Detailed Feature Model
This feature model groups Markdown-derived requirement clusters into system-security architecture domains. It is not a flat requirement repeat.
Core Product Capabilities
Classification: Needs Customer Clarification
No feature cluster is confirmed in the current requirements. Customer clarification is needed.
Vehicle/ECU Integration Capabilities
Classification: Needs Customer Clarification
No feature cluster is confirmed in the current requirements. Customer clarification is needed.
Communication and Connectivity Capabilities
Feature: Secure communication and freshness protection
Feature ID: FEAT-X001
Purpose
Protect vehicle or client/server data exchanges against unauthorized origin, modification, replay, and stale state.
User/System Value
Turns SecOC/SDT-style requirements into a coherent communication security behavior.
Requirement Basis
- Related requirements: RFQX-CVS123-2-0241; RFQX-CVS154-0036; RFQX-CVS31-0014; RFQX-CVS31-0015; RFQX-CVS32-0007; RFQX-CVS32-0009; RFQX-CVS32-0012; RFQX-CVS32-0014; RFQX-CVS32-0016; RFQX-CVS32-0019; RFQX-CVS32-0021; RFQX-CVS32-0025; RFQX-CVS32-0026; RFQX-CVS32-0027; RFQX-CVS32-0028; RFQX-CVS32-0029; RFQX-CVS32-0030; RFQX-CVS32-0031 (sample: 18 of 201)
- Source document sections: source document page 29; source document page 10; source document page 7; source document page 4; source document page 6; source document page 7; source document page 8; source document page 9(sample: 8 of 27)
Functional Scope
Authentication/encryption, verify/decrypt processing, counters, replay checks, and discard behavior for invalid traffic.
Out of Scope / Not Confirmed
Exact algorithms, key lengths, message IDs, and bus allocation need customer confirmation.
Interfaces Involved
Vehicle network, ECU-to-ECU communication, client/server SDT flows.
Data Handled
Protected signals, counters, request/response payloads, authentication tags.
Security Relevance
This feature directly protects integrity, authenticity, freshness, and in some cases confidentiality of vehicle data.
- Secure communication
- Cryptographic protection
- Key management
Impacted Architecture Elements
- External Interfaces
- Security Services
- Application Software
Confidence Level
Low
Classification
Inferred from Requirements
Open Questions
- Confirm whether this statement is a binding requirement.
Evidence Basis:
- Related requirements: RFQX-CVS123-2-0241; RFQX-CVS154-0036; RFQX-CVS31-0014; RFQX-CVS31-0015; RFQX-CVS32-0007; RFQX-CVS32-0009; RFQX-CVS32-0012; RFQX-CVS32-0014; RFQX-CVS32-0016; RFQX-CVS32-0019 (sample: 10 of 201)
- Source document: source document page 29; source document page 10; source document page 7; source document page 4; source document page 6; source document page 7; source document page 8; source document page 9(sample: 8 of 27)
- Confidence level: Low
- Classification: Inferred from Requirements
Diagnostic and Maintenance Capabilities
Classification: Needs Customer Clarification
No feature cluster is confirmed in the current requirements. Customer clarification is needed.
Cybersecurity Capabilities
Classification: Needs Customer Clarification
No feature cluster is confirmed in the current requirements. Customer clarification is needed.
Classification: Needs Customer Clarification
No feature cluster is confirmed in the current requirements. Customer clarification is needed.
Operational and Lifecycle Capabilities
Feature: Secure software update and flash readiness
Feature ID: FEAT-X002
Purpose
Ensure software update, flash, and IVD-related flows preserve authenticity, integrity, and regulatory evidence.
User/System Value
Supports UNECE-style software update obligations and safe maintenance of E/E components.
Requirement Basis
- Related requirements: RFQX-3299216-1-0176; RFQX-CVS123-2-0023; RFQX-CVS123-2-0030; RFQX-CVS123-2-0037; RFQX-CVS123-2-0039; RFQX-CVS123-2-0042; RFQX-CVS123-2-0043; RFQX-CVS123-2-0048; RFQX-CVS123-2-0049; RFQX-CVS123-2-0050; RFQX-CVS123-2-0062; RFQX-CVS123-2-0064; RFQX-CVS123-2-0065; RFQX-CVS123-2-0067; RFQX-CVS123-2-0070; RFQX-CVS123-2-0071; RFQX-CVS123-2-0072; RFQX-CVS123-2-0078 (sample: 18 of 131)
- Source document sections: source document page 34; source document page 6; source document page 7; source document page 9; source document page 10; source document page 11; source document page 12; source document page 20(sample: 8 of 56)
Functional Scope
Update package handling, flash/programming paths, integrity validation data, and update evidence.
Out of Scope / Not Confirmed
Update transport, campaign management, rollback policy, and production signing chain need confirmation.
Interfaces Involved
Backend/update infrastructure, diagnostic/programming tool, ECU boot/update manager, PKI.
Data Handled
Software packages, signatures, IVD data, certificates, programming requests, update logs.
Security Relevance
Unauthorized or corrupted software undermines ECU authenticity and all data security goals.
- Secure software update
- Secure boot and platform integrity
- Key and certificate management
Impacted Architecture Elements
- Backend and IT Systems
- Security Services
- Hardware Platform
Confidence Level
Low
Classification
Inferred from Requirements
Open Questions
- Confirm whether this statement is a binding requirement.
Evidence Basis:
- Related requirements: RFQX-3299216-1-0176; RFQX-CVS123-2-0023; RFQX-CVS123-2-0030; RFQX-CVS123-2-0037; RFQX-CVS123-2-0039; RFQX-CVS123-2-0042; RFQX-CVS123-2-0043; RFQX-CVS123-2-0048; RFQX-CVS123-2-0049; RFQX-CVS123-2-0050 (sample: 10 of 131)
- Source document: source document page 34; source document page 6; source document page 7; source document page 9; source document page 10; source document page 11; source document page 12; source document page 20(sample: 8 of 56)
- Confidence level: Low
- Classification: Inferred from Requirements
Compliance and Evidence Capabilities
Feature: Security evidence and traceability
Feature ID: FEAT-X003
Purpose
Provide proof that requirements, controls, architecture decisions, verification, validation, and residual risk remain connected.
User/System Value
Gives reviewers a way to audit security decisions before accepting the architecture.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0021; RFQX-3299216-1-0018; RFQX-3299216-1-0109; RFQX-3299216-1-0134; RFQX-3299216-1-0286; RFQX-3299216-1-0288; RFQX-CVS123-2-0049; RFQX-CVS123-2-0067; RFQX-CVS123-2-0207; RFQX-CVS123-2-0216; RFQX-CVS123-2-0217 (sample: 18 of 59)
- Source document sections: source document page 3; source document page 5; source document page 6; source document page 5; source document page 23; source document page 27; source document page 50; source document page 10(sample: 8 of 34)
Functional Scope
Traceability matrices, evidence reports, human-review queues, quality gates, and open decisions.
Out of Scope / Not Confirmed
Customer acceptance workflow and evidence repository ownership are not confirmed.
Interfaces Involved
ALM/evidence repository, OEM/customer review, supplier security process.
Data Handled
Requirement IDs, source sections, controls, test reports, decisions, open questions.
Security Relevance
Without evidence traceability, control implementation cannot be credibly argued.
- Compliance and evidence management
- Development and toolchain security
Impacted Architecture Elements
- Compliance Process
- Engineering Toolchain
Confidence Level
Medium
Classification
Inferred from Requirements
Open Questions
- Confirm whether this statement is a binding requirement.
- Review possible noise/boilerplate contamination.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0021; RFQX-3299216-1-0018; RFQX-3299216-1-0109 (sample: 10 of 59)
- Source document: source document page 3; source document page 5; source document page 6; source document page 5; source document page 23; source document page 27; source document page 50; source document page 10(sample: 8 of 34)
- Confidence level: Medium
- Classification: Inferred from Requirements