –Part 1: Application layer
View all 10 rows
Document designationTitle
CVS30X.509
CVS320x84 SecuredDataTranmission
CVS33Entity Management Protocol
CVS34EMP – Basic Entity Definitions Specification
CVS124Traton Specification on Unified diagnostic Services (UDS) requirements
CVS150Requirements on using cryptographic algorithms in the vehicle
CVS151RBAC v2 for diagnostic
ISO 14229-1:2020Road vehicles – Unified diagnostic services (UDS) –Part 1: Application layer
RFC 5280Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile https://datatracker.ietf.org/doc/html/rfc5280
RFC 7748Elliptic Curves for Security

Diagnostic parameter or service behavior

Diagrams (7)

DiagramFigure 1 – Overview of relation between specifications

1.1 Summary · page 4 · Linked: 1.1

Page SnapshotLink confidence: High
Open full size

Diagnostic parameter or service behavior

DiagramFigure 2 – Security concepts (ISO 14229-1:2020)

1.1 Summary · page 5 · Linked: None

Embedded ImageLink confidence: High
Open full size

Security protocol or cryptographic context

DiagramFigure 3 – Client certificate validation logic

4.1 Certificate · page 17 · Linked: AUTH_REQ 9; AUTH_REQ 166; AUTH_REQ 106

Page SnapshotLink confidence: High
Open full size

Security protocol or cryptographic context

DiagramFigure 4 – Overview Ephemeral Diffie-Hellman key-exchange

4.3 SessionKey · page 22 · Linked: AUTH_INFO 146; AUTH_REQ 167; AUTH_REQ 168; AUTH_INFO 26; AUTH_REQ 24; AUTH_REQ 33

Page SnapshotLink confidence: High
Open full size

Diagnostic parameter or service behavior

DiagramFigure 5 – Overview

4.9 Authentication completion timer · page 25 · Linked: AUTH_INFO 36

Page SnapshotLink confidence: High
Open full size

Diagnostic parameter or service behavior

DiagramFigure 6 – Server Handling of Signature

4.9 Authentication completion timer · page 26 · Linked: None

Page SnapshotLink confidence: High
Open full size

Security protocol or cryptographic context

DiagramFigure 7 – Authentication State Transition

4.9 Authentication completion timer · page 28 · Linked: AUTH_REQ 4; AUTH_REQ 159; AUTH_REQ 1; AUTH_REQ 160; AUTH_REQ 2; AUTH_REQ 161

Page SnapshotLink confidence: Medium
Open full size

State-machine or transition behavior

What This PDF Is About

FieldValue
Source PDFCVS31.pdf
Document TypeDiagnostic Standard
DomainKey / Certificate Handling
Scope Summary163 confirmed requirements, 12 needing clarification, 77 information, 2 reference items; 18 linked SSRs; 5 linked open points.
Main ThemesRequirement; System architecture design; System; Cybersecurity concept and evidence; Responsibility and customer approval model (sample: 5 of 8)
Does Not ConfirmCustomer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.
ConfidenceHigh
Evidence BasisMarkdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Critical Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

IDScoreCategoryRequirement / ReasonSupplier Position
RFQX-CVS31-004995High risk due to unclear OEM/supplier responsibilityIf an active authentication state already exists, the server shall replace the existing state with the newly established one.security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivationNeeds Customer Clarification
RFQX-CVS31-009695High risk due to unclear OEM/supplier responsibilityIf content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivationNeeds Customer Clarification
RFQX-CVS31-009995High risk due to unclear OEM/supplier responsibilityIf non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.security relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivationNeeds Customer Clarification
RFQX-CVS31-000881High risk due to unclear OEM/supplier responsibilityShall be agreed between the supplier and the vehicle manufacturer.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-CVS31-000981High risk due to unclear OEM/supplier responsibilityIt contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-CVS31-001081High risk due to unclear OEM/supplier responsibilityIt contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-CVS31-001581High risk due to unclear OEM/supplier responsibilityIf such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
AUTH_REQ 15577High risk due to unclear OEM/supplier responsibilityThe server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
AUTH_REQ 11777High risk due to unclear OEM/supplier responsibilityTable 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
AUTH_REQ 11877High risk due to unclear OEM/supplier responsibilityIf upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
AUTH_REQ 4577High risk due to unclear OEM/supplier responsibilityIf the server verifies the client certificate as valid, the server shall create the requested client authentication pending state.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
AUTH_REQ 17377High risk due to unclear OEM/supplier responsibilityThe server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept

Customer Clarifications / Open Points

Total Open Points5document-linked
P10priority
P20priority
Blocking Conceptyesyes / no
Blocking Estimationyesyes / no
Blocking SSRyesyes / no

Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.

Impact if unresolved: Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.

OpenOpen

Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Impact if unresolved: ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.

OpenOpen

Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.

Impact if unresolved: Update-control scope and evidence ownership stay open; risk of an unprotected update path.

OpenOpen

Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.

Impact if unresolved: Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case.

OpenOpen

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Impact if unresolved: Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.

OpenOpen
Open full open-point table (all fields)

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Open PointPriorityQuestion / ImpactRequired Customer DecisionRecommended Supplier PositionOwnerStatus
OP-002Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Implement configurable session/security-access on the ECU and request the customer-confirmed service-to-role table.Shared (OEM policy / Supplier ECU)Open
OP-003Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.Provide ECU-side secure storage and provisioning hooks; require OEM confirmation of PKI ownership and the provisioning interface.OEM / Customer (PKI) + Supplier (ECU)Open
OP-004Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.Update-control scope and evidence ownership stay open; risk of an unprotected update path.Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.Implement authenticated, integrity-protected ECU programming with controlled boot/app state; require OEM update-chain definition.Shared (OEM backend / Supplier ECU)Open
OP-009Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case.Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.Deliver supplier-owned work products per concept; require a signed DIA/RASIC before treating shared items as supplier scope.OEM / Customer + Supplier (DIA)Open
OP-011Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context.Carry the items as customer-confirmation dependencies and review them in the next clarification workshop.OEM / CustomerOpen

Confirmed requirements (163)

Items carrying a customer requirement ID and a normative (shall/must) statement.

AUTH_REQ 155RFQX-CVS31-0014Requirement3 subFunctionspage 7

The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message.

Partially AcceptOpen point OP-002SSR SSR-RBAC-0061 tables · 0 diagrams
Details & reviewer feedback
Section

Table 4 – Supported subFunctions (ISO 14229-1:2020) Name verifyCertificateBidirectional proofOfOwnership deAuthenticate

Page

page 7

Feature / Interface

Secure communication and freshness protection / None

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 117RFQX-CVS31-0017Requirement3.1.1 Requestpage 8

Table 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running.

Partially AcceptOpen point OP-002SSR SSR-DAI-0011 tables · 0 diagrams
Details & reviewer feedback
Section

3.1.1 Request

Page

page 8

Security capability

Authentication

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 118RFQX-CVS31-0019Requirement3.1.1 Requestpage 8

If upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request.

Partially AcceptOpen point OP-003SSR SSR-KEY-0031 tables · 0 diagrams
Details & reviewer feedback
Section

3.1.1 Request

Page

page 8

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 45RFQX-CVS31-0021Requirement3.1.1 Requestpage 8

If the server verifies the client certificate as valid, the server shall create the requested client authentication pending state.

Partially AcceptOpen point OP-003SSR SSR-DAI-0011 tables · 0 diagrams
Details & reviewer feedback
Section

3.1.1 Request

Page

page 8

Security capability

Authentication

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 173RFQX-CVS31-0027Requirement3.1.2 Responsepage 9

The server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request.

Partially AcceptOpen point OP-003SSR SSR-KEY-003
Details & reviewer feedback
Section

3.1.2 Response

Page

page 9

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 174RFQX-CVS31-0028Requirement3.1.2 Responsepage 9

If the lengthOfCertificateClient value is not within the expected range, the server shall send negative response code 0x13 (incorrectMessageLengthOrInvalidFormat).

Partially AcceptOpen point OP-003SSR SSR-KEY-0031 tables · 0 diagrams
Details & reviewer feedback
Section

3.1.2 Response

Page

page 9

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 121RFQX-CVS31-0036Requirement3.2 proofOfOwnershippage 11

If upon reception of verifyCertificateBidirectional request the Authentication delay timer is running, the server shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x37, indicating requiredTimeDelayNotExpired.

Partially AcceptOpen point OP-003SSR SSR-KEY-003
Details & reviewer feedback
Section

3.1.3 Negative Response

Page

page 11

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 122RFQX-CVS31-0037Requirement3.2 proofOfOwnershippage 11

If the server verifies the client certificate as invalid, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x10, indicating generalReject.

Partially AcceptOpen point OP-003SSR SSR-KEY-001
Details & reviewer feedback
Section

3.2 proofOfOwnership

Page

page 11

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 123RFQX-CVS31-0038Requirement3.2 proofOfOwnershippage 11

If the server fails or cannot determine that the authentication pending state was stored, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

Partially AcceptOpen point OP-003SSR SSR-KEY-003
Details & reviewer feedback
Section

3.2 proofOfOwnership

Page

page 11

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 110RFQX-CVS31-0042Requirement3.2.1 Requestpage 12

Table 7 – proofOfOwnership Request Field Description Type/Value Cvt Included in proofOfOwnershipClient Authentication Request SID Service ID for 0x29 M Yes proofOfOwnership] Verify the Proof of Ownership from the client 0x03 M Yes lengthOfProofOfOwnershipClient This field indicates the length (in octets) of the proofOfOwnershipClient field proofOfOwnershipClient See 3.2.1.1 uint8[] M No lengthOfEphemeralPublicKey Client Length parameter for ephemeralPublicKey Client ephemeralPublicKeyClient See 3.2.1.2 uint16 M Yes The server shall verify whether any existing authentication pending state corresponds to the client submitting the proofOfOwnership request.

Partially AcceptOpen point OP-002SSR SSR-RBAC-0041 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Supplier proposal

Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 126RFQX-CVS31-0060Requirement3.2.3 Negative Responsepage 14

If the server cannot determine if the client does have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

Partially AcceptOpen point OP-004SSR SSR-COM-004
Details & reviewer feedback
Section

3.2.3 Negative Response

Page

page 14

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 128RFQX-CVS31-0062Requirement3.2.3 Negative Responsepage 14

If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server cannot determine that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

Partially AcceptOpen point OP-004SSR SSR-DAI-006
Details & reviewer feedback
Section

3.2.3 Negative Response

Page

page 14

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 129RFQX-CVS31-0063Requirement3.2.3 Negative Responsepage 14

If the server is deleting the authentication pending state as consequence of failure to store the authentication state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

Partially AcceptOpen point OP-004SSR SSR-TOOL-002
Details & reviewer feedback
Section

3.2.3 Negative Response

Page

page 14

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 177RFQX-CVS31-0075Requirement4.1 Certificatepage 16

The server shall use the private key corresponding to the server certificate to generate the signatures.

Partially AcceptOpen point OP-003SSR SSR-KEY-001
Details & reviewer feedback
Section

4.1 Certificate

Page

page 16

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 164RFQX-CVS31-0078Requirement4.1 Certificatepage 16

The server shall reject a received client’s certificate, sent using the verifyCertificateBidirectional subFunction, if it matches the server’s own certificate.

Partially AcceptOpen point OP-003SSR SSR-KEY-001
Details & reviewer feedback
Section

4.1 Certificate

Page

page 16

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 165RFQX-CVS31-0080Requirement4.1 Certificatepage 16

The server shall verify the client certificate, sent using the verifyCertificateBidirectional subFunction, according to Figure 3.

Partially AcceptOpen point OP-003SSR SSR-KEY-001
Details & reviewer feedback
Section

4.1 Certificate

Page

page 16

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 134RFQX-CVS31-0081Requirement4.1 Certificatepage 16

The server shall verify the Signature of the Client certificate using the AUTH-CA EMP entity public key.

Partially AcceptOpen point OP-003SSR SSR-DAI-001
Details & reviewer feedback
Section

4.1 Certificate

Page

page 16

Security capability

Authentication

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 9RFQX-CVS31-0083Requirement4.1.3 D-RBACC extensionpage 18

• If the server NodeUID is not found in the NodeUID extension, the server shall reject the certificate and generate NRC 0x10 (generalReject).

Partially AcceptOpen point OP-003SSR SSR-KEY-0010 tables · 1 diagrams
Details & reviewer feedback
Section

4.1.3 D-RBACC extension

Page

page 18

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0003 Diagram: Figure 3 – Client certificate validation logic page 17
    Security protocol or cryptographic context Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 169RFQX-CVS31-0106Requirement4.1.8 Certificate Validity Timepage 19

The server shall validate the certificate so that: 𝑛𝑜𝑡𝐵𝑒𝑓𝑜𝑟𝑒 ≤ 𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒-𝑡𝑖𝑚𝑒 ≤ 𝑛𝑜𝑡𝐴𝑓𝑡𝑒𝑟

Partially AcceptOpen point OP-003SSR SSR-KEY-001
Details & reviewer feedback
Section

4.1.8 Certificate Validity Time

Page

page 19

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 156RFQX-CVS31-0111Requirement4.2 State-keepingpage 20

If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication pending state.

Partially AcceptOpen point OP-002SSR SSR-DIAG-006
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.

AUTH_REQ 157RFQX-CVS31-0119Requirement4.2 State-keepingpage 20

If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication state.

Partially AcceptOpen point OP-002SSR SSR-DIAG-006
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.

AUTH_REQ 25RFQX-CVS31-0143Requirement4.7.1 TimeBasedPassiveDeAuthenticationpage 23

The server shall always allow the Authentication 0x29 service (ISO 14229-1:2020) regardless of

Partially AcceptOpen point OP-002SSR SSR-RBAC-004
Details & reviewer feedback
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

Supplier proposal

Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.

AUTH_REQ 151RFQX-CVS31-0156Requirement4.9 Authentication completion timerpage 24

If the delay timer is not running, the server shall start it as part of verifyCertificateBidirectional request.

Partially AcceptOpen point OP-003SSR SSR-KEY-003
Details & reviewer feedback
Section

4.9 Authentication completion timer

Page

page 24

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 131RFQX-CVS31-0070Requirement3.3.3 Negative Responsepage 15

If the server cannot determine that the client is currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x94, indicating a ResourceTemporarilyNotAvailable.

Partially AcceptOpen point OP-004SSR SSR-COM-0041 tables · 0 diagrams
Details & reviewer feedback
Section

3.3.3 Negative Response

Page

page 15

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0010 Table: Table 10 – deAuthenticate response message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_REQ 119RFQX-CVS31-0022Requirement3.1.2 Responsepage 9

If an authentication pending state already exists, the server shall replace the existing

Partially AcceptSSR SSR-TOOL-0021 tables · 0 diagrams
Details & reviewer feedback
Section

3.1.2 Response

Page

page 9

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 120RFQX-CVS31-0030Requirement3.1.2 Responsepage 9

Upon positively responding, the server shall start the Authentication completion timer.

Partially AcceptSSR SSR-TOOL-0021 tables · 0 diagrams
Details & reviewer feedback
Section

3.1.2 Response

Page

page 9

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 6RFQX-CVS31-0031Requirement3.1.2 Responsepage 10

The challengeServer field shall consists of 32 octets generated using a CRNG.

Partially AcceptSSR SSR-TOOL-0041 tables · 0 diagrams
Details & reviewer feedback
Section

ephemeralPublicKeyServer See 3.1.2.3 uint8[] M Yes 3.1.2.1 challengeServer

Page

page 10

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 116RFQX-CVS31-0041Requirement3.2.1 Requestpage 12

If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.

Partially AcceptSSR SSR-DAI-0031 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 111RFQX-CVS31-0043Requirement3.2.1 Requestpage 12

If an existing authentication pending state is found, the server shall verify if the Authentication completion timer is currently running.

Partially AcceptSSR SSR-TOOL-0021 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 112RFQX-CVS31-0045Requirement3.2.1 Requestpage 12

If the Authentication completion timer is currently running, the server shall continue to process the client’s proofOfOwnership request.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 113RFQX-CVS31-0046Requirement3.2.1 Requestpage 12

If the client proofOfOwnership signature verification fails, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.

Partially AcceptSSR SSR-DAI-0061 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 114RFQX-CVS31-0047Requirement3.2.1 Requestpage 12

If the server fails or cannot determine that the authentication state was stored, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.

Partially AcceptSSR SSR-COM-0041 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 115RFQX-CVS31-0048Requirement3.2.1 Requestpage 12

If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.

Partially AcceptSSR SSR-DAI-0031 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 124RFQX-CVS31-0058Requirement3.2.3 Negative Responsepage 14

If the server determines that the client does not have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.

Partially AcceptSSR SSR-TOOL-0021 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.3 Negative Response

Page

page 14

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_REQ 125RFQX-CVS31-0059Requirement3.2.3 Negative Responsepage 14

If the server determines that the client have an existing authentication pending state and the Authentication completion timer is expired, the server shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

3.2.3 Negative Response

Page

page 14

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 127RFQX-CVS31-0061Requirement3.2.3 Negative Responsepage 14

If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server determines that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x10, indicating generalReject.

Partially AcceptSSR SSR-DAI-006
Details & reviewer feedback
Section

3.2.3 Negative Response

Page

page 14

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 158RFQX-CVS31-0067Requirement3.3.3 Negative Responsepage 15

The server shall delete/invalidate the client’s authentication prior to positively responding to the deAuthenticate request.

Partially AcceptSSR SSR-TOOL-0021 tables · 0 diagrams
Details & reviewer feedback
Section

0x00 – 0xFF M

Page

page 15

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0010 Table: Table 10 – deAuthenticate response message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_REQ 132RFQX-CVS31-0071Requirement4.1 Certificatepage 16

If the server is unable to delete the client's authentication state or cannot verify its presence, it shall respond to the deAuthenticate request with Negative Response Code (NRC) 0x94,

Partially AcceptSSR SSR-COM-004
Details & reviewer feedback
Section

4.1 Certificate

Page

page 16

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 16RFQX-CVS31-0113Requirement4.2 State-keepingpage 20

If a client and server have successfully completed the authentication process, the server shall invalidate the authentication state in the event of: • The server is reset (i.e server is power cycled).

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 140RFQX-CVS31-0120Requirement4.2 State-keepingpage 20

The server’s authentication pending state shall contain the minimum of (non-exhaustive list): • Client address that issued the authentication request.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 21RFQX-CVS31-0128Requirement4.2 State-keepingpage 21

The server’s authentication state shall contain the minimum of (non-exhaustive list): • SessionKey.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.

AUTH_REQ 149RFQX-CVS31-0133Requirement4.2 State-keepingpage 21

The server shall support only one authentication state.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 150RFQX-CVS31-0134Requirement4.2 State-keepingpage 21

The server shall support only one authentication pending state.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 24RFQX-CVS31-0141Requirement4.5 CRNGpage 22

The server shall ensure that the sessionKey is exclusively used for the application responsible for communication over securedDataTransmission (CVS32).

Partially AcceptSSR SSR-COM-0060 tables · 1 diagrams
Details & reviewer feedback
Section

4.5 CRNG

Page

page 22

Supplier proposal

Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 26RFQX-CVS31-0147Requirement4.7.1 TimeBasedPassiveDeAuthenticationpage 23

The server shall start the timer (A3) after a valid proofOfOwnership has been received.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 28RFQX-CVS31-0151Requirement4.7.1 TimeBasedPassiveDeAuthenticationpage 23

If the A3 timer timeouts before a new request is received (from the same client), the server shall invalidate the authentication state.

Partially AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 152RFQX-CVS31-0157Requirement4.9 Authentication completion timerpage 24

If the server can determine that a delay is not running after reset, it shall accept a subsequent authentication request without any delay.

Partially AcceptSSR SSR-COM-004
Details & reviewer feedback
Section

4.9 Authentication completion timer

Page

page 24

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 153RFQX-CVS31-0158Requirement4.9 Authentication completion timerpage 24

If the server cannot determine that a delay is not running after reset, it shall not accept a subsequent authentication request without any delay.

Partially AcceptSSR SSR-COM-004
Details & reviewer feedback
Section

4.9 Authentication completion timer

Page

page 24

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 14RFQX-CVS31-0093Requirement4.1.3 D-RBACC extensionpage 18

If D-RBACC extension is detected, the server shall overrule the RBACC with the D-RBACC permissions.

Partially AcceptSSR SSR-RBAC-003
Details & reviewer feedback
Section

4.1.3 D-RBACC extension

Page

page 18

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 135RFQX-CVS31-0095Requirement4.1.8 Certificate Validity Timepage 19

• The server shall validate the D-RBACC by parsing all its content. If content is invalid,

Partially AcceptSSR SSR-RBAC-003
Details & reviewer feedback
Section

4.1.8 Certificate Validity Time

Page

page 19

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

AUTH_REQ 136RFQX-CVS31-0098Requirement4.1.8 Certificate Validity Timepage 19

• The server shall verify that the D-RBACC version provided by the client is compatible with the server’s supported D-RBACC version.

Partially AcceptSSR SSR-RBAC-003
Details & reviewer feedback
Section

4.1.8 Certificate Validity Time

Page

page 19

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

1.1RFQX-CVS31-0006Requirement1.1 Summarypage 4

Summary

The purpose of this document is to clarify vehicle manufacture specific extensions and exceptions to the Authentication 0x29 service specified in ISO 14229-1:2020. CVS150 Cryptographic Specification CVS32 SecuredDataTransmis sion 0x84 CVS151 RBAC CVS33 Entity Management Protocol (EMP) CVS31 Authenticate 0x29 CVS124 Traton Specification on Unified diagnostic services (UDS) CVS30 X.509 Specification CVS34 EMP – Basic Entities Figure 1 – Overview of relation between specifications The following documents are normative and indispensable for the application of this document: • Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) • ISO 14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements Whenever a requirement in this specification or the Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) is non-compliant with one or more requirements in ISO 14229-1:2020 the requirements in this specification and (CVS124) take precedence. Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer. It is the vehicle manufacturer that decides if a deviation can be accepted or not. Multiple security concepts are available in the Authentication (ISO 14229-1:2020) service, however, only APCE (ISO 14229-1:2020) is supported by the concept described in this document, see Figure 2.

Accept with AssumptionSSR SSR-RBAC-0010 tables · 1 diagrams
Details & reviewer feedback
Section

1.1 Summary

Page

page 4

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Authentication

Supplier proposal

Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0001 Diagram: Figure 1 – Overview of relation between specifications page 4
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 2RFQX-CVS31-0016Requirement3.1.1 Requestpage 8

The request for verifyCertificateBidirectional subfunction shall be formatted according to

Accept with AssumptionSSR SSR-KEY-0022 tables · 1 diagrams
Details & reviewer feedback
Section

3.1.1 Request

Page

page 8

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 1

  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 172RFQX-CVS31-0026Requirement3.1.2 Responsepage 9

The expected range values of lengthOfCertificateClient shall be from 0x00C8 to 0x0800.

Accept with AssumptionSSR SSR-KEY-002
Details & reviewer feedback
Section

3.1.1.2 lengthOfCertificateClient

Page

page 9

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 5RFQX-CVS31-0029Requirement3.1.2 Responsepage 9

The response for verifyCertificateBidirectional subfunction shall be formatted according to Table 6.

Accept with AssumptionSSR SSR-KEY-0021 tables · 0 diagrams
Details & reviewer feedback
Section

3.1.2 Response

Page

page 9

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 96RFQX-CVS31-0066Requirement3.3.3 Negative Responsepage 15

Table 9 – deAuthenticate request message layout Field Description Type/Value Cvt Authentication Request SID Service ID for 0x29 M SubFunction = [AuthenticationTask = deAuthenticate] Subfunction for request to leave the authenticated state 0x00 M 3.3.2 Response The response for deAuthenticate subfunction shall be formatted according to Table 10.

Accept with AssumptionSSR SSR-RBAC-0042 tables · 0 diagrams
Details & reviewer feedback
Section

3.3.3 Negative Response

Page

page 15

Supplier proposal

Accept with assumption. Implement the ECU-side diagnostic behavior with configurable authorization and verification evidence, subject to customer-confirmed UDS service allocation and role model. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 0

  • TABLE-CVS31-0009 Table: Table 9 – deAuthenticate request message layout page 15
    State-machine or transition behavior Image available: no View artifact
  • TABLE-CVS31-0010 Table: Table 10 – deAuthenticate response message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_REQ 175RFQX-CVS31-0073Requirement4.1 Certificatepage 16

The signature algorithm used throughout the authentication process shall be ED25519.

Accept with AssumptionSSR SSR-DAI-001
Details & reviewer feedback
Section

4 General 4.1 Certificate

Page

page 16

Security capability

Authentication

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 176RFQX-CVS31-0074Requirement4.1 Certificatepage 16

The client shall use the private key corresponding to the client certificate to generate the signatures.

Accept with AssumptionSSR SSR-KEY-001
Details & reviewer feedback
Section

4.1 Certificate

Page

page 16

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 163RFQX-CVS31-0077Requirement4.1 Certificatepage 16

The format and the structure of the certificates shall be based on (CVS30).

Accept with AssumptionSSR SSR-KEY-002
Details & reviewer feedback
Section

4.1 Certificate

Page

page 16

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 170RFQX-CVS31-0088Requirement4.1.3 D-RBACC extensionpage 18

The ECU-Diagnostic role extension shall be included in the client certificate.

Accept with AssumptionSSR SSR-KEY-001
Details & reviewer feedback
Section

4.1.2 ECU-Diagnostic Role extension

Page

page 18

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 15RFQX-CVS31-0101Requirement4.1.8 Certificate Validity Timepage 19

The Key Usage extension (RFC 5280) shall be included in the client certificate.

Accept with AssumptionSSR SSR-KEY-001
Details & reviewer feedback
Section

4.1.5 Key Usage extension

Page

page 19

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 47RFQX-CVS31-0102Requirement4.1.8 Certificate Validity Timepage 19

The Key Usage extension shall contain DigitalSignature.

Accept with AssumptionSSR SSR-KEY-001
Details & reviewer feedback
Section

4.1.8 Certificate Validity Time

Page

page 19

Security capability

Key management

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

AUTH_REQ 95RFQX-CVS31-0103Requirement4.1.8 Certificate Validity Timepage 19

The Extended Key Usage extension (RFC 5280) shall be included in the client certificate.

Accept with AssumptionSSR SSR-KEY-001
Details & reviewer feedback
Section

4.1.6 Extended Key Usage extension

Page

page 19

Security capability

Certificate handling

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

AUTH_REQ 107RFQX-CVS31-0104Requirement4.1.8 Certificate Validity Timepage 19

The extension ExtendedKeyUsage shall contain clientAuth (1.3.6.1.5.5.7.3.2).

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

4.1.8 Certificate Validity Time

Page

page 19

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

AUTH_REQ 167RFQX-CVS31-0137Requirement4.5 CRNGpage 22

The private keys shall be generated using a CRNG.

Accept with AssumptionSSR SSR-KEY-0020 tables · 1 diagrams
Details & reviewer feedback
Section

4.5 CRNG

Page

page 22

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 168RFQX-CVS31-0138Requirement4.5 CRNGpage 22

The sessionKey shall be generated according to the pseudo code below.

Accept with AssumptionSSR SSR-SYS-0010 tables · 1 diagrams
Details & reviewer feedback
Section

4.5 CRNG

Page

page 22

Supplier proposal

Accept with assumption. Implement the ECU-side diagnostic behavior with configurable authorization and verification evidence, subject to customer-confirmed UDS service allocation and role model. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 109RFQX-CVS31-0146Requirement4.7.1 TimeBasedPassiveDeAuthenticationpage 23

Only Passive time-based de-authentication shall be supported.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

AUTH_REQ 154RFQX-CVS31-0160Requirement4.9 Authentication completion timerpage 24

The Authentication completion timer shall be set to 1 minute.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

4.9 Authentication completion timer

Page

page 24

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

AUTH_REQ 19RFQX-CVS31-0116Requirement4.2 State-keepingpage 20

• A new successful authentication is established.

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 20RFQX-CVS31-0117Requirement4.2 State-keepingpage 20

• By passive de-authentication, see 4.7.

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 141RFQX-CVS31-0121Requirement4.2 State-keepingpage 20

• Authentication completion timer.

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 142RFQX-CVS31-0122Requirement4.2 State-keepingpage 20

• Client’s certificate public key

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 144RFQX-CVS31-0123Requirement4.2 State-keepingpage 21

• Client D-RBACC, if provided in the client’s certificate

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 145RFQX-CVS31-0124Requirement4.2 State-keepingpage 21

• Server ephemeral private key

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 22RFQX-CVS31-0129Requirement4.2 State-keepingpage 21

• A3 Timer for passive de-authentication information.

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 23RFQX-CVS31-0130Requirement4.2 State-keepingpage 21

• Client address that issued the authentication request.

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 147RFQX-CVS31-0131Requirement4.2 State-keepingpage 21

• Client roles (ECU diagnostic Role extension in client’s certificate)

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 148RFQX-CVS31-0132Requirement4.2 State-keepingpage 21

• Client D-RBACC, if provided in the client’s certificate

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 168RFQX-CVS31-0201Requirement6 Normative referencespage 29

Added chapter for Certificate validity Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 128RFQX-CVS31-0208Requirement6 Normative referencespage 29

(fails -> failure) Changed Table 7 (EphemeralPublicKeyClient -> ephemeralPublicKeyClient) Removed ambiguity Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 135RFQX-CVS31-0211Requirement6 Normative referencespage 29

Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 157RFQX-CVS31-0242Requirement6 Normative referencespage 30

Changed Table 3 (Authentication pending state and authentication state) Changed Table 5 (Changed column name POO -> proofOfOwnershipServer) Changed Table 6 (Changed column name POO -> proofOfOwnershipServer) Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 171RFQX-CVS31-0244Requirement6 Normative referencespage 30

(Maximum size of elements is to be defined by max size of certificate) Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 108RFQX-CVS31-0246Requirement6 Normative referencespage 30

Added Chapter 2.1.1.2 lengthOfCertificateClient Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 174RFQX-CVS31-0249Requirement6 Normative referencespage 30

Clarified the signature algorithm to be used over the authentication process Removed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 7RFQX-CVS31-0033Requirement3.2 proofOfOwnershippage 11

The proof/signature shall be generated according to the pseudo code below.

Accept with AssumptionSSR SSR-DAI-0081 tables · 0 diagrams
Details & reviewer feedback
Section

3.2 proofOfOwnership

Page

page 11

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 162RFQX-CVS31-0056Requirement3.2.3 Negative Responsepage 14

The signature shall be generated according to the pseudo code below.

Accept with AssumptionSSR SSR-DAI-0081 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.3 Negative Response

Page

page 14

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_REQ 13RFQX-CVS31-0089Requirement4.1.3 D-RBACC extensionpage 18

The roles shall correspond to a bit pattern-octet string.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

4.1.3 D-RBACC extension

Page

page 18

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

AUTH_REQ 105RFQX-CVS31-0105Requirement4.1.8 Certificate Validity Timepage 19

The extension SignatureAlgorithm shall contain ED25519 (1.3.101.112).

Accept with AssumptionSSR SSR-DAI-008
Details & reviewer feedback
Section

4.1.7 SignatureAlgorithm

Page

page 19

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

AUTH_REQ 138RFQX-CVS31-0108Requirement4.2 State-keepingpage 20

• The server is reset (i.e server is power cycled).

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 1RFQX-CVS31-0012Requirement3 subFunctionspage 7

The server shall only support subfunctions in Table 4.

AcceptSSR SSR-TOOL-0022 tables · 1 diagrams
Details & reviewer feedback
Section

3 subFunctions

Page

page 7

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 1

  • TABLE-CVS31-0003 Table: Table 3 – Terms and Definitions page 6
    Security protocol or cryptographic context Image available: no View artifact
  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 3RFQX-CVS31-0024Requirement3.1.2 Responsepage 9

This field shall consists of 32 octets.

AcceptSSR SSR-SYS-001
Details & reviewer feedback
Section

3.1.1.1 challengeClient

Page

page 9

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

AUTH_REQ 4RFQX-CVS31-0025Requirement3.1.2 Responsepage 9

The challengeClient (ISO 14229-1:2020) shall be generated using a CRNG.

AcceptSSR SSR-SYS-002
Details & reviewer feedback
Section

3.1.2 Response

Page

page 9

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

AUTH_REQ 8RFQX-CVS31-0040Requirement3.2.1 Requestpage 12

The request for proofOfOwnership subfunction shall be defined according to Table 7.

AcceptSSR SSR-SYS-0011 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.1 Request

Page

page 12

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 160RFQX-CVS31-0051Requirement3.2.2 Responsepage 13

The proofOfOwnershipClient shall be generated according to the pseudo code below.

AcceptSSR SSR-SYS-0011 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.2 Response

Page

page 13

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_REQ 161RFQX-CVS31-0054Requirement3.2.2 Responsepage 13

The response for proofOfOwnership subfunction shall be according to Table 8.

AcceptSSR SSR-SYS-0011 tables · 0 diagrams
Details & reviewer feedback
Section

3.2.2 Response

Page

page 13

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_REQ 159RFQX-CVS31-0065Requirement3.3.3 Negative Responsepage 15

The request for deAuthenticate subfunction shall be formatted according to Table 9.

AcceptSSR SSR-SYS-0012 tables · 0 diagrams
Details & reviewer feedback
Section

3.3.1 Request

Page

page 15

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 0

  • TABLE-CVS31-0009 Table: Table 9 – deAuthenticate request message layout page 15
    State-machine or transition behavior Image available: no View artifact
  • TABLE-CVS31-0010 Table: Table 10 – deAuthenticate response message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_REQ 130RFQX-CVS31-0068Requirement3.3.3 Negative Responsepage 15

If the server determines that the client is not currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x24, indicating a requestSequenceError.

AcceptSSR SSR-TOOL-0021 tables · 0 diagrams
Details & reviewer feedback
Section

3.3.3 Negative Response

Page

page 15

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0010 Table: Table 10 – deAuthenticate response message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_REQ 106RFQX-CVS31-0084Requirement4.1.3 D-RBACC extensionpage 18

If the NodeUID extension is not detected, the operation shall continue as in

AcceptSSR SSR-SYS-0010 tables · 1 diagrams
Details & reviewer feedback
Section

4.1.3 D-RBACC extension

Page

page 18

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0003 Diagram: Figure 3 – Client certificate validation logic page 17
    Security protocol or cryptographic context Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 42RFQX-CVS31-0100Requirement4.1.8 Certificate Validity Timepage 19

The basicConstraints extension CA field shall be False.

AcceptSSR SSR-SYS-001
Details & reviewer feedback
Section

4.1.4 basicContraints extension

Page

page 19

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

AUTH_REQ 33RFQX-CVS31-0142Requirement4.5 CRNGpage 22

Solution for a CRNG shall be according to (CVS150).

AcceptSSR SSR-SYS-0010 tables · 1 diagrams
Details & reviewer feedback
Section

4.5 CRNG

Page

page 22

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 27RFQX-CVS31-0148Requirement4.7.1 TimeBasedPassiveDeAuthenticationpage 23

The server shall restart the timer (A3) every time a request is received by the same client.

AcceptSSR SSR-TOOL-002
Details & reviewer feedback
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

AUTH_REQ 29RFQX-CVS31-0152Requirement4.7.1 TimeBasedPassiveDeAuthenticationpage 23

The parameter for passive timeout based deAuthenticate shall be decided in the project.

AcceptSSR SSR-SYS-001
Details & reviewer feedback
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

AUTH_REQ 133RFQX-CVS31-0155Requirement4.9 Authentication completion timerpage 24

The delay timer shall be set to 1 second.

AcceptSSR SSR-SYS-001
Details & reviewer feedback
Section

4.9 Authentication completion timer

Page

page 24

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

AUTH_REQ 166RFQX-CVS31-0082Requirement4.1.3 D-RBACC extensionpage 18

• Check if the NodeUID of the server is present in the NodeUIDs extension.

Informational Only0 tables · 1 diagrams
Details & reviewer feedback
Section

4.1.3 D-RBACC extension

Page

page 18

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0003 Diagram: Figure 3 – Client certificate validation logic page 17
    Security protocol or cryptographic context Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 11RFQX-CVS31-0087Requirement4.1.3 D-RBACC extensionpage 18

For the length of NodeUID see (CVS124).

Informational Only
Details & reviewer feedback
Section

4.1.3 D-RBACC extension

Page

page 18

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 143RFQX-CVS31-0109Requirement4.2 State-keepingpage 20

State-keeping

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 139RFQX-CVS31-0110Requirement4.2 State-keepingpage 20

• Power failure.

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 17RFQX-CVS31-0114Requirement4.2 State-keepingpage 20

• Power failure.

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 18RFQX-CVS31-0115Requirement4.2 State-keepingpage 20

• Successful deAuthenticate (see 3.3) subFunction (ISO 14229-1:2020).

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 20

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 146RFQX-CVS31-0125Requirement4.2 State-keepingpage 21

• H0 hash value

Informational Only
Details & reviewer feedback
Section

4.2 State-keeping

Page

page 21

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 167RFQX-CVS31-0162Requirement6 Normative referencespage 29

Informational Only0 tables · 1 diagrams
Details & reviewer feedback
Section

Migrated Req. into

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 169RFQX-CVS31-0163Requirement6 Normative referencespage 29

Informational Only
Details & reviewer feedback
Section

Added

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 4RFQX-CVS31-0166Requirement6 Normative referencespage 29

to

Informational Only0 tables · 1 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 159RFQX-CVS31-0167Requirement6 Normative referencespage 29

Changed tag

Informational Only2 tables · 1 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 1

  • TABLE-CVS31-0009 Table: Table 9 – deAuthenticate request message layout page 15
    State-machine or transition behavior Image available: no View artifact
  • TABLE-CVS31-0010 Table: Table 10 – deAuthenticate response message layout page 15
    State-machine or transition behavior Image available: no View artifact
  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 1RFQX-CVS31-0168Requirement6 Normative referencespage 29

to

Informational Only2 tables · 1 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 1

  • TABLE-CVS31-0003 Table: Table 3 – Terms and Definitions page 6
    Security protocol or cryptographic context Image available: no View artifact
  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 160RFQX-CVS31-0169Requirement6 Normative referencespage 29

Changed tag

Informational Only0 tables · 1 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 2RFQX-CVS31-0170Requirement6 Normative referencespage 29

to

Informational Only1 tables · 1 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 1

  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 161RFQX-CVS31-0171Requirement6 Normative referencespage 29

Changed tag

Informational Only0 tables · 1 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0007 Diagram: Figure 7 – Authentication State Transition page 28
    State-machine or transition behavior Image available: yes View artifact
    Page SnapshotLink confidence: Medium
    Open full size
AUTH_REQ 3RFQX-CVS31-0172Requirement6 Normative referencespage 29

to

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 162RFQX-CVS31-0173Requirement6 Normative referencespage 29

Changed tag

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 5RFQX-CVS31-0174Requirement6 Normative referencespage 29

to

Informational Only1 tables · 0 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 163RFQX-CVS31-0175Requirement6 Normative referencespage 29

Changed tag

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 6RFQX-CVS31-0176Requirement6 Normative referencespage 29

to

Informational Only1 tables · 0 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 164RFQX-CVS31-0177Requirement6 Normative referencespage 29

Changed tag

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 7RFQX-CVS31-0178Requirement6 Normative referencespage 29

to

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 165RFQX-CVS31-0179Requirement6 Normative referencespage 29

Changed tag

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 8RFQX-CVS31-0180Requirement6 Normative referencespage 29

to

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 166RFQX-CVS31-0181Requirement6 Normative referencespage 29

Changed tag

Informational Only0 tables · 1 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0003 Diagram: Figure 3 – Client certificate validation logic page 17
    Security protocol or cryptographic context Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_REQ 12RFQX-CVS31-0182Requirement6 Normative referencespage 29

to

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 170RFQX-CVS31-0183Requirement6 Normative referencespage 29

Changed tag

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 10RFQX-CVS31-0184Requirement6 Normative referencespage 29

to

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 171RFQX-CVS31-0185Requirement6 Normative referencespage 29

Duplicated AUTH_INFO due to typo.

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 167RFQX-CVS31-0200Requirement6 Normative referencespage 29

Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 169RFQX-CVS31-0202Requirement6 Normative referencespage 29

Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 107RFQX-CVS31-0204Requirement6 Normative referencespage 29

Fixed typo Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 127RFQX-CVS31-0207Requirement6 Normative referencespage 29

(fails -> failure) Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 137RFQX-CVS31-0210Requirement6 Normative referencespage 29

since it is covered by

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 29

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 155RFQX-CVS31-0212Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Changed

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 117RFQX-CVS31-0213Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Changed

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 45RFQX-CVS31-0214Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Changed

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 122RFQX-CVS31-0216Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Changed

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 164RFQX-CVS31-0218Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Changed

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 136RFQX-CVS31-0220Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Changed

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 156RFQX-CVS31-0221Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Changed

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 172RFQX-CVS31-0222Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Added

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 173RFQX-CVS31-0223Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Added

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 175RFQX-CVS31-0225Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Added

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 176RFQX-CVS31-0226Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Added

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 177RFQX-CVS31-0227Requirement6 Normative referencespage 30

Informational Only
Details & reviewer feedback
Section

Added

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 1RFQX-CVS31-0230Requirement6 Normative referencespage 30

Reformulation for clarity improvement Changed

Informational Only1 tables · 0 diagrams
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0003 Table: Table 3 – Terms and Definitions page 6
    Security protocol or cryptographic context Image available: no View artifact
AUTH_REQ 155RFQX-CVS31-0231Requirement6 Normative referencespage 30

Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 117RFQX-CVS31-0232Requirement6 Normative referencespage 30

Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 45RFQX-CVS31-0234Requirement6 Normative referencespage 30

Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 122RFQX-CVS31-0236Requirement6 Normative referencespage 30

Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 164RFQX-CVS31-0238Requirement6 Normative referencespage 30

Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 136RFQX-CVS31-0240Requirement6 Normative referencespage 30

Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 156RFQX-CVS31-0241Requirement6 Normative referencespage 30

Changed

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 172RFQX-CVS31-0247Requirement6 Normative referencespage 30

Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 173RFQX-CVS31-0248Requirement6 Normative referencespage 30

Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 175RFQX-CVS31-0251Requirement6 Normative referencespage 30

Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 176RFQX-CVS31-0252Requirement6 Normative referencespage 30

Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

AUTH_REQ 177RFQX-CVS31-0253Requirement6 Normative referencespage 30

Added

Informational Only
Details & reviewer feedback
Section

6 Normative references

Page

page 30

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

Needs customer clarification (12)

Reads like a requirement but no customer requirement ID was identified in the source. Confirm with the customer before baselining — not counted as a confirmed requirement.

RFQX-CVS31-0049Needs Clarification3.2.2 Responsepage 13

If an active authentication state already exists, the server shall replace the existing state with the newly established one.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

3.2.2 Response

Page

page 13

RFQX-CVS31-0096Needs Clarification4.1.8 Certificate Validity Timepage 19

If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.

Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Open point OP-003
Details
Section

4.1.8 Certificate Validity Time

Page

page 19

Security capability

Certificate handling

RFQX-CVS31-0099Needs Clarification4.1.8 Certificate Validity Timepage 19

If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.

Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Open point OP-003
Details
Section

4.1.8 Certificate Validity Time

Page

page 19

Security capability

Certificate handling

RFQX-CVS31-0008Needs Clarification2 Abbrevationspage 6

Shall be agreed between the supplier and the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2 Abbrevations

Page

page 6

Feature / Interface

None / OEM/Customer Review Interface

RFQX-CVS31-0009Needs Clarification2 Abbrevationspage 6

It contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2 Abbrevations

Page

page 6

RFQX-CVS31-0010Needs Clarification2 Abbrevationspage 6

It contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2 Abbrevations

Page

page 6

RFQX-CVS31-0015Needs Clarification3 subFunctionspage 7

If such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response.

Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.

Open point OP-002
Details
Section

3 subFunctions

Page

page 7

Feature / Interface

Secure communication and freshness protection / None

RFQX-CVS31-0001Needs Clarificationpage-1 Page 1page 1

The User shall apply the latest version of this CVS31.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

page-1 Page 1

Page

page 1

RFQX-CVS31-0003Needs Clarificationpage-3 Page 3page 3

Any review of CVS31 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”.

Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.

Open point OP-009
Details
Section

page-3 Page 3

Page

page 3

RFQX-CVS31-0004Needs Clarificationpage-3 Page 3page 3

The whole standard has been reworked and shall be read in its entirety.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

page-3 Page 3

Page

page 3

RFQX-CVS31-0005Needs Clarificationpage-3 Page 3page 3

• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

page-3 Page 3

Page

page 3

RFQX-CVS31-0007Needs Clarification1.1 Summarypage 4

Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

1.1 Summary

Page

page 4

Feature / Interface

None / OEM/Customer Review Interface

Information / descriptive (77)

Descriptive or contextual statements with a customer ID but no binding (shall/must) wording.

RFQX-CVS31-0092Information4.1.3 D-RBACC extensionpage 18

While the ECU-Diagnostic Role extension specifies the roles assigned to a client, the D-RBACC extension may both grant additional permissions and restrict permissions beyond those derived from the client’s roles.

Details
Section

4.1.3 D-RBACC extension

Page

page 18

AUTH_INFO 24RFQX-CVS31-0020Information3.1.1 Requestpage 8

The column “Included in proofOfOwnershipServer”, present in several message-definition tables, indicates whether the corresponding field shall be covered by the proofOfOwnershipServer signature computed by the server and included in its response.

1 tables · 0 diagrams
Details
Section

3.1.1 Request

Page

page 8

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 7RFQX-CVS31-0079Information4.1 Certificatepage 16

It should not be possible to “unlock” the server using its own key/certificate.

Details
Section

4.1 Certificate

Page

page 16

Security capability

Certificate handling

AUTH_INFO 8RFQX-CVS31-0090Information4.1.3 D-RBACC extensionpage 18

The interpretation of the roles should follow as the example below: • Role 1 -> 0000 0000 0000 0000 0000 0000 0000 0001 – 00 00 00 01 • Role 32 -> 1000 0000 0000 0000 0000 0000 0000 0000 – 80 00 00 00 • Role 2 and 4 -> 0000 0000 0000 0000 0000 0000 0000 1010 – 00 00 00 0A.

Details
Section

4.1.3 D-RBACC extension

Page

page 18

AUTH_INFO 61RFQX-CVS31-0094Information4.1.3 D-RBACC extensionpage 18

This means that if D-RBACC logic denies/permits certain access, the server shall deny/permit the access regardless of what RBACC logic permits/denies.

Details
Section

4.1.3 D-RBACC extension

Page

page 18

AUTH_INFO 38RFQX-CVS31-0154Information4.9 Authentication completion timerpage 24

The delay timer represents the required minimum time between verifyCertificateBidirectional

Details
Section

4.9 Authentication completion timer

Page

page 24

AUTH_INFO 30RFQX-CVS31-0018Information3.1.1 Requestpage 8

For details on Authentication delay timer, refer to chapter 4.8.

1 tables · 0 diagrams
Details
Section

3.1.1 Request

Page

page 8

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 27RFQX-CVS31-0023Information3.1.2 Responsepage 9

For details in how to validate a client certificate, refer to chapter 4.1.

1 tables · 0 diagrams
Details
Section

3.1.2 Response

Page

page 9

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0005 Table: Table 5 – verifyCertificateBidirectional Request page 8
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 143RFQX-CVS31-0032Information3.2 proofOfOwnershippage 11

This field consists of a signature that proves to the client that the server has access to the private key of the provided certificateServer (ISO 14229-1:2020). Additionally, the field proves that the same message sent by the client has been received by the server and vice-versa.

1 tables · 0 diagrams
Details
Section

3.2 proofOfOwnership

Page

page 11

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0006 Table: Table 6 – verifyCertificateBidirectional Response page 10
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 60RFQX-CVS31-0034Information3.2 proofOfOwnershippage 11

For obvious reasons, the proofOfOwnershipServer in the VerifyCertificates is not included, in the “concatenation” (see pseudo code above) when the signature/proof is being calculated.

Details
Section

𝐻0 ∶= 𝑆𝐻𝐴512_ℎ𝑎𝑠ℎ(𝑉𝑒𝑟𝑖𝑓𝑦𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒𝑟𝑒𝑞|| 𝑉𝑒𝑟𝑖𝑓𝑦𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒𝑟𝑒𝑠) 𝑃𝑟𝑜𝑜𝑓𝑂𝑓𝑂𝑤𝑛𝑒𝑟𝑠ℎ𝑖𝑝𝑆𝑒𝑟𝑣𝑒𝑟 ∶= 𝑆𝑖𝑔𝑛(𝑆𝑒𝑟𝑣𝑒𝑟𝑃𝑟𝑖𝑣𝑎𝑡𝑒𝐾𝑒𝑦, 𝐻0)

Page

page 11

AUTH_INFO 4RFQX-CVS31-0035Information3.2 proofOfOwnershippage 11

This field provides the client with the necessary server-side data for the chosen key-exchange scheme/algorithm.

Details
Section

3.1.2.3 ephemeralPublicKeyServer

Page

page 11

AUTH_INFO 5RFQX-CVS31-0039Information3.2 proofOfOwnershippage 11

This subfunction (ISO 14229-1:2020) serves several purposes – it proves to the server that the client owns the private key of the provided certificateClient (ISO 14229-1:2020).

Details
Section

3.2 proofOfOwnership

Page

page 11

AUTH_INFO 31RFQX-CVS31-0044Information3.2.1 Requestpage 12

For details on Authentication completion timer, refer to chapter 4.9.

1 tables · 0 diagrams
Details
Section

3.2.1 Request

Page

page 12

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0007 Table: Table 7 – proofOfOwnership Request page 12
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 141RFQX-CVS31-0050Information3.2.2 Responsepage 13

The field proofOfOwnershipClient is a signature that proves to the server that the client has access to the private key of the certificateClient (ISO 14229-1:2020).

Details
Section

3.2.1.1 proofOfOwnershipClient

Page

page 13

AUTH_INFO 142RFQX-CVS31-0052Information3.2.2 Responsepage 13

The reason for the concatenation, is to ensure that the full communication (all sent and received requests and responses) has integrity.

1 tables · 0 diagrams
Details
Section

3.2.2 Response

Page

page 13

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_INFO 3RFQX-CVS31-0053Information3.2.2 Responsepage 13

This field provides the server with the necessary client-side data for the chosen key-exchange scheme/algorithm.

1 tables · 0 diagrams
Details
Section

3.2.1.2 ephemeralPublicKeyClient

Page

page 13

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_INFO 140RFQX-CVS31-0055Information3.2.3 Negative Responsepage 14

The sessionKeyInfo includes a signature that proves to the client that the server has accepted the proofOfOwnership (ISO 14229-1:2020).

1 tables · 0 diagrams
Details
Section

3.2.3 Negative Response

Page

page 14

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_INFO 145RFQX-CVS31-0057Information3.2.3 Negative Responsepage 14

For obvious reasons, the sessionKeyInfo in the ProofOfOwnershipres is not included, in the “concatenation” (see pseudo code above) when the signature is being calculated.

1 tables · 0 diagrams
Details
Section

3.2.3 Negative Response

Page

page 14

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0008 Table: Table 8 – proofOfOwnership Response page 13
    Diagnostic parameter or service behavior Image available: no View artifact
AUTH_INFO 32RFQX-CVS31-0069Information3.3.3 Negative Responsepage 15

The server only responds NRC 0x24 in the case that it can confirm that there is no authentication state connected to the client requesting to deAuthenticate.

1 tables · 0 diagrams
Details
Section

3.3.3 Negative Response

Page

page 15

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0010 Table: Table 10 – deAuthenticate response message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_INFO 133RFQX-CVS31-0072Information4.1 Certificatepage 16

If the server is unable to delete the client’s authentication state or cannot retrieve it due to internal errors, the server responds NRC 0x94.This informs the client that the authentication state may still exist on the server.

Details
Section

4.1 Certificate

Page

page 16

AUTH_INFO 101RFQX-CVS31-0076Information4.1 Certificatepage 16

The signature algorithm in the client, server and authentication CA certificates are ED25519 (1.3.101.112).

Details
Section

4.1 Certificate

Page

page 16

AUTH_INFO 25RFQX-CVS31-0085Information4.1.3 D-RBACC extensionpage 18

A certificate without NodeUID extension implies that the certificate is applicable for any NodeUID.

Details
Section

4.1.3 D-RBACC extension

Page

page 18

AUTH_INFO 100RFQX-CVS31-0086Information4.1.3 D-RBACC extensionpage 18

The maximum number of elements in the list (number of ids) is limited by the maximum size of the certificate.

Details
Section

4.1.3 D-RBACC extension

Page

page 18

AUTH_INFO 9RFQX-CVS31-0091Information4.1.3 D-RBACC extensionpage 18

The D-RBACC extension defines client-specific rules that override the role-based access control configuration in the server.

Details
Section

4.1.3 D-RBACC extension

Page

page 18

AUTH_INFO 33RFQX-CVS31-0097Information4.1.8 Certificate Validity Timepage 19

• Parsing means that the server tries to decode the DER encoded D-RBACC structure, which includes checking the decoded results against the server’s supported/known ASN.1 definition.

Details
Section

4.1.8 Certificate Validity Time

Page

page 19

AUTH_INFO 137RFQX-CVS31-0107Information4.1.8 Certificate Validity Timepage 19

The notBefore and notAfter are received as fields in the certificate while Certificate-Time is the EMP entity defined in CVS34.

Details
Section

4.1.8 Certificate Validity Time

Page

page 19

AUTH_INFO 134RFQX-CVS31-0112Information4.2 State-keepingpage 20

If a request to reset (e.g service 0x11) is received over the service 0x84 (securedDataTransmission) it permits the server to respond before the sessionKey is locked/invalidated.

Details
Section

4.2 State-keeping

Page

page 20

AUTH_INFO 10RFQX-CVS31-0118Information4.2 State-keepingpage 20

Authentication state invalidated by the server implies that any unlocked services and sessionKey is locked/invalidated.

Details
Section

4.2 State-keeping

Page

page 20

AUTH_INFO 34RFQX-CVS31-0126Information4.2 State-keepingpage 21

The server ephemeral private key is the pair of the public key (ephemeralPublicKeyServer) sent as verifyCertificateBidirectional response.

Details
Section

4.2 State-keeping

Page

page 21

AUTH_INFO 35RFQX-CVS31-0127Information4.2 State-keepingpage 21

H0 hash value is calculated as part of proofOfOwnershipServer in verifyCertificateBidirectional response.

Details
Section

4.2 State-keeping

Page

page 21

AUTH_INFO 135RFQX-CVS31-0135Information4.5 CRNGpage 22

The ephemeralPublicKeyClient in the proofOfOwnership-request (from the client) and the ephemeralPublicKeyClient in the verifyCertificate-response (from the server) consists of a Curve25519 [RFC 7748] public key.

Details
Section

4.5 CRNG

Page

page 22

AUTH_INFO 136RFQX-CVS31-0136Information4.5 CRNGpage 22

An overview of the key-exchange process is shown in Figure 4.

Details
Section

4.5 CRNG

Page

page 22

AUTH_INFO 146RFQX-CVS31-0139Information4.5 CRNGpage 22

ephemeralPublicKeyServer) ephemeralPublicKeyServer, ephemeralPrivateKeyServer:= Curve25519() sessionKey := X25519(ephemeralPrivateKeyServer, ephemeralPublicKeyClient) sessionKey := X25519(ephemeralPrivateKeyClient , ephemeralPublicKeyServer) ephemeralPublicKeyClient, ephemeralPrivateKeyClient := Curve25519() ProofOfOwnership(...) VerifyCertificate(...) Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange 4.4 External usage of the sessionKey The sessionKey is used outside the Authentication (ISO 14229-1:2020) service and is run through a key derivation function defined in (CVS32) to derive a key that can be used for securedDataTransmission communication.

0 tables · 1 diagrams
Details
Section

4.5 CRNG

Page

page 22

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_INFO 26RFQX-CVS31-0140Information4.5 CRNGpage 22

The SessionKey is referred as SecuredDataTransmissionKey in (CVS32).

0 tables · 1 diagrams
Details
Section

4.5 CRNG

Page

page 22

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_INFO 12RFQX-CVS31-0144Information4.7.1 TimeBasedPassiveDeAuthenticationpage 23

Example: If the server’s RBACC is for some reason corrupt or misconfigured this would lock out the client from doing diagnostics (the server will refuse all diagnostics).

Details
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

AUTH_INFO 13RFQX-CVS31-0145Information4.7.1 TimeBasedPassiveDeAuthenticationpage 23

Two passive de-authentication mechanisms are described in (ISO 14229-1:2020).

Details
Section

4.7 PassiveDeAuthentication

Page

page 23

AUTH_INFO 147RFQX-CVS31-0149Information4.7.1 TimeBasedPassiveDeAuthenticationpage 23

For this requirement, “same client” refers to a request that originates from the same tester address as the tester currently authenticated by the server.

Details
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

AUTH_INFO 148RFQX-CVS31-0150Information4.7.1 TimeBasedPassiveDeAuthenticationpage 23

When a request is received, authenticated or not, the server upon verifying it is from the same client will restart the timer (A3).

Details
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

AUTH_INFO 36RFQX-CVS31-0159Information4.9 Authentication completion timerpage 24

The Authentication completion timer represents the timeframe that the client is allowed to perform proofOfOwnership request after a verifyCertificateBidirectional request.

0 tables · 1 diagrams
Details
Section

4.9 Authentication completion timer

Page

page 24

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0005 Diagram: Figure 5 – Overview page 25
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_INFO 37RFQX-CVS31-0161Information4.9 Authentication completion timerpage 24

The Authentication completion timer is started upon positive response for verifyCertificateBidirectional request.

Details
Section

4.9 Authentication completion timer

Page

page 24

AUTH_INFO 12RFQX-CVS31-0164Information6 Normative referencespage 29

Removed AUTH_REQ 137 since it is covered by AUTH_REQ 135 Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 146RFQX-CVS31-0197Information6 Normative referencespage 29

Removed Unused reference Fixed wrong cross reference Migrated Annex A “ephemeralPublicKey” into new chapter 3.3 “SessionKey” and added pseudo code for sessionKey Migrated Info into

0 tables · 1 diagrams
Details
Section

6 Normative references

Page

page 29

Related Tables / Diagrams

Linked tables: 0 | Linked diagrams: 1

  • DIAGRAM-CVS31-0004 Diagram: Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange page 22
    Diagnostic parameter or service behavior Image available: yes View artifact
    Page SnapshotLink confidence: High
    Open full size
AUTH_INFO 137RFQX-CVS31-0203Information6 Normative referencespage 29

Added OID for client authentication Changed

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 60RFQX-CVS31-0206Information6 Normative referencespage 29

(VerifyCertificateres -> VerifyCertificates) Changed Table 5 (lengthofCertificateClient -> lengthOfCertificateClient) Changed Table 6 (lengthOfCertitifacteServer -> lengthOfCertificateServer) Changed

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 147RFQX-CVS31-0229Information6 Normative referencespage 30

Updated document quirks chapter Removed the information that italic terms are often clickable.

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 100RFQX-CVS31-0245Information6 Normative referencespage 30

(Maximum size of elements is to be defined by max size of certificate) Updated Figure 3 Reformulation requirements over the length of client certificate Removed

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 101RFQX-CVS31-0254Information6 Normative referencespage 30

2025-08 CVS31 First edition 2025-05-30 RFQ 2517 Delivery Added authentication delay timer Added Authentication Completion timer Clarified negative responses cases for each subfunction

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 14RFQX-CVS31-0153Information4.7.1 TimeBasedPassiveDeAuthenticationpage 23

The A3 timer differs from S3 timer in terms of expected behavior during timeout and should not be implemented as a single timer.

Details
Section

4.7.1 TimeBasedPassiveDeAuthentication

Page

page 23

AUTH_INFO 1RFQX-CVS31-0011Information3 subFunctionspage 7

This section of the document describes vehicle manufacturer specific requirements regarding the behaviour and content of the subFunctions (ISO 14229-1:2020) found in Table 4.

2 tables · 0 diagrams
Details
Section

3 subFunctions

Page

page 7

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 0

  • TABLE-CVS31-0003 Table: Table 3 – Terms and Definitions page 6
    Security protocol or cryptographic context Image available: no View artifact
  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 2RFQX-CVS31-0013Information3 subFunctionspage 7

In this document, each subFunction (ISO 14229-1:2020) is described in its own sub-section.

2 tables · 0 diagrams
Details
Section

3 subFunctions

Page

page 7

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 0

  • TABLE-CVS31-0003 Table: Table 3 – Terms and Definitions page 6
    Security protocol or cryptographic context Image available: no View artifact
  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 11RFQX-CVS31-0064Information3.3.3 Negative Responsepage 15

This chapter specifies the behaviour of the deAuthenticate subfunction.

1 tables · 0 diagrams
Details
Section

3.3.3 Negative Response

Page

page 15

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0009 Table: Table 9 – deAuthenticate request message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_INFO 1RFQX-CVS31-0186Information6 Normative referencespage 29

to

2 tables · 0 diagrams
Details
Section

6 Normative references

Page

page 29

Related Tables / Diagrams

Linked tables: 2 | Linked diagrams: 0

  • TABLE-CVS31-0003 Table: Table 3 – Terms and Definitions page 6
    Security protocol or cryptographic context Image available: no View artifact
  • TABLE-CVS31-0004 Table: Table 4 – Supported subFunctions (ISO 14229-1:2020) page 7
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 141RFQX-CVS31-0187Information6 Normative referencespage 29

Changed tag

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 2RFQX-CVS31-0188Information6 Normative referencespage 29

to

1 tables · 0 diagrams
Details
Section

6 Normative references

Page

page 29

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0003 Table: Table 3 – Terms and Definitions page 6
    Security protocol or cryptographic context Image available: no View artifact
AUTH_INFO 142RFQX-CVS31-0189Information6 Normative referencespage 29

Changed tag

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 3RFQX-CVS31-0190Information6 Normative referencespage 29

to

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 143RFQX-CVS31-0191Information6 Normative referencespage 29

Changed tag

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 4RFQX-CVS31-0192Information6 Normative referencespage 29

to

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 140RFQX-CVS31-0193Information6 Normative referencespage 29

Changed tag

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 5RFQX-CVS31-0194Information6 Normative referencespage 29

to

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 145RFQX-CVS31-0195Information6 Normative referencespage 29

Changed tag

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 11RFQX-CVS31-0196Information6 Normative referencespage 29

to

1 tables · 0 diagrams
Details
Section

6 Normative references

Page

page 29

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-CVS31-0009 Table: Table 9 – deAuthenticate request message layout page 15
    State-machine or transition behavior Image available: no View artifact
AUTH_INFO 135RFQX-CVS31-0198Information6 Normative referencespage 29

Migrated Info into

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 136RFQX-CVS31-0199Information6 Normative referencespage 29

Migrated Req.

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 136RFQX-CVS31-0205Information6 Normative referencespage 29

(Removed “shown in only”) Changed

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 12RFQX-CVS31-0209Information6 Normative referencespage 29

Removed

Details
Section

6 Normative references

Page

page 29

AUTH_INFO 3RFQX-CVS31-0215Information6 Normative referencespage 30

Details
Section

Changed

Page

page 30

AUTH_INFO 5RFQX-CVS31-0217Information6 Normative referencespage 30

Details
Section

Changed

Page

page 30

AUTH_INFO 9RFQX-CVS31-0219Information6 Normative referencespage 30

Details
Section

Changed

Page

page 30

AUTH_INFO 6RFQX-CVS31-0224Information6 Normative referencespage 30

Details
Section

Removed

Page

page 30

AUTH_INFO 147RFQX-CVS31-0228Information6 Normative referencespage 30

and

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 24RFQX-CVS31-0233Information6 Normative referencespage 30

Changed

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 3RFQX-CVS31-0235Information6 Normative referencespage 30

Changed

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 5RFQX-CVS31-0237Information6 Normative referencespage 30

Changed

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 9RFQX-CVS31-0239Information6 Normative referencespage 30

Changed

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 24RFQX-CVS31-0243Information6 Normative referencespage 30

(Changed POO -> proofOfOwnershipServer) Removed

Details
Section

6 Normative references

Page

page 30

AUTH_INFO 6RFQX-CVS31-0250Information6 Normative referencespage 30

Added

Details
Section

6 Normative references

Page

page 30

Reference / document information (2)

Definitions, abbreviations, document history, scope and other boilerplate. Not customer requirements.

RFQX-CVS31-0165Reference6 Normative referencespage 29

Normative references

Annex B (informative) Change history Release Date Changes The whole standard has been reworked and shall be read in its entirety.

Details
Section

6 Normative references

Page

page 29

RFQX-CVS31-0002Referencepage-3 Page 3page 3

Page 3

Foreword This CVS31 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.

Details
Section

page-3 Page 3

Page

page 3

Derived Supplier System Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

SSRStatement / TraceFeatureSecurity CapabilityInterfaceResponsibilityStatusVerification
SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0047; RFQX-CVS31-0060; RFQX-CVS31-0070; RFQX-CVS31-0071; RFQX-CVS31-0157; RFQX-CVS31-0158. Secure Communication and Boundary ControlNoneNoneSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-COM-006Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0141. Secure Communication and Boundary ControlNoneNoneSharedReady for Customer AlignmentReview + Test + table/diagram context review
SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (Cybersecurity domain; allocated to Security Services; security capability: Authentication; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0017; RFQX-CVS31-0021; RFQX-CVS31-0073; RFQX-CVS31-0081. Data Authenticity and Integrity VerificationAuthenticationOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0041; RFQX-CVS31-0048. Data Authenticity and Integrity VerificationNoneNoneSharedReady for Customer AlignmentReview + Test + table/diagram context review
SSR-DAI-006Security evidence and traceability — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Security evidence and traceability data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0046; RFQX-CVS31-0061; RFQX-CVS31-0062. Security evidence and traceabilityNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-DAI-008Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (System domain; allocated to System Core).From this PDF: RFQX-CVS31-0033; RFQX-CVS31-0056; RFQX-CVS31-0105. Data Authenticity and Integrity VerificationNoneNoneSupplier-OwnedCandidateReview + Test + table/diagram context review
SSR-DIAG-006Diagnostic Services — Diagnostic ServicesThe ECU shall provide the diagnostic services for Diagnostic Services required by the allocated customer requirements, including the specified services, sessions and data identifiers (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0111; RFQX-CVS31-0119. Diagnostic ServicesNoneNoneSharedBlocked by Customer ClarificationTest + table/diagram context review
SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (Cybersecurity domain; allocated to Security Services; security capability: Certificate handling; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0037; RFQX-CVS31-0074; RFQX-CVS31-0075; RFQX-CVS31-0078; RFQX-CVS31-0080; RFQX-CVS31-0083; RFQX-CVS31-0088; RFQX-CVS31-0101; RFQX-CVS31-0102; RFQX-CVS31-0103; RFQX-CVS31-0106. Key and Certificate HandlingCertificate handlingOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-KEY-002Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (System domain; allocated to System Core).From this PDF: RFQX-CVS31-0016; RFQX-CVS31-0026; RFQX-CVS31-0029; RFQX-CVS31-0077; RFQX-CVS31-0137. Key and Certificate HandlingNoneNoneSupplier-OwnedCandidateReview + Test + table/diagram context review
SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0019; RFQX-CVS31-0027; RFQX-CVS31-0028; RFQX-CVS31-0036; RFQX-CVS31-0038; RFQX-CVS31-0156. Key and Certificate HandlingNoneNoneSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Cybersecurity domain; allocated to Security Services; security capability: Diagnostic security; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0006. Secure Diagnostics / RBACDiagnostic securityOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (IT / backend domain; allocated to Backend and IT Systems).From this PDF: RFQX-CVS31-0093; RFQX-CVS31-0095; RFQX-CVS31-0098. Secure Diagnostics / RBACNoneNoneSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0042; RFQX-CVS31-0066; RFQX-CVS31-0143. Secure Diagnostics / RBACNoneNoneSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-RBAC-006Secure communication and freshness protection — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure communication and freshness protection, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software).From this PDF: RFQX-CVS31-0014. Secure communication and freshness protectionNoneNoneSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-SYS-001System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (System domain; allocated to System Core; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0024; RFQX-CVS31-0040; RFQX-CVS31-0051; RFQX-CVS31-0054; RFQX-CVS31-0065; RFQX-CVS31-0084; RFQX-CVS31-0089; RFQX-CVS31-0100; RFQX-CVS31-0104; RFQX-CVS31-0138; RFQX-CVS31-0142; RFQX-CVS31-0146; RFQX-CVS31-0152; RFQX-CVS31-0155; RFQX-CVS31-0160. System FunctionNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateTest + table/diagram context review
SSR-SYS-002System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (Process / compliance domain; allocated to Compliance Process; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0025. System FunctionNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateTest + table/diagram context review
SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0012; RFQX-CVS31-0022; RFQX-CVS31-0030; RFQX-CVS31-0043; RFQX-CVS31-0045; RFQX-CVS31-0058; RFQX-CVS31-0059; RFQX-CVS31-0063; RFQX-CVS31-0067; RFQX-CVS31-0068; RFQX-CVS31-0113; RFQX-CVS31-0120; RFQX-CVS31-0128; RFQX-CVS31-0133; RFQX-CVS31-0134; RFQX-CVS31-0147; RFQX-CVS31-0148; RFQX-CVS31-0151. Tooling / IT / Evidence StorageNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-TOOL-004Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (System domain; allocated to System Core; interface: OEM/Customer Review Interface).From this PDF: RFQX-CVS31-0031. Tooling / IT / Evidence StorageNoneOEM/Customer Review InterfaceSharedReady for Customer AlignmentReview + Test + table/diagram context review

System / Security Design Impact

Impact AreaEvidence From This PDF
Impacted system featuresSecure communication and freshness protection; Security evidence and traceability
Impacted interfacesOEM/Customer Review Interface
Impacted security capabilitiesAuthentication; Certificate handling; Key management
Impacted architecture elementsApplication Software; Backend and IT Systems; Backend and IT Systems; OEM/Customer Review Interface; Compliance Process; Security Services; Security Services; OEM/Customer Review Interface; System Core; System Core; OEM/Customer Review Interface
Impacted work productsCybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; Requirement traceability record; System/architecture design
Tools / IT / hardware / testHigh/High/Low; High/High/Medium; High/Low/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium; Medium/High/Low; Medium/High/Medium; Medium/Low/Low; Medium/Low/Medium
Design assumptions introducedSecurity-relevant requirement the ECU can own once responsibility/method is confirmed. Linked source table/diagram context was considered for interpretation.; Security-relevant requirement the ECU can own once responsibility/method is confirmed.
Design decisions requiredConfirm with customer whether this is a binding requirement and assign a customer ID.

Estimation / Resource / Tooling Impact

ImpactStatus
Estimation impactyes
Resource/tool/IT/HW/test impactHigh/High/Low; High/High/Medium; High/Low/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium; Medium/High/Low; Medium/High/Medium; Medium/Low/Low; Medium/Low/Medium

Document Impact Diagram

Document Impact

Generated from document-specific requirement, traceability, SSR, and open-point evidence.

flowchart LR doc["CVS31.pdf"] d0["Authentication"] doc --> d0 d1["Certificate handling"] doc --> d1 d2["Key management"] doc --> d2 f0["Feature: Secure communication and freshness protection"] doc --> f0 f1["Feature: Security evidence and traceability"] doc --> f1 i0["Interface: OEM/Customer Review Interface"] doc --> i0 s0["SSR: SSR-COM-004"] doc --> s0 s1["SSR: SSR-COM-006"] doc --> s1 s2["SSR: SSR-DAI-001"] doc --> s2 o0["Open point: OP-002"] doc --> o0 o1["Open point: OP-003"] doc --> o1 o2["Open point: OP-004"] doc --> o2
Mermaid source
flowchart LR
  doc["CVS31.pdf"]
  d0["Authentication"]
  doc --> d0
  d1["Certificate handling"]
  doc --> d1
  d2["Key management"]
  doc --> d2
  f0["Feature: Secure communication and freshness protection"]
  doc --> f0
  f1["Feature: Security evidence and traceability"]
  doc --> f1
  i0["Interface: OEM/Customer Review Interface"]
  doc --> i0
  s0["SSR: SSR-COM-004"]
  doc --> s0
  s1["SSR: SSR-COM-006"]
  doc --> s1
  s2["SSR: SSR-DAI-001"]
  doc --> s2
  o0["Open point: OP-002"]
  doc --> o0
  o1["Open point: OP-003"]
  doc --> o1
  o2["Open point: OP-004"]
  doc --> o2

Source Traceability

Source document

CVS31.pdf

Document type

Diagnostic Standard

Domain

Key / Certificate Handling

Generated records

163 requirements, 77 information, 18 SSRs

Linked artifacts

11 tables, 7 diagrams

Evidence basis

Markdown-derived requirements and registers; OCR disabled; no downstream PDF analysis

Requirement to SSR Traceability

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Customer RequirementSSRDispositionConfidenceReason
RFQX-CVS31-0001NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0002NoneCovered by Existing Supplier System Requirementn/aAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0003NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0004NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0005NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0006SSR-RBAC-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0007NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0008NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0009NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0010NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0011NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0012SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0013NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0014SSR-RBAC-006Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0015NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0016SSR-KEY-002Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-CVS31-0017SSR-DAI-001Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0018NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0019SSR-KEY-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0020NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0021SSR-DAI-001Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0022SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0023NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0024SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0025SSR-SYS-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0026SSR-KEY-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0027SSR-KEY-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0028SSR-KEY-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0029SSR-KEY-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0030SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0031SSR-TOOL-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0032NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0033SSR-DAI-008Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-CVS31-0034NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0035NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0036SSR-KEY-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0037SSR-KEY-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0038SSR-KEY-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0039NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0040SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0041SSR-DAI-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0042SSR-RBAC-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0043SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0044NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0045SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0046SSR-DAI-006Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0047SSR-COM-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0048SSR-DAI-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0049NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0050NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0051SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0052NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0053NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0054SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0055NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0056SSR-DAI-008Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0057NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0058SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0059SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0060SSR-COM-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0061SSR-DAI-006Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0062SSR-DAI-006Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0063SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0064NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0065SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0066SSR-RBAC-004Covered by Existing Supplier System RequirementLowAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0067SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0068SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0069NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0070SSR-COM-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0071SSR-COM-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0072NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0073SSR-DAI-001Covered by Existing Supplier System RequirementLowAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0074SSR-KEY-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0075SSR-KEY-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0076NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0077SSR-KEY-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0078SSR-KEY-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0079NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0080SSR-KEY-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0081SSR-DAI-001Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0082NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0083SSR-KEY-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0084SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0085NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0086NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0087NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0088SSR-KEY-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0089SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0090NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0091NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0092NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0093SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0094NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0095SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0096NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0097NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0098SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0099NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-CVS31-0100SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0101SSR-KEY-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0102SSR-KEY-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0103SSR-KEY-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0104SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0105SSR-DAI-008Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0106SSR-KEY-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0107NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0108NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0109NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0110NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0111SSR-DIAG-006Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0112NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0113SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0114NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0115NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0116NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0117NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0118NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0119SSR-DIAG-006Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0120SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0121NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0122NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0123NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0124NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0125NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0126NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0127NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0128SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0129NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0130NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0131NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0132NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0133SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0134SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0135NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0136NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0137SSR-KEY-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0138SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0139NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0140NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0141SSR-COM-006Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0142SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0143SSR-RBAC-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0144NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0145NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0146SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0147SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0148SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0149NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0150NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0151SSR-TOOL-002Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0152SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0153NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0154NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0155SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0156SSR-KEY-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0157SSR-COM-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0158SSR-COM-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-CVS31-0159NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0160SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0161NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0162NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0163NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0164NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0165NoneCovered by Existing Supplier System Requirementn/aAccepted requirement; covered by a clustered SSR.
RFQX-CVS31-0166NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0167NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0168NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0169NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0170NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0171NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0172NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0173NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0174NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0175NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0176NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0177NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0178NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0179NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0180NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0181NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0182NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0183NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0184NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0185NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0186NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0187NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0188NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0189NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0190NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0191NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0192NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0193NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0194NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0195NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0196NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0197NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0198NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0199NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0200NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0201NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0202NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0203NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0204NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0205NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0206NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0207NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0208NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0209NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0210NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0211NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0212NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0213NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0214NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0215NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0216NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0217NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0218NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0219NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0220NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0221NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0222NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0223NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0224NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0225NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0226NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0227NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0228NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0229NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0230NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0231NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0232NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0233NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0234NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0235NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0236NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0237NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0238NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0239NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0240NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0241NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0242NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0243NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0244NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0245NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0246NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0247NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0248NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0249NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0250NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0251NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0252NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0253NoneInformational Onlyn/aNon-binding; not derived.
RFQX-CVS31-0254NoneInformational Onlyn/aNon-binding; not derived.

Next Actions

Resolve 5 open clarification point(s) with the customer

Blocks the agreement baseline until confirmed.

Confirm 63 critical requirement(s) with the customer

High impact on concept, design, estimation, or SSR derivation.

Review derived supplier system requirements

Validate allocation, responsibility, and verification intent.

Detailed Evidence

Document intelligence markdown

CVS31

  • Source PDF: CVS31.pdf
  • Converted Markdown: converted/markdown/source document
  • Document type: Diagnostic Standard
  • Domain: Key / Certificate Handling
  • Confidence: High
  • Evidence basis: Markdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Executive Summary

Scope: this diagnostic standard specifies requirement, covering 1 Scope; 1.1 Summary; 2 Abbrevations; 3 subFunctions; 3.1 verifyCertificateBidirectional; 3.1.1 Request. System boundary and interfaces: the document constrains 1 interface(s) - OEM/Customer Review Interface; principal functions in scope are Secure communication and freshness protection; Security evidence and traceability.

Engineering obligations: 163 confirmed customer requirement(s) carry an explicit ID and normative wording and must be implemented and verified; 12 further requirement-like statement(s) have no customer ID and must be clarified before they can be baselined; 77 informational and 2 reference item(s) were separated out as non-binding. Design and security impact: affects Secure communication and freshness protection; Security evidence and traceability; security capabilities touched: Authentication; Certificate handling; Key management; 18 supplier system requirement(s) were derived from this document.

Open for the customer: 5 document-linked open point(s) - mainly Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. (sample: 3 of 5) - plus 12 unidentified requirement-like statement(s). Do not baseline these until the customer confirms. Confidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.

Document Abstract

FieldInterpretation
Document PurposeScope: this diagnostic standard specifies requirement, covering 1 Scope; 1.1 Summary; 2 Abbrevations; 3 subFunctions; 3.1 verifyCertificateBidirectional; 3.1.1 Request.
Engineering InterpretationSystem boundary and interfaces: the document constrains 1 interface(s) - OEM/Customer Review Interface; principal functions in scope are Secure communication and freshness protection; Security evidence and traceability.
Supplier Proposal ImpactEngineering obligations: 163 confirmed customer requirement(s) carry an explicit ID and normative wording and must be implemented and verified; 12 further requirement-like statement(s) have no customer ID and must be clarified before they can be baselined; 77 informational and 2 reference item(s) were separated out as non-binding.
System / Security ImpactDesign and security impact: affects Secure communication and freshness protection; Security evidence and traceability; security capabilities touched: Authentication; Certificate handling; Key management; 18 supplier system requirement(s) were derived from this document.
Customer Clarification ImpactOpen for the customer: 5 document-linked open point(s) - mainly Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. (sample: 3 of 5) - plus 12 unidentified requirement-like statement(s). Do not baseline these until the customer confirms.
Confidence and LimitsConfidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.

Main Requirement Themes

ThemeSummaryRequirement CountRepresentative Requirements
RequirementGroups related document requirements into a single engineering theme.163RFQX-CVS31-0006; RFQX-CVS31-0012; RFQX-CVS31-0014
System architecture designGroups related document requirements into a single engineering theme.148RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004
SystemGroups related document requirements into a single engineering theme.138RFQX-CVS31-0001; RFQX-CVS31-0002; RFQX-CVS31-0004
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.106RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.85RFQX-CVS31-0003; RFQX-CVS31-0005; RFQX-CVS31-0006
InformationGroups related document requirements into a single engineering theme.77RFQX-CVS31-0011; RFQX-CVS31-0013; RFQX-CVS31-0018
Key, certificate, and PKI handlingAffects ECU trust material storage, provisioning, lifecycle ownership, and customer PKI dependencies.72RFQX-CVS31-0006; RFQX-CVS31-0016; RFQX-CVS31-0017
CybersecurityGroups related document requirements into a single engineering theme.41RFQX-CVS31-0006; RFQX-CVS31-0017; RFQX-CVS31-0021

Document Content Structure

SectionRequirementsInformationUnknownExcludedTotal ItemsCriticalOpen PointsSSR Links
1 Scope10002111
-- 1.1 Summary10002111
2 Abbrevations00003310
3 subFunctions4117006029414
-- 3.1 verifyCertificateBidirectional1330016827
-- -- 3.1.1 Request42006323
-- -- 3.1.2 Response910010516
-- 3.2 proofOfOwnership211000321749
-- -- 3.2.1 Request81009716
-- -- 3.2.2 Response23006111
-- -- 3.2.3 Negative Response72009614
-- 3.3 deAuthenticate52007214
-- -- 3.3.3 Negative Response52007214
4 General6227009126212
-- 4.1 Certificate241100371217
-- -- 4.1.3 D-RBACC extension760013213
-- -- 4.1.8 Certificate Validity Time920013514
-- 4.2 State-keeping2340027712
-- 4.5 CRNG44008103
-- 4.7 PassiveDeAuthentication650011313
-- -- 4.7.1 TimeBasedPassiveDeAuthentication650011313
-- 4.9 Authentication completion timer53008313
6 Normative references59330093000

Tables and Diagrams

ArtifactTypeCaptionPageRelated RequirementsImpact
TABLE-CVS31-0001TableTable 1 – Abbreviationspage 6NoneDiagnostic parameter or service behavior
TABLE-CVS31-0002TableTable 2 – Conventionspage 6NoneTable source context
TABLE-CVS31-0003TableTable 3 – Terms and Definitionspage 6RFQX-CVS31-0011; RFQX-CVS31-0012; RFQX-CVS31-0013; RFQX-CVS31-0168; RFQX-CVS31-0186; RFQX-CVS31-0188; RFQX-CVS31-0230Security protocol or cryptographic context
TABLE-CVS31-0004TableTable 4 – Supported subFunctions (ISO 14229-1:2020)page 7RFQX-CVS31-0014; RFQX-CVS31-0011; RFQX-CVS31-0012; RFQX-CVS31-0013; RFQX-CVS31-0016; RFQX-CVS31-0168; RFQX-CVS31-0170; RFQX-CVS31-0186Security protocol or cryptographic context
TABLE-CVS31-0005TableTable 5 – verifyCertificateBidirectional Requestpage 8RFQX-CVS31-0017; RFQX-CVS31-0021; RFQX-CVS31-0016; RFQX-CVS31-0018; RFQX-CVS31-0019; RFQX-CVS31-0020; RFQX-CVS31-0022; RFQX-CVS31-0023Security protocol or cryptographic context
TABLE-CVS31-0006TableTable 6 – verifyCertificateBidirectional Responsepage 10RFQX-CVS31-0029; RFQX-CVS31-0031; RFQX-CVS31-0028; RFQX-CVS31-0030; RFQX-CVS31-0032; RFQX-CVS31-0033; RFQX-CVS31-0174; RFQX-CVS31-0176Security protocol or cryptographic context
TABLE-CVS31-0007TableTable 7 – proofOfOwnership Requestpage 12RFQX-CVS31-0042; RFQX-CVS31-0041; RFQX-CVS31-0043; RFQX-CVS31-0046; RFQX-CVS31-0047; RFQX-CVS31-0048; RFQX-CVS31-0040; RFQX-CVS31-0044Security protocol or cryptographic context
TABLE-CVS31-0008TableTable 8 – proofOfOwnership Responsepage 13RFQX-CVS31-0054; RFQX-CVS31-0051; RFQX-CVS31-0052; RFQX-CVS31-0053; RFQX-CVS31-0055; RFQX-CVS31-0056; RFQX-CVS31-0057; RFQX-CVS31-0058Diagnostic parameter or service behavior
TABLE-CVS31-0009TableTable 9 – deAuthenticate request message layoutpage 15RFQX-CVS31-0066; RFQX-CVS31-0065; RFQX-CVS31-0064; RFQX-CVS31-0167; RFQX-CVS31-0196State-machine or transition behavior
TABLE-CVS31-0010TableTable 10 – deAuthenticate response message layoutpage 15RFQX-CVS31-0066; RFQX-CVS31-0069; RFQX-CVS31-0065; RFQX-CVS31-0067; RFQX-CVS31-0068; RFQX-CVS31-0070; RFQX-CVS31-0167State-machine or transition behavior
TABLE-CVS31-0011TableTable 11 – Referencespage 27NoneDiagnostic parameter or service behavior
DIAGRAM-CVS31-0001DiagramFigure 1 – Overview of relation between specificationspage 4RFQX-CVS31-0006Diagnostic parameter or service behavior
DIAGRAM-CVS31-0002DiagramFigure 2 – Security concepts (ISO 14229-1:2020)page 5NoneSecurity protocol or cryptographic context
DIAGRAM-CVS31-0003DiagramFigure 3 – Client certificate validation logicpage 17RFQX-CVS31-0083; RFQX-CVS31-0082; RFQX-CVS31-0084; RFQX-CVS31-0181Security protocol or cryptographic context
DIAGRAM-CVS31-0004DiagramFigure 4 – Overview Ephemeral Diffie-Hellman key-exchangepage 22RFQX-CVS31-0139; RFQX-CVS31-0137; RFQX-CVS31-0138; RFQX-CVS31-0140; RFQX-CVS31-0141; RFQX-CVS31-0142; RFQX-CVS31-0162; RFQX-CVS31-0197Diagnostic parameter or service behavior
DIAGRAM-CVS31-0005DiagramFigure 5 – Overviewpage 25RFQX-CVS31-0159Diagnostic parameter or service behavior
DIAGRAM-CVS31-0006DiagramFigure 6 – Server Handling of Signaturepage 26NoneSecurity protocol or cryptographic context
DIAGRAM-CVS31-0007DiagramFigure 7 – Authentication State Transitionpage 28RFQX-CVS31-0166; RFQX-CVS31-0167; RFQX-CVS31-0168; RFQX-CVS31-0169; RFQX-CVS31-0170; RFQX-CVS31-0171; RFQX-CVS31-0012; RFQX-CVS31-0016State-machine or transition behavior

What this document does not confirm

Customer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.

Critical Requirements

IDScoreCategoryReasonStatement
RFQX-CVS31-004995High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivationIf an active authentication state already exists, the server shall replace the existing state with the newly established one.
RFQX-CVS31-009695High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivationIf content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.
RFQX-CVS31-009995High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; High estimation impact; blocks SSR derivationIf non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.
RFQX-CVS31-000881High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationShall be agreed between the supplier and the vehicle manufacturer.
RFQX-CVS31-000981High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationIt contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response.
RFQX-CVS31-001081High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationIt contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses.
RFQX-CVS31-001581High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationIf such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response.
RFQX-CVS31-001477High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactThe server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message.
RFQX-CVS31-001777High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactTable 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running.
RFQX-CVS31-001977High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactIf upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request.

Open Points

Open PointPriorityQuestionImpactStatus
OP-002Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.Open
OP-003Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.Open
OP-004Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied.Update-control scope and evidence ownership stay open; risk of an unprotected update path.Open
OP-009Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed.Without an agreed DIA the supplier risks owning customer work products or leaving cybersecurity gaps in the case.Open
OP-011Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.Open

Supplier System Requirements

SSRTitleStatementReqs From This PDFOther PDFsStatus
SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (IT / backend domain; allocated to Backend and IT Systems).RFQX-CVS31-0047; RFQX-CVS31-0060; RFQX-CVS31-0070; RFQX-CVS31-0071; RFQX-CVS31-0157; RFQX-CVS31-0158noBlocked by Customer Clarification
SSR-COM-006Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (Software domain; allocated to Application Software).RFQX-CVS31-0141noReady for Customer Alignment
SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (Cybersecurity domain; allocated to Security Services; security capability: Authentication; interface: OEM/Customer Review Interface).RFQX-CVS31-0017; RFQX-CVS31-0021; RFQX-CVS31-0073; RFQX-CVS31-0081noBlocked by Customer Clarification
SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems).RFQX-CVS31-0041; RFQX-CVS31-0048noReady for Customer Alignment
SSR-DAI-006Security evidence and traceability — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Security evidence and traceability data and reject manipulated or unauthenticated data (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface).RFQX-CVS31-0046; RFQX-CVS31-0061; RFQX-CVS31-0062noBlocked by Customer Clarification
SSR-DAI-008Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (System domain; allocated to System Core).RFQX-CVS31-0033; RFQX-CVS31-0056; RFQX-CVS31-0105noCandidate
SSR-DIAG-006Diagnostic Services — Diagnostic ServicesThe ECU shall provide the diagnostic services for Diagnostic Services required by the allocated customer requirements, including the specified services, sessions and data identifiers (Software domain; allocated to Application Software).RFQX-CVS31-0111; RFQX-CVS31-0119noBlocked by Customer Clarification
SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (Cybersecurity domain; allocated to Security Services; security capability: Certificate handling; interface: OEM/Customer Review Interface).RFQX-CVS31-0037; RFQX-CVS31-0074; RFQX-CVS31-0075; RFQX-CVS31-0078; RFQX-CVS31-0080; RFQX-CVS31-0083; RFQX-CVS31-0088; RFQX-CVS31-0101; RFQX-CVS31-0102; RFQX-CVS31-0103; RFQX-CVS31-0106noBlocked by Customer Clarification
SSR-KEY-002Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (System domain; allocated to System Core).RFQX-CVS31-0016; RFQX-CVS31-0026; RFQX-CVS31-0029; RFQX-CVS31-0077; RFQX-CVS31-0137noCandidate
SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (IT / backend domain; allocated to Backend and IT Systems).RFQX-CVS31-0019; RFQX-CVS31-0027; RFQX-CVS31-0028; RFQX-CVS31-0036; RFQX-CVS31-0038; RFQX-CVS31-0156noBlocked by Customer Clarification
SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Cybersecurity domain; allocated to Security Services; security capability: Diagnostic security; interface: OEM/Customer Review Interface).RFQX-CVS31-0006noBlocked by Customer Clarification
SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (IT / backend domain; allocated to Backend and IT Systems).RFQX-CVS31-0093; RFQX-CVS31-0095; RFQX-CVS31-0098noBlocked by Customer Clarification
SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure Diagnostics / RBAC, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software).RFQX-CVS31-0042; RFQX-CVS31-0066; RFQX-CVS31-0143noBlocked by Customer Clarification
SSR-RBAC-006Secure communication and freshness protection — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Secure communication and freshness protection, restricting security-relevant diagnostic services per the OEM-agreed role model (Software domain; allocated to Application Software).RFQX-CVS31-0014noBlocked by Customer Clarification
SSR-SYS-001System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (System domain; allocated to System Core; interface: OEM/Customer Review Interface).RFQX-CVS31-0024; RFQX-CVS31-0040; RFQX-CVS31-0051; RFQX-CVS31-0054; RFQX-CVS31-0065; RFQX-CVS31-0084; RFQX-CVS31-0089; RFQX-CVS31-0100; RFQX-CVS31-0104; RFQX-CVS31-0138; RFQX-CVS31-0142; RFQX-CVS31-0146; RFQX-CVS31-0152; RFQX-CVS31-0155; RFQX-CVS31-0160noCandidate
SSR-SYS-002System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (Process / compliance domain; allocated to Compliance Process; interface: OEM/Customer Review Interface).RFQX-CVS31-0025noCandidate
SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (IT / backend domain; allocated to Backend and IT Systems; interface: OEM/Customer Review Interface).RFQX-CVS31-0012; RFQX-CVS31-0022; RFQX-CVS31-0030; RFQX-CVS31-0043; RFQX-CVS31-0045; RFQX-CVS31-0058; RFQX-CVS31-0059; RFQX-CVS31-0063; RFQX-CVS31-0067; RFQX-CVS31-0068; RFQX-CVS31-0113; RFQX-CVS31-0120; RFQX-CVS31-0128; RFQX-CVS31-0133; RFQX-CVS31-0134; RFQX-CVS31-0147; RFQX-CVS31-0148; RFQX-CVS31-0151noBlocked by Customer Clarification
SSR-TOOL-004Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Tooling / IT / Evidence Storage (System domain; allocated to System Core; interface: OEM/Customer Review Interface).RFQX-CVS31-0031noReady for Customer Alignment

Design Impact

  • Impacted System Features: Secure communication and freshness protection; Security evidence and traceability
  • Impacted Interfaces: OEM/Customer Review Interface
  • Impacted Security Capabilities: Authentication; Certificate handling; Key management
  • Impacted Architecture Elements: Application Software; Backend and IT Systems; Backend and IT Systems; OEM/Customer Review Interface; Compliance Process; Security Services; Security Services; OEM/Customer Review Interface; System Core; System Core; OEM/Customer Review Interface
  • Impacted Work Products: Cybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; Requirement traceability record; System/architecture design
  • Impacted Document Artifacts: TABLE-CVS31-0003; TABLE-CVS31-0004; TABLE-CVS31-0005; TABLE-CVS31-0006; TABLE-CVS31-0007; TABLE-CVS31-0008; TABLE-CVS31-0009; TABLE-CVS31-0010 (sample: 8 of 13)
  • Impacted Tools It Hardware Test: High/High/Low; High/High/Medium; High/Low/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium (sample: 8 of 12)
  • Impacted Supplier System Requirements: SSR-COM-004; SSR-COM-006; SSR-DAI-001; SSR-DAI-003; SSR-DAI-006; SSR-DAI-008; SSR-DIAG-006; SSR-KEY-001 (sample: 8 of 18)
  • Design Assumptions Introduced: Security-relevant requirement the ECU can own once responsibility/method is confirmed. Linked source table/diagram context was considered for interpretation.; Security-relevant requirement the ECU can own once responsibility/method is confirmed.
  • Design Decisions Required: Confirm with customer whether this is a binding requirement and assign a customer ID.