INCOSE Requirements Analysis

GtWR v4 analysis of the customer requirements and freshly authored, traceable system requirements — ready for Jira import.

Generated 2026-07-14 · INCOSE GtWR v4 / NRM v2 · writer+verifier agents
SESystems EngineeringINCOSE

INCOSE Requirements Analysis

System of Interest: ECA (Electronic Clutch Actuator) · Project P112478. Customer requirements analysed against INCOSE GtWR v4; stakeholder needs and system requirements derived per the NRM transformation and Carson patterns, authored and independently verified by sub-agents.

918 customer requirements → 202 stakeholder needs → 1077 traceable system requirements

Every customer statement is checked verbatim against the 18 compulsory GtWR rules, abstracted into stakeholder needs, then refined into ECA-level system requirements that carry the specific obligation. Quantitative values come only from the customer sources — none are invented.

Customer Requirements918testable, analysed
GtWR Compliant (customer)28731% of customer set
Stakeholder Needs202all compliant
System Requirements1077authored + verified
SSR GtWR-Compliant688/107764% compliant
Needs Clarification66source truncated / non-normative
Managed Unknowns196TBD, not invented
Traceability Gaps0orphans / childless

Method & standards

Analysis follows the INCOSE Guide to Writing Requirements v4 (rules R1–R42, characteristics C1–C15), the Needs & Requirements Manual v2 transformation flow, and the Carson requirement patterns (Functional/Performance, Suitability, Environment, Design). Customer statements are the RFQX extracted set from the customer RFQ (1001379436) and referenced specifications (3299216_1, CVS31/32/123-2/124/151/154). Each customer requirement is refined into one or more ECA-level system requirements that restate its specific obligation, authored and independently checked by writer and verifier sub-agents. Where the customer states no measurable target, the value is recorded as a managed unknown (TBD/TBC) rather than invented.

Customer set — GtWR rule compliance

RuleNameNon-compliantCompliantSet verdict
R1Structured Statements117801117 flagged
R2Active Voice131787131 flagged
R5Definite Articles2489424 flagged
R7Vague Terms3388533 flagged
R8Escape Clauses49144 flagged
R9Open-Ended Clauses1090810 flagged
R10Superfluous Infinitives1890018 flagged
R16Use of 'Not'121797121 flagged
R17Oblique Symbol7284672 flagged
R18Single-Thought Sentence4887048 flagged
R19Combinators256662256 flagged
R20Purpose Phrases1790117 flagged
R21Parentheses206712206 flagged
R24Pronouns5086850 flagged
R26Absolutes8183781 flagged
R32Universal Qualification106812106 flagged
R34Measurable Performance4387543 flagged
R35Temporal Dependencies19171 flagged

Customer requirements (918)

IDCustomer IDAreaCategoryPrioGtWRViolatedStatement (verbatim)
CR-CYBER-0001CYBERDesign constraintLowNON-COMPLIANTR9The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybe rsecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc.
CR-CYBER-0002REQ_SEC_0001CYBERDesign constraintLowNON-COMPLIANTR19The supplier shall provide documentation describing their strategies and methods for working with embedded systems cybersecurity.
CR-CYBER-0003REQ_SEC_0002CYBERDesign constraintMediumNON-COMPLIANTR19The supplier shall perform risk assessment based on a threat and vulnerability analysis for each release, including any vehicle manufacturer-specific adaptations.
CR-SYS-0001SYSDesign constraintMediumNON-COMPLIANTR19Method and scope shall be proposed to and approved by the vehicle manufacturer.
CR-VAL-0001VALDesign constraintLowNON-COMPLIANTR19Documentation on the method and results shall be provided to the vehicle manufacturer.
CR-CYBER-0004REQ_SEC_0003CYBERDesign constraintLowNON-COMPLIANTR19The supplier shall describe the cybersecurity concept and how it is implemented in hardware and software respectively.
CR-CYBER-0005REQ_SEC_0022CYBERDesign constraintLowNON-COMPLIANTR26R32All risks identified in cybersecurity risk analyses shall be evaluated.
CR-CYBER-0006CYBERDesign constraintLowCOMPLIANTFor each risk identified in the cybersecurity risk analyses, a risk treatment decision shall be made to avoid, reduce, share, or retain the risk.
CR-CYBER-0007REQ_SEC_0023CYBERDesign constraintLowCOMPLIANTCybersecurity controls shall sufficiently reduce the risk.
CR-CYBER-0008CYBERDesign constraintLowNON-COMPLIANTR24It shall be possible to verify which cybersecurity controls were derived from which requirements.
CR-CYBER-0009REQ_SEC_0024CYBERDesign constraintHighNON-COMPLIANTR19The cybersecurity concept of the supplier shall contain a documentation of the accepted residual risk and be agreed with the vehicle manufacturer.
CR-CYBER-0010REQ_SEC_0004CYBERDesign constraintLowNON-COMPLIANTR19The supplier shall provide documentation of the verification and validation methods of cybersecurity features.
CR-CYBER-0011REQ_SEC_0005CYBERDesign constraintLowNON-COMPLIANTR19The supplier shall provide test reports detailing the results from the verification and validation of cybersecurity features.
CR-CYBER-0012REQ_SEC_0040CYBERDesign constraintHighNON-COMPLIANTR1R2The vehicle manufacturer reserves the right to perform penetration testing on the ECU to identify potential vulnerabilities.
CR-SYS-0002REQ_SEC_0007SYSDesign constraintLowNON-COMPLIANTR2R5R19An inventory of software and protocols, including their versions, shall be provided by the supplier.
CR-HW-0001REQ_SEC_0025HWDesign constraintLowNON-COMPLIANTR2R5R19A BOM containing part numbers and versions of hardware components used in the product shall be provided by the supplier.
CR-VAL-0002REQ_SEC_0041VALDesign constraintMediumNON-COMPLIANTR1R2R19The vehicle manufacturer reserves the right to request documentation and evidence as well as to perform or order a compliance audit to determine whether the listed requirements are fulfilled.
CR-CYBER-0013REQ_SEC_0042CYBERDesign constraintMediumNON-COMPLIANTR19The vehicle manufacturer and the supplier shall set up a cybersecurity DIA to agree on the responsibilities for the distributed cybersecurity activities.
CR-CYBER-0014REQ_SEC_0008CYBERDesign constraintMediumNON-COMPLIANTR10R19R34The ECU shall be able to verify integrity and authenticity of a vehicle manufacturer-specified set of data stored within the ECU.
CR-SYS-0003SYSDesign constraintMediumNON-COMPLIANTR19Methods shall be proposed to and approved by the vehicle manufacturer.
CR-CYBER-0015REQ_SEC_0009CYBERDesign constraintLowNON-COMPLIANTR17R19The supplier shall apply methods for isolation of software/hardware components and data to reduce the effect in case of a cybersecurity breach.
CR-SYS-0004REQ_SEC_0020SYSDesign constraintLowNON-COMPLIANTR19Selection of cryptographic methods and their use shall be agreed upon between the vehicle manufacturer and the supplier.
CR-SYS-0005REQ_SEC_0010SYSDesign constraintLowNON-COMPLIANTR26R32All network services implemented in the ECU shall undergo hardening.
CR-SYS-0006REQ_SEC_0011SYSDesign constraintLowNON-COMPLIANTR19The ECU shall only expose network and communication services that have been agreed upon with the vehicle manufacturer.
CR-MECH-0001REQ_SEC_0012MECHDesign constraintLowNON-COMPLIANTR17Communication interfaces shall use boundary controls such as ingress/egress filtering.
CR-SYS-0007REQ_SEC_0013SYSDesign constraintLowCOMPLIANTCommunication boundary controls shall be configurable by the vehicle manufacturer.
CR-SYS-0008SYSDesign constraintLowNON-COMPLIANTR19Methods shall be proposed and approved by the vehicle manufacturer.
CR-SYS-0009REQ_SEC_0014SYSDesign constraintLowNON-COMPLIANTR19R32Any interfaces used for development purposes shall be removed or disabled in series production.
CR-SYS-0010SYSDesign constraintLowNON-COMPLIANTR19The details shall be agreed upon between the vehicle manufacturer and the supplier.
CR-HW-0002REQ_SEC_0026HWDesign constraintLowNON-COMPLIANTR19Only hardware interfaces and protocols specified by the vehicle manufacturer shall be available in series production.
CR-CYBER-0016REQ_SEC_0027CYBERDesign constraintLowNON-COMPLIANTR24It shall be possible for the vehicle manufacturer to securely inject data into the product in accordance with the specification provided by the vehicle manufacturer.
CR-SYS-0011REQ_SEC_0028SYSDesign constraintLowCOMPLIANTData specified by the vehicle manufacturer shall be protected from manipulations.
CR-SYS-0012REQ_SEC_0029SYSDesign constraintLowCOMPLIANTData specified by the vehicle manufacturer shall be protected from disclosure.
CR-SYS-0013REQ_SEC_0006SYSDesign constraintLowCOMPLIANTIntellectual property of the vehicle manufacturer shall be protected from disclosure.
CR-CYBER-0017REQ_SEC_0016CYBERDesign constraintHighNON-COMPLIANTR19R24It shall be possible for the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECU according to the specification of the vehicle manufacturer.
CR-CYBER-0018REQ_SEC_0019CYBERDesign constraintMediumCOMPLIANTSecrets, public keys and other data used for cybersecurity controls in production vehicle systems shall be different from those used in pre-production phases.
CR-SYS-0014REQ_SEC_0021SYSDesign constraintLowNON-COMPLIANTR19ECUs shall only contain the secrets agreed between the vehicle manufacturer and the supplier.
CR-CYBER-0019REQ_SEC_0015CYBERDesign constraintLowCOMPLIANTECUs shall conform to the harmonized Security Access specification [1] provided by the vehicle manufacturer.
CR-CYBER-0020REQ_SEC_0043CYBERDesign constraintLowNON-COMPLIANTR24It shall be possible to update the software of the ECU.
CR-CYBER-0021REQ_SEC_0030CYBERDesign constraintLowNON-COMPLIANTR32The supplier shall inform the vehicle manufacturer if any cybersecurity patches are available.
CR-CYBER-0022REQ_SEC_0044CYBERDesign constraintMediumNON-COMPLIANTR5R19An incident response process shall be proposed to and approved by the vehicle manufacturer.
CR-CYBER-0023REQ_SEC_0045CYBERDesign constraintLowCOMPLIANTIn case of cybersecurity incidents, the incident response process shall be used.
CR-CYBER-0024REQ_SEC_0046CYBERDesign constraintLowCOMPLIANTThe incident response process shall be maintained for the entire product lifetime.
CR-CYBER-0025REQ_SEC_0032CYBERDesign constraintLowCOMPLIANTThe incident response process shall ensure that risk is managed in coordination with the vehicle manufacturer.
CR-CYBER-0026REQ_SEC_0033CYBERDesign constraintLowNON-COMPLIANTR32Any vulnerabilities that are identified during product lifecycle shall be promptly communicated to the vehicle manufacturer.
CR-VAL-0003VALDesign constraintLowNON-COMPLIANTR17The report shall include information needed to identify the affected vehicles/products.
CR-SYS-0015SYSDesign constraintMediumNON-COMPLIANTR7R19Methods including the stipulation of a reasonable notification time shall be proposed to and approved by the vehicle manufacturer.
CR-CYBER-0027REQ_SEC_0034CYBERDesign constraintLowCOMPLIANTFollowing each identified and reported vulnerability, the supplier and vehicle manufacturer shall agree on an initial response to the vulnerability.
CR-CYBER-0028REQ_SEC_0035CYBERDesign constraintLowNON-COMPLIANTR7R34Within adequate time after the initial vulnerability report, the supplier shall provide more information about the identified vulnerability.
CR-CYBER-0029CYBERDesign constraintLowNON-COMPLIANTR19The information shall contain • the version(s) of affected hardware or software components, • nature of the vulnerability, • description of the affected cybersecurity goal, • technical conditions to exploit the vulnerability, • impact of the exploitation and • possibilities to remove the vulnerability.
CR-VAL-0004VALDesign constraintMediumNON-COMPLIANTR7R19Methods including the stipulation of a reasonable reporting time shall be proposed to and approved by the vehicle manufacturer.
CR-SYS-0016REQ_SEC_0036SYSDesign constraintLowCOMPLIANTThe supplier shall have a method for monitoring available vulnerability databases for vulnerabilities that can affect the delivered product.
CR-CYBER-0030REQ_SEC_0037CYBERDesign constraintLowNON-COMPLIANTR19R26R32Identified vulnerabilities shall be considered in all current development projects or projects under field monitoring.
CR-HW-0003REQ_SEC_0047HWDesign constraintLowNON-COMPLIANTR5An ECU returned from field shall allow for field-return analysis.
CR-SYS-0017REQ_SEC_0048SYSDesign constraintLowNON-COMPLIANTR16Field-return analysis secrets shall not be operational in the field.
CR-HW-0004REQ_SEC_0049HWDesign constraintLowNON-COMPLIANTR5R16An ECU enabled for field-return analysis shall not be possible to use as a spare part.
CR-HW-0005REQ_SEC_0050HWDesign constraintLowNON-COMPLIANTR26R32All secrets specified by the vehicle manufacturer shall be protected throughout the lifecycle of the ECU.
CR-SYS-0018SYSDesign constraintLowNON-COMPLIANTR19End-of-life and decommissioning shall be specifically considered.
CR-HW-0006HWDesign constraintLowNON-COMPLIANTR16Notes: a) It shall not be possible for a third party to reuse an ECU without system support from the vehicle manufacturer.
CR-CYBER-0031CYBERDesign constraintLowNON-COMPLIANTR16R19b) Decommissioning of an ECU shall not have the potential of causing unacceptable risk to the road user or the vehicle manufacturer.
CR-CYBER-0032REQ_SEC_0051CYBERDesign constraintLowNON-COMPLIANTR19Security related events shall be identified and logged.
CR-SYS-0019SYSDesign constraintHighNON-COMPLIANTR18R19R26R32The gearbox itself shall be used in all drivetrains and the ECA shall be common and must be complaint to be put on any driveline setup.
CR-SYS-00202.1SYSFunctionalLowCOMPLIANTThe clutch actuator shall be electrically driven
CR-SYS-00212.3SYSFunctionalMediumNON-COMPLIANTR1R2R19R21The ECA (Electric Clutch Actuator) must have its own internal ECU for manoeuvring and error handling.
CR-MECH-00022.6MECHDesign constraintMediumNON-COMPLIANTR16R18R21The ECA units shall be manufactured with marking variants according to the requirements in Scania STD19 (Ref 14.17). The variant type shall be based on delivery agreement and Brand involved. Variant 1: For Scania units, wordmark variant C1 Part number (7 digits). Variant 2: For MAN units, wordmark variant Z1. Part number (13 digits). Variant 3: For International units, wordmark variant X1. Part number (8 digits) Variant 4 Tentik wordmark variant W. Part number (9 digits, two spaces in format: 12 345 6789). Common marking requirements that must be fulfilled for each marking variant are: Marking method: MA1 Marking height: 3 mm Date format: YYMMDD A unique serial number A DMC according to Scania STD 4562 (Ref 14.18) that contains the part number and serial number information. The marking shall not be visible when the ECA is mounted on a gearbox. The ECA units shall be delivered to the required Traton brand’s production in a position in the pallet where the marking is visible.
CR-SYS-0022SYSDesign constraintLowNON-COMPLIANTR19The variant type shall be based on delivery agreement and Brand involved.
CR-MECH-0003MECHDesign constraintMediumNON-COMPLIANTR1R2R19R21Common marking requirements that must be fulfilled for each marking variant are: Marking method: MA1 Marking height: 3 mm Date format: YYMMDD A unique serial number A DMC according to Scania STD 4562 (Ref 14.18) that contains the part number and serial number information.
CR-MECH-0004MECHDesign constraintLowNON-COMPLIANTR16The marking shall not be visible when the ECA is mounted on a gearbox.
CR-MECH-0005MECHDesign constraintLowCOMPLIANTThe ECA units shall be delivered to the required Traton brand’s production in a position in the pallet where the marking is visible.
CR-MECH-00062.7MECHDesign constraintLowNON-COMPLIANTR16R18R21The rubber cover (See req. 4.16) shall be marked according to the requirements in Scania STD19 (Ref 14.17) Tentik, wordmark variant W Part number (9 digits, two spaces in format 12 345 6789) Marking method: CAS Marking height: 2-6 mm. Date dial: CVM. Alternative design: CXM or equivalent combination of date dial and date field The rubber cover marking shall not be visible when the ECA is mounted on a gearbox
CR-MECH-00072.8MECHDesign constraintLowNON-COMPLIANTR17R19The ECA shall be designed with Remanufacturing and/or Refurbishment in mind with possibility of swapping out larger electronic assemblies/components. Details to be agreed with Traton
CR-SYS-00232.11SYSDesign constraintLowNON-COMPLIANTR9R19The mechanics shall also be tested and verified, in an overall durability test as stated in Appendix B etc.
CR-MECH-0008MECHDesign constraintLowNON-COMPLIANTR214.16) shall be marked according to the requirements in Scania STD19 (Ref 14.17) Tentik, wordmark variant W Part number (9 digits, two spaces in format 12 345 6789) Marking method: CAS Marking height: 2-6 mm.
CR-SYS-0024SYSDesign constraintLowNON-COMPLIANTR19Details to be agreed with Traton 2.9 Traton shall be invited to participate in electrical and mechanical design reviews.
CR-SYS-0025SYSDesign constraintLowNON-COMPLIANTR1R2R26R322.10 Traton requires extensive testing to be performed by the supplier to verify all demands stated in the requirement specification.
CR-VAL-0005VALDesign constraintLowNON-COMPLIANTR1R22.12 Traton requires: - Documentation of the product, i.e.
CR-HW-0007HWDesign constraintLowNON-COMPLIANTR1R2R16R19R26Should the PP be fully calculated from the AP-sensor, then this offset should not exist.
CR-MECH-00094.2MECHDesign constraintLowCOMPLIANTThe total stroke of the actuator shall be 85 mm
CR-SYS-00264.3SYSFunctionalLowNON-COMPLIANTR10R19The clutch actuator shall be able to reach the extreme positions A and B in with the center of the pushrod end. Dimensions measured on the ECA. See Figure 3 - Pushrod positions. Figure 3 - Pushrod positions
CR-MECH-00104.6MECHDesign constraintLowNON-COMPLIANTR16R20R21When the ECA is assembled, it shall not be possible to insert an object larger than Ø0,2 mm (A wire could be used as test object) between the ECA and gearbox flange, so that the object enters the space behind the ECA. The rubber grommet at the lower part of the flange can have the same interface as the surrounding aluminum flange.
CR-MECH-00114.7MECHDesign constraintLowNON-COMPLIANTR18When the ECA is assembled, a gap of 3,5 mm towards surface B with a profile tolerance of ±1 mm to the nominal dimensions shall be provided. The surface roughness of the ECA opposite to surface B shall be equal or finer than Ra 3,2 µm.
CR-MECH-00124.8MECHDesign constraintLowCOMPLIANTThe ECA shall be adapted for 6 pcs M8 flange screws described by Scania STD4435
CR-MECH-0013MECHDesign constraintLowNON-COMPLIANTR16R19R32P 1 Page 4.4 ECA shall not interfere with any geometry in the 3D envelope -1 1_RFQ2030.stp except where interference fits or other types of functional contacts are required.
CR-SYS-0027SYSDesign constraintLowNON-COMPLIANTR19The surface roughness of the ECA opposite to surface B shall be equal or finer than Ra 3,2 µm.
CR-MECH-00144.9MECHDesign constraintLowCOMPLIANTThe ECA shall be adapted for 2 pcs 10 mm guide pins Figure 5 - Gearbox flange
CR-MECH-00154.10MECHDesign constraintLowNON-COMPLIANTR17R18R32The guide pin holes in the ECA shall be Ø 10,1±0.05 mm and at least 12 mm deep. The holes shall also block the guide pin from protruding more than 14 mm from the gearbox housing. Both depths measured from the center of the oval hole in the Gearbox/ECA flange.
CR-MECH-00164.11MECHDesign constraintLowNON-COMPLIANTR10R21R26R34The ECA shall be able to be held by the guide pins only while being exposed to the max clutch load, (req. 4.22) up to 50 times. The clutch load will be removed and the screw interface tightened between every load occasion. Surface indents in the contacts are allowed as long as the structural integrity is unaffected
CR-MECH-00174.12MECHDesign constraintLowCOMPLIANTThe pushrod end that makes contact with the clutch lever shall be a Ø15,93±0,07 mm steel sphere.
CR-CYBER-00334.13CYBERDesign constraintLowNON-COMPLIANTR18R19R24It shall be possible to pull the pushrod 50 times with a force of 300 N without risk for it to come loose from the ECA. Alternatively it can have a loose fit in the ECA, but it shall be possible to reconnect it by pushing it back by hand.
CR-MECH-00184.14MECHDesign constraintLowCOMPLIANTThe ECA shall allow space for external tools according to the cylinders in the 3D envelope attached.
CR-MECH-00194.15MECHDesign constraintLowNON-COMPLIANTR21The ECA shall have a window where the volume shown in Figure 6 – Snap in tool space, could pass through(See req. 4.4).
CR-MECH-00204.16MECHDesign constraintLowNON-COMPLIANTR16R19R34The ECA shall provide a support for a clutch snap in tool on the marked surface in Figure 4 ISO view of 3D envelope. The maximum force is 1kN. Surface indents are allowed as long as it does not affect other requirements or the structural integrity of the ECA.
CR-MECH-0021MECHDesign constraintLowCOMPLIANTThe holes shall also block the guide pin from protruding more than 14 mm from the gearbox housing.
CR-SYS-0028SYSDesign constraintLowNON-COMPLIANTR19Alternatively it can have a loose fit in the ECA, but it shall be possible to reconnect it by pushing it back by hand.
CR-MECH-00224.17MECHDesign constraintLowNON-COMPLIANTR17R18R21The hole shall be equipped with a cover possible to assemble and disassemble at least 50 times without tools. If an interference fit is chosen, the maximum force to assemble/disassemble shall be 50 N in room temperature. It shall still remain intac t and keep tightness after vibration testing (See req.10.5)
CR-MECH-00234.18MECHDesign constraintLowNON-COMPLIANTR16When the cover is assembled it shall not be possible to insert an object larger than Ø0,2 mm into the gearbox housing between the cover and ECA. A wire could be used as test object. Figure 6 - Snap in tool space
CR-MECH-00244.19MECHDesign constraintLowNON-COMPLIANTR7R18R21The ECA shall have a loop or similar feature where the cable can be fixated with a cable tie Optionally an M8 screw thread and rotation stop for a sheet metal bracket indicated in Figure 4 - ISO view of 3D envelope, can be provided. The loop or Scania assembled bracket shall be located close to the centre ( ± 20 mm) of the cable section between the connector and last cable fixation point on the gearbox
CR-MECH-00254.20MECHDesign constraintLowNON-COMPLIANTR18The connector for communication and power shall be positioned as indicated in Figure 4 ISO view of 3D envelope, when connected. Details regarding actual length and positioning tolerances shall be agreed in design phase.
CR-SYS-00294.21SYSFunctionalLowNON-COMPLIANTR16R21If the ECA is powered up with the PP in the utmost forward position (for example when not connected to the clutch lever) it shall move AP to its utmost reversed position.
CR-MECH-0026MECHDesign constraintLowNON-COMPLIANTR17If an interference fit is chosen, the maximum force to assemble/disassemble shall be 50 N in room temperature.
CR-SYS-0030SYSFunctionalLowNON-COMPLIANTR19Details regarding actual length and positioning tolerances shall be agreed in design phase.
CR-SYS-00314.23SYSFunctionalLowNON-COMPLIANTR18The actuator shall apply a preload force for the release bearing. The preload force measured on the push rod shall be 150N to 250N independent of the clutch position
CR-MECH-00274.25MECHDesign constraintLowNON-COMPLIANTR24R32It must be possible to assemble the actuator independent of the lever position without any power connection. This means that the push rod shall be possible to move by hand. Maximum force allowed is 300N.
CR-SYS-0032SYSFunctionalMediumNON-COMPLIANTR16R21R264.26 When the clutch is fully engaged, the active control mode is position or torque control mode and there is no active request to extract the pushrod (clutch opening motion), the ECA shall not apply a force outside of limits in preload force defined in req.
CR-SYS-0033SYSFunctionalMediumNON-COMPLIANTR17R21P 1 Page 5 Clutch engage and disengage 5.1 It shall be possible to disengage the clutch in 180ms (= Ts) with accuracy according to ,and max speed set to 125mm/s (see
CR-SYS-0034SYSFunctionalLowNON-COMPLIANTR21R24R34This shall be measured against the maximum disengage force (See Appendix A) Figure 7 – Maximum disengage time
CR-SYS-0035SYSFunctionalLowNON-COMPLIANTR17R21P 1 Page 5.2 It shall be possible to engage the clutch in 180ms (=Ts) with accuracy according to re q.5.10, and the max speed set to 125mm/s (see ).
CR-SYS-0036SYSFunctionalLowNON-COMPLIANTR21R24R34This shall be measured against the minimum engage force (See Appendix A) Figure 8 - Maximum engage time
CR-MECH-00285.3MECHDesign constraintLowNON-COMPLIANTR21The clutch actuator shall report the absolute position of the current actuator stroke (AP) (Ref 14.14).
CR-MECH-00295.4MECHDesign constraintLowNON-COMPLIANTR21R24R26It shall also report the position that corresponds to a fully closed clutch position (FCCP), expressed in absolute position of the actuator stroke and relative to the absolute zero position (See req. 6.5).
CR-SYS-00375.5SYSFunctionalLowNON-COMPLIANTR21The clutch actuator shall be equipped with a displacement sensor measuring the movement of the push rod, (Ref 14.14)
CR-SYS-00385.6SYSFunctionalLowNON-COMPLIANTR1R2R10R17R19R21The actuator must be able to determine the pushrod position according to the following Accuracy (maximum difference between measured pushrod position and actual pushrod position): +/- 1.6mm. Resolution (smallest discernible unit of change along the X axis): 0.0125mm. Repeatability (maximum variation between measurements at the same position and in the same unit, with equal environmental conditions): +/- 0.1mm. Range: 85mm (AP)
CR-MECH-00305.7MECHDesign constraintLowNON-COMPLIANTR18R19R26For each stroke that the actuator performs it shall adjust to the current wear of the clutch. This means that is shall be possible to request a relative stroke from the fully closed clutch position and achieve the step accuracy as defined in req. 5.10. The implementation can be either a pure mechanical solution or it can be implemented using a software based solution.
CR-SYS-00395.9SYSFunctionalLowNON-COMPLIANTR21The maximum stationary position error relative to real FCCP (i e self-adjustment error + step response error) shall be ±0.15mm.
CR-MECH-0031MECHDesign constraintMediumCOMPLIANTThe FCCP after a clutch engage shall be updated to 90% of the step within 0,2 s per mm that the FCCP have changed during the stroke.
CR-SYS-0040SYSFunctionalLowNON-COMPLIANTR17R18P 1 Page 5.10 The actuator shall move the pushrod according to the following points: Actuator maximum speed: The maximum achievable speed of the pushrod shall be at least 125 mm/s.
CR-SYS-0041SYSFunctionalLowNON-COMPLIANTR34The actuator shall move the pushrod at the highest possible speed, limited only by its maximum achievable speed and the maximum speed request.
CR-SYS-0042SYSFunctionalLowNON-COMPLIANTR17R19R216.4) Dynamics start of movement: The requested speed (or 125mm/s, if requested speed > 125mm/s) shall be achieved within 50ms from when a new value for requested position is sent.
CR-SYS-0043SYSFunctionalLowCOMPLIANTDynamics end of movement: The requested speed shall be kept until 2 mm from the target position.
CR-SYS-0044SYSFunctionalLowNON-COMPLIANTR1R2100ms after reaching 2 mm from target, the maximum position error should be ±0.1mm.
CR-MECH-0032MECHDesign constraintLowNON-COMPLIANTR19Maximum overshoot is 0.2 mm When a new position is requested, but the stroke is too short to reach requested speed, the ECA shall complete the stroke in minimum time with dynamic in compliance with the , 5.2 and this section.
CR-SYS-00455.11SYSFunctionalLowNON-COMPLIANTR26Req. 5.10 shall be tested with a step response test cycle, according to description and Figure 10 - Step response test cycle. Step from FCCP to 0.5x fully open position Wait 2 seconds Step to fully open position Wait 2 seconds Step to 0.5x fully open position Wait 2 seconds Step to FCCP Figure 10 - Step response test cycle
CR-SYS-0046SYSDesign constraintLowCOMPLIANT5.10 shall be tested with a step response test cycle, according to description and Figure 10 - Step response test cycle.
CR-SYS-0047SYSDesign constraintLowNON-COMPLIANTR10R19R32P 1 Page 5.12 The ECA shall be able to run the 4 second test cycle in Figure 11 - Release frequency test continuously for 5 hours without any degradation or failure.
CR-SYS-0048SYSFunctionalLowNON-COMPLIANTR19R21R34The test shall be done with the highest operating temperature (see ) and maximum clutch force (See Appendix A) Figure 11 - Release frequency test
CR-CYBER-00345.14CYBERDesign constraintLowNON-COMPLIANTR18R19R21R24It shall be possible to keep the clutch disengaged continuously without risk of loss of function for 120 min. This shall be measured against the maximum disengage force (Appendix A) and an highest operating temperature (see req. 8.1).
CR-SYS-0049SYSFunctionalLowNON-COMPLIANTR19R32Between 16V and loss of power the ECA shall hold its current position or move towards requested position without any time requirement.
CR-SYS-0050SYSDesign constraintLowNON-COMPLIANTR19The strategy shall be disc ussed and approved with Traton.
CR-SYS-0051SYSFunctionalLowNON-COMPLIANTR19R21R24R34This shall be measured against the maximum disengage force (Appendix A) and an highest operating temperature (see req.
CR-SYS-00526.2SYSDesign constraintLowNON-COMPLIANTR7R21The ECA will be controlled by messages on the CAN bus and by the PWM signal specified in req. 7.24-7.33. The CAN communication messages are specified in PD2497100 (Ref 14.14). It shall be followed to its full extent. If needed, some messages might be complemented with additional checksums and message counters
CR-SYS-0053SYSDesign constraintLowCOMPLIANTP 1 Page 6 SW functionality 6.1 TB4684 shall be applied.
CR-SYS-0054SYSDesign constraintLowNON-COMPLIANTR24It shall be followed to its full extent.
CR-SW-00016.3.1SWFunctionalLowNON-COMPLIANTR18R19R21When requesting Absolute Position Control the actuator shall move to the actuator position defined by the Requested Position (RP). The RP can in this mode correspond to the full wear travel of the clutch (see req. 4.3) It is allowed to control movement to protect the ECA and clutch from hardware damage. Specific cases shall be approved with Traton. Control mode Absolute position 0x01
CR-SW-00026.3.2SWFunctionalLowNON-COMPLIANTR16R19R21R26Control (RPC) the actuator shall move to an offset that corresponds to the Requested Position from the Fully Closed Clutch Position (FCCP). The RP can be up to a full Release Travel (22,4 mm) in this mode. How the FCCP can be identified is described in 6.5. When RP = 0 the actuator is allowed to have a position that is less than the FCCP but not more, since this would open the clutch. Control mode Relative position 0x02
CR-SYS-0055SYSFunctionalLowCOMPLIANTWhen requesting Absolute Position Control the actuator shall move to the actuator position defined by the Requested Position (RP).
CR-SYS-0056SYSDesign constraintLowCOMPLIANTSpecific cases shall be approved with Traton.
CR-SW-0003SWFunctionalHighCOMPLIANTControl mode Relative position 0x02 6.3.3 When requesting Torque Control (TC) the actuator shall actuate the requested motor torque.
CR-SYS-00576.4SYSFunctionalLowNON-COMPLIANTR5R16R34A maximum allowed speed of the actuator is sent as a separate signal on CAN. If the actuator can move faster than this value it shall be controlled in a such way that it does not exceed this limit.
CR-SYS-00586.5.2SYSFunctionalLowNON-COMPLIANTR19The value shall be frozen at the last identified position and used for RPC. Self-adjustment disabled 0x3
CR-SYS-0059SYSFunctionalLowCOMPLIANT6.3.4 When requesting Test Mode, the actuator shall perform tests to detect latent faults.
CR-SW-0004SWFunctionalLowNON-COMPLIANTR19R21ECA behavior and additional requirements for this mode can be found in (Ref 14.16) Control mode Test mode 0x04 6.3.5 When this Control Mode is sent the actuator shall behave as if the power supply was cut with aspect to control of the actuator.
CR-SYS-0060SYSDesign constraintLowCOMPLIANTCAN communication shall still be active.
CR-SYS-0061SYSFunctionalLowNON-COMPLIANTR16R34If the actuator can move faster than this value it shall be controlled in a such way that it does not exceed this limit.
CR-SYS-0062SYSDesign constraintLowCOMPLIANT6.5 Self-adjustment The self-adjustment signal defines the restrictions of how the FCCP shall be identified.
CR-SYS-0063SYSDesign constraintLowNON-COMPLIANTR21The value of the FCCP shall be reported via CAN(Ref 14.14) Req.
CR-SYS-0064SYSFunctionalLowNON-COMPLIANTR19The value shall be frozen at the last identified position and used for RPC.
CR-VAL-00066.9VALDesign constraintLowCOMPLIANTThe ECA shall report a unique ECA individual identification number
CR-SYS-00656.10SYSDesign constraintLowCOMPLIANTThe ECA shall report supplier code 5 via CAN.
CR-VAL-00076.11VALDesign constraintLowNON-COMPLIANTR19The ECA shall report a complete SW version number. The number is decided by the supplier and can be in the range 0-64255.
CR-VAL-00086.12VALDesign constraintLowNON-COMPLIANTR19The ECA shall report a complete HW version number. The number is decided by the supplier and can be in the range 0-64255.
CR-HW-00086.14HWDesign constraintLowCOMPLIANTThe ECA shall report its current System State. Valid states are explained in requirements 6.14.1 - 6.14.9.
CR-SYS-0066SYSFunctionalLowCOMPLIANT6.6.1 When low accuracy mode is requested, the maximum push rod position(PP) error can be ±0.5mm Accuracy mode Low accuracy 0x0 6.6.2 Accuracy according to 5.10 shall be fulfilled.
CR-SW-0005SWFunctionalMediumNON-COMPLIANTR196.13 Error State Diagnostic - ESD and Error State Action - ESA The ECA shall send a bit field via CAN containing errors present Additionally, see ,
CR-VAL-0009VALDesign constraintLowNON-COMPLIANTR19R21ESA definition( Ref 14.16) The supplier shall provide documentation for the ESD bits and related faults .
CR-SYS-00676.14.2SYSFunctionalLowNON-COMPLIANTR24This value shall be sent when the ECA is actuating Absolute Position Control. 0x1
CR-SYS-00686.14.3SYSFunctionalLowNON-COMPLIANTR24This value shall be sent when the ECA is actuating Relative Position Control. 0x2
CR-SYS-00696.14.4SYSFunctionalHighestNON-COMPLIANTR24This value shall be sent when the ECA is actuating Torque Control. The torque being controlled is the torque of the motor. 0x4
CR-SYS-00706.14.5SYSDesign constraintLowNON-COMPLIANTR16R19R21R24This value shall be sent when the ECA is performing a Self-Adjustment procedure that is not part of a RPC or TC request (i.e. passing FCCP). 0x5
CR-SW-00066.14.6SWFunctionalLowNON-COMPLIANTR7R16R19R24This value shall be sent when the ECA is performing its initiation routine and is not yet available for control. 0xA
CR-SYS-00716.14.8SYSFunctionalLowNON-COMPLIANTR19R24This value shall be sent when the actuator is in debug or test control state. 0xC
CR-SYS-00726.14.9SYSFunctionalLowNON-COMPLIANTR24This value shall be sent when the actuator is performing a motor brake simulation. 0xD
CR-SW-0007SWFunctionalLowCOMPLIANT6.14.1 Boot Mode If the actuator is in boot mode, 0x00 shall be reported as active state.
CR-SYS-0073SYSDesign constraintLowNON-COMPLIANTR16R190xA 6.14.7 Shut down This value shall be sent when the ECA is performing its shut down routing and is not available for control.
CR-HW-00096.15HWDesign constraintLowNON-COMPLIANTR21The ECA shall report the current system temperature.(Ref 14.14)
CR-SYS-00746.16SYSFunctionalMediumNON-COMPLIANTR19R21The ECA shall calculate and report the actuator motor torque. (Ref 14.14)
CR-SYS-00756.17SYSFunctionalLowNON-COMPLIANTR18R21The ECA shall report the current for each phase of the actuator. These values shall be calculated using a moving mean filter. The filter time shall equal the update frequency . (Ref 14.14)
CR-HW-00106.18HWDesign constraintLowNON-COMPLIANTR21The ECA shall report the current system voltage. (input voltage) (Ref 14.14)
CR-VAL-00106.19.1VALDesign constraintLowNON-COMPLIANTR19The ECA shall store and report its accumulated operational hours.
CR-VAL-00116.19.2VALDesign constraintLowCOMPLIANTThe ECA shall report its accumulated lifetime travel length.
CR-SYS-00766.20SYSDesign constraintLowNON-COMPLIANTR21CVS120 shall be applied (Ref 14.12).
CR-SW-00086.21SWFunctionalMediumNON-COMPLIANTR8R17Cybersecurity shall be considered through a separate process with the latest Traton workflow in mind. The following apply: Mandatory: TRATON secure updates - CVS31,CVS32,CVS123-2,CVS154 TRATON secure diagnostics - CVS31,CVS32,CVS151 TRATON Specification on Unified diagnostic Services CVS124 Other applicable documents considered as supporting specifications: CVS30, CVS33, CVS34,CVS121,CVS122,SecureBoot,Vehicle Baseline Requirements, ECU Baseline Requirements Additional standards/documents will be made available, if applicable.
CR-SYS-0077SYSDesign constraintLowNON-COMPLIANTR24These values shall be calculated using a moving mean filter.
CR-SYS-0078SYSDesign constraintLowCOMPLIANTThe filter time shall equal the update frequency .
CR-VAL-00126.23VALDesign constraintLowNON-COMPLIANTR1R2R10R19The reported ESD must be able to be validated and invalidated.
CR-SW-00096.24SWFunctionalLowNON-COMPLIANTR9R19R21R32R34The gearbox control unit(TCU) shall be responsible for setting DTCs based on received notifications from ECA via ESD, including time-stamps, occurrence counters etc. One unique DTC will be set per bit in the ESD signal. If higher resolution is required for the supplier to properly troubleshoot any individual occurrence, then the ECA is responsible for storing these parameters internally. Internally stored parameters may be accessible only using supplier defined tools .
CR-SYS-00796.25SYSDesign constraintLowNON-COMPLIANTR19R32Any data logged or stored shall be agreed upon together with Traton.
CR-HW-00116.26HWDesign constraintLowNON-COMPLIANTR16R18R21When storing data in the device, the supplier shall take measures to prevent corruption of data which can occur for example when suffering power loss during read or write cycles. The supplier shall also ensure that systems are in place that ensure that data corruption is handled without loss of data, or loss of function. This could be designed with for example data mirroring. It is acceptable if purely statistical data (e.g. operation hours) from the active operation cycle is not stored in case of an abnormal shutdown.
CR-SYS-00806.27SYSDesign constraintLowNON-COMPLIANTR16R18There shall only be one calibration set of the ECA that is delivered to Traton, i.e, the calibration shall not be dependent of installation variants.
CR-FUSA-00016.28FUSAFunctionalHighNON-COMPLIANTR17R24R26R32It shall be possible to reset the ECA application with a power off/on cycle after all functional safety events. Handling to be agreed with Traton.
CR-SYS-0081SYSDesign constraintLowNON-COMPLIANTR1R2R19R32R34If higher resolution is required for the supplier to properly troubleshoot any individual occurrence, then the ECA is responsible for storing these parameters internally.
CR-SYS-0082SYSDesign constraintLowNON-COMPLIANTR1R2Internally stored parameters may be accessible only using supplier defined tools .
CR-SYS-0083SYSDesign constraintLowCOMPLIANTThe supplier shall also ensure that systems are in place that ensure that data corruption is handled without loss of data, or loss of function.
CR-SYS-00847.1SYSDesign constraintLowNON-COMPLIANTR1R2R21The electrical design must ensure that an internal short circuit through one of H -bridges (“shoot through”) is avoided.
CR-HW-00127.3HWDesign constraintLowNON-COMPLIANTR1R2R5A safe boot sequence must be set to prevent unwanted or undefined behavior during or after loss of power, or corruption of stored data.
CR-FUSA-00027.4FUSAFunctionalMediumNON-COMPLIANTR1R2R5R17R20R21A safe memory read/write sequence must also be implemented during actuator movement, in order to ensure safe and predictable behavior during operation, or in case of power lo ss. Relates to Safety Goals set in PD3339794 (Ref 14.16).
CR-HW-00137.5HWDesign constraintLowNON-COMPLIANTR18R26R32All external electrical connectors shall be geometrically coded. If internal components are included in repair kits, the internal electrical connectors shall also be geometrically coded.
CR-HW-0014HWDesign constraintLowNON-COMPLIANTR27.2 Short circuit protection shall be implemented by hardware.
CR-HW-0015HWDesign constraintLowCOMPLIANTIf internal components are included in repair kits, the internal electrical connectors shall also be geometrically coded.
CR-HW-0016HWDesign constraintLowNON-COMPLIANTR18R217.8 ECU tab headers shall comply with TB1787.(Ref 14.6) 7.9 ECU tab headers shall be made of self-extinguishing materials (i.e.
CR-HW-00177.12HWDesign constraintLowNON-COMPLIANTR19R26R32The ECA can be connected to the battery+ (30) permanently through the system fuse or through a master switch that physically cuts off power. All power used by the ECA shall be taken from this battery connection.
CR-MECH-00337.13MECHDesign constraintLowNON-COMPLIANTR16R19The ECA is connected directly to the battery GND (31). This ground connection will act as system ground and reference for the entire ECA. The ground shall not be DC connected to the ECA housing. Requirements Power cable dimension: Operating parameters Remark Min Typ. Max. Unit
CR-SYS-00857.18SYSFunctionalLowNON-COMPLIANTR1R2R19CVS41 limits may go below this value. Valid only for ECU and communication function. For clutch actuation see req. 5.13
CR-HW-0018HWDesign constraintLowNON-COMPLIANTR26R32All power used by the ECA shall be taken from this battery connection.
CR-MECH-0034MECHDesign constraintLowNON-COMPLIANTR16The ground shall not be DC connected to the ECA housing.
CR-HW-0019HWDesign constraintLowNON-COMPLIANTR1R2R217.23 Quiescent current: According to CVS41 (Ref 14.2), must be met independent of input and output conditions.
CR-HW-0020HWDesign constraintLowNON-COMPLIANTR24It shall be used to control the power up sequence to the µP.
CR-SYS-0086SYSDesign constraintLowCOMPLIANTThe Wake-up signal shall also be connected to a digital input on the µP.
CR-SYS-0087SYSDesign constraintLowNON-COMPLIANTR19Special precautions shall be taken to prevent direct connection between Wake-up and 30 in case of a single failure.
CR-SYS-0088SYSFunctionalLowNON-COMPLIANTR18R35After the wake-up line goes to high state: The ECA shall communicate on the CAN line within 250ms in case of a normal start -up The ECA shall be ready to open the clutch within 350ms in case of a normal start -up The ECA shall be ready to open the clutch as soon as possible after necessary movements in case of an abnormal start-up.
CR-SYS-0089SYSFunctionalLowNON-COMPLIANTR18After movement and reset, the ECA shall communicate on the CAN line within 250ms After movement and reset, the ECA shall be ready to open the clutch within 400ms In the case if the wake-up goes "high" at the same time as U30 signal the ECA should be ready to open the clutch within 3 seconds.
CR-SYS-0090SYSFunctionalLowNON-COMPLIANTR10R19Definition ready to open clutch: The actuator position shall be between FCCP and FCCP -3mm and the ECA is capable to move to disengaged clutch directly when requeste d.
CR-SYS-0091SYSDesign constraintLowCOMPLIANTRedundancies due improper shutdown shall be aligned with Traton.
CR-SYS-0092SYSFunctionalLowCOMPLIANTIf a signal for disengaging the clutch is received the ECA shall actuate the request regardless of CAN-request.
CR-SYS-00937.34SYSDesign constraintLowNON-COMPLIANTR18R21R32The ECA has one CAN bus. Any watchdog circuit shall have no influence on the CAN bus The CAN front end shall be designed to comply with TB1905 (Ref 14.3), with the following additional information in this chapter.
CR-SYS-00947.35SYSDesign constraintLowNON-COMPLIANTR19The controller and transceiver shall be CAN FD ready Parameter Limit values Unit Remarks Min. Typ. Max.
CR-SYS-0095SYSDesign constraintLowNON-COMPLIANTR32Any watchdog circuit shall have no influence on the CAN bus.
CR-SYS-0096SYSDesign constraintLowNON-COMPLIANTR21The CAN front end shall be designed to comply with TB1905 (Ref 14.3), with the following additional information in this chapter.
CR-SW-0010SWDesign constraintLowNON-COMPLIANTR17R187.36 Termination resistance: - 2 x 60 - Ω 1% resistors shall be used 7.37 Baud rate: 250 500 1000 kbit/s Flashing in production shall be possible with 1000kbit/s.
CR-SYS-00977.39SYSDesign constraintLowNON-COMPLIANTR7R17R19R26The layout shall always be present on the PCB and the supplier must be flexible in changing/removing the CAN related components in this section.
CR-SYS-00987.40SYSDesign constraintLowNON-COMPLIANTR16R18R19R21CAN shield. Footprint prepared for internal connection to system ground 31_ECA via a resistor and a capacitor in series. The components shall not be populated by default. The CAN front end shall be designed to comply with TB1905. (Ref 14.3)
CR-SYS-0099SYSDesign constraintLowNON-COMPLIANTR16The components shall not be populated by default.
CR-SYS-0100SYSDesign constraintLowCOMPLIANTThe CAN front end shall be designed to comply with TB1905.
CR-SYS-01017.45SYSDesign constraintLowNON-COMPLIANTR18R20The air inside the electronics enclosure shall be ventilated with the use of a membrane. The following requirements shall be fulfilled: The unit shall withstand the salt-spray environment, according to CVS40 §6.1.6, without clogging of the membrane. The membrane shall be placed so that it is protected against blunt force, falling dust and dripping salt-water. The design shall be made to prevent accumulation of water on top of the membrane, or in the cavity of the membrane.
CR-SYS-0102SYSFunctionalLowNON-COMPLIANTR19The quality of the wire bonding and position shall be properly analyzed.
CR-HW-0021HWDesign constraintLowNON-COMPLIANTR19The material shall be lead free and of ”high temperatures solder type”.
CR-SYS-0103SYSFunctionalLowNON-COMPLIANTR2R19The melting point of the soldering material and the composition of the soldering material shall be declared by supplier.
CR-VAL-0013VALDesign constraintLowNON-COMPLIANTR1R2R16R19R32The PCB must be supported and must not bent in any direction during the process.
CR-SYS-0104SYSDesign constraintLowNON-COMPLIANTR19R26R32Conformal coating or lacquer shall cover the entire PCB and all solder joints.
CR-SYS-0105SYSDesign constraintLowNON-COMPLIANTR20The layout of the PCB, including component placement, shall take the applying of conformal coating into consideration so that the aforementioned requirement can be met.
CR-SYS-0106SYSDesign constraintLowCOMPLIANTshall be specified in the initial offer.
CR-VAL-0014VALDesign constraintLowNON-COMPLIANTR17R19The conformal coating process and materials shall apply to the latest versions of IPC/EIA J-STD-001 (with applicable standards as e.g.
CR-SYS-0107SYSDesign constraintLowCOMPLIANTHDBK-001, IPC-CC-830 and HDBK-830) and the visual appearance of the final coating shall be consistent with the latest version of IPC-A-610.
CR-SYS-0108SYSDesign constraintLowNON-COMPLIANTR16R19Water based and silicone lacquers shall not be used.
CR-SYS-0109SYSDesign constraintLowNON-COMPLIANTR18The following requirements shall be fulfilled: The unit shall withstand the salt-spray environment, according to CVS40 §6.1.6, without clogging of the membrane.
CR-SYS-0110SYSDesign constraintLowNON-COMPLIANTR20The membrane shall be placed so that it is protected against blunt force, falling dust and dripping salt-water.
CR-SYS-0111SYSDesign constraintLowCOMPLIANTThe design shall be made to prevent accumulation of water on top of the membrane, or in the cavity of the membrane.
CR-SYS-0112SYSDesign constraintLowNON-COMPLIANTR1R2R16R327.46 Forbidden components: BGA capsule in any form must not be used.
CR-HW-0022HWDesign constraintLowNON-COMPLIANTR1R2R16Tantalum capacitors must not be used Serial resistors on power supply circuits must not be used.
CR-SYS-01138.3SYSFunctionalLowCOMPLIANTThe clutch actuator shall withstand 6 500 000 actuations with the test cycle described in Appendix B.
CR-SYS-01148.5SYSDesign constraintLowNON-COMPLIANTR1R2The ECA must be maintenance free over the whole life time
CR-SYS-01158.8SYSDesign constraintLowNON-COMPLIANTR21The maintenance window cover (See req. 4.17) shall be provided as a spare part
CR-SYS-01168.9SYSFunctionalLowCOMPLIANTIn a situation where the ECA has jammed, and is holding the clutch open, it shall be possible to remove the clutch force by following an instruction documented on the ECA drawing. It is allowed to destroy the ECA in the process.
CR-SYS-0117SYSFunctionalLowCOMPLIANT8.4 Six consecutive units shall run past 6.5M actuations at the supplier, and continue to end of life.
CR-SYS-0118SYSFunctionalLowCOMPLIANTThree consecutive units shall run past 6.5M actuations at Scania, and continue to end of life.
CR-HW-0023HWDesign constraintLowNON-COMPLIANTR17R19R348.6 Failure rate for ECU and electronics shall be less than: 0ppm @ “0” km 200ppm/year during year 1-5 400ppm/year during year 6-10 1000ppm/year during year 11-15 8.7 External vulnerable components might need to be replaceable.
CR-SYS-0119SYSDesign constraintLowNON-COMPLIANTR19Spare parts or repair kits shall be defined together in agreement.
CR-SYS-0120SYSDesign constraintLowCOMPLIANT4.17) shall be provided as a spare part.
CR-MECH-00359.1MECHDesign constraintLowNON-COMPLIANTR7R16R18R19R21The ECA shall fulfil the requirements stated in STD3868 STD3868 is a comprehensive document referring to several underlying standards. Out of a recycling and environmental perspective the following standards shall be taken under consideration in addition to CVS55(Ref 14.32): STD4158, Chemical substances which shall not be used – Scania Black list. STD4159, Chemical substances with limited use – Scania Grey list. CVS 83, Material declaration according to Scania IMDS reporting std. The different parts of the housing shall be marked according to material content. The ECA shall be lead free.
CR-SYS-01219.2SYSDesign constraintMediumNON-COMPLIANTR17R18R26R32All included parts shall fulfil applicable sections of Part 9 in Annex B to the latest ADR ,as applicable at the time of type approval. For type approval, the vehicle and its components shall comply with ECE Regulation No. 105 and with European Directive 2008/68/EC, as amended.
CR-HW-0024HWDesign constraintLowNON-COMPLIANTR16R18R19R21Out of a recycling and environmental perspective the following standards shall be taken under consideration in addition to CVS55(Ref 14.32): STD4158, Chemical substances which shall not be used – Scania Black list.
CR-MECH-0036MECHDesign constraintLowCOMPLIANTThe different parts of the housing shall be marked according to material content.
CR-SYS-0122SYSDesign constraintLowCOMPLIANTThe ECA shall be lead free.
CR-SYS-0123SYSDesign constraintLowCOMPLIANTFor type approval, the vehicle and its components shall comply with ECE Regulation No.
CR-SYS-012410.1SYSDesign constraintLowNON-COMPLIANTR1R2R21The ECA must fulfil the general requirements for Electronic Control Units (ECUs), which are stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2).
CR-SYS-012510.2SYSDesign constraintLowNON-COMPLIANTR1R2R16R19R21The ECA must not be dependent on software for protection against requirements stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2).
CR-SYS-0126SYSDesign constraintLowNON-COMPLIANTR16CAN communication shall not be affected.
CR-HW-0025HWDesign constraintLowCOMPLIANTMemory functions shall remain Class A.
CR-SYS-0127SYSDesign constraintLowNON-COMPLIANTR19Accepted behaviour in this case shall be agreed upon between Traton and Supplier.
CR-MECH-003710.4MECHDesign constraintLowNON-COMPLIANTR18R21R26R32R34For this unit, the following definitions of test procedure I and test procedure II shall be used Test procedure I A comprehensive test where all functional requirements are verified. This test shall be performed before and after exposure. Test procedure I (See Figure 17 - Test procedure I) shall at least contain: - Full stroke to evaluate speed - Staircase to evaluate accuracy - Power loss to evaluate safety Figure 17 - Test procedure I Test procedure II A reduced function test where the fundamental requirements are verified. This test shall be possible to perform during exposure. Reduced versions of test procedure II may be agreed and used during various tests. Alternative 1: Test cycle according to Appendix B, frequency 10 to 30 strokes per minute. Alternative 2: Release frequency test according to req. 5.12.
CR-SYS-0128SYSDesign constraintLowNON-COMPLIANTR19R24This test shall be performed before and after exposure.
CR-MECH-0038MECHDesign constraintMediumNON-COMPLIANTR21R34Test procedure I (See Figure 17 - Test procedure I) shall at least contain: - Full stroke to evaluate speed - Staircase to evaluate accuracy - Power loss to evaluate safety Figure 17 - Test procedure I Test procedure II A reduced function test where the fundamental requirements are verified.
CR-SYS-0129SYSDesign constraintLowNON-COMPLIANTR24This test shall be possible to perform during exposure.
CR-SYS-0130SYSDesign constraintLowNON-COMPLIANTR1R2R19Reduced versions of test procedure II may be agreed and used during various tests.
CR-MECH-003910.5.16MECHDesign constraintLowCOMPLIANTCVS40 §5.10 TC-10 Ingress protection The ECA shall also fulfil IP54 without mounted connectors. IP classes to test: IP6K6K, IP6K7, and IP6K9K Y
CR-SYS-013110.5.33SYSDesign constraintLowNON-COMPLIANTR20R21R32CVS40 §8.1 TS-01 Flammability In order to fulfil flammability demands, any plastic materials (i.e. tab headers) shall be made of self- extinguishing materials (i.e. UL94). Y
CR-SYS-0132SYSDesign constraintLowCOMPLIANTtab headers) shall be made of self- extinguishing materials (i.e.
CR-SYS-013310.7.27SYSDesign constraintLowNON-COMPLIANTR1R2R32CVS46 §5.1 Vehicle test ESD Traton performs Vehicle test, Traton may need support from supplier with any issues originating from the component. Y
CR-SYS-013410.7.34SYSDesign constraintLowNON-COMPLIANTR1R2CVS46 §5.4 Vehicle test RI: Immunity of vehicles to radiated fields Traton performs Vehicle test, Traton may need support from supplier with Y
CR-FUSA-0003FUSAFunctionalHighNON-COMPLIANTR19P 1 Page 11 Functional safety The ECA is a part of a safety critical system and shall be handled as such.
CR-FUSA-0004FUSAFunctionalHighNON-COMPLIANTR19The ECA shall therefore be developed and implemented in accordance with the objectives and requirements of ISO 26262 "Road vehicles - Functional Safety".
CR-CYBER-0035CYBERDesign constraintHighNON-COMPLIANTR32The supplier shall analyse risks of individua l HW and SW components, mechanics, and any other technologies, independently of the scope of ISO 26262.
CR-SYS-0135SYSDesign constraintLowNON-COMPLIANTR1R2For this purpose possible causes must be systematically identified.
CR-FUSA-0005FUSAFunctionalHighNON-COMPLIANTR34For these analyses at least the methods in ISO 26262 shall be applied.
CR-SYS-013612.3SYSDesign constraintLowNON-COMPLIANTR1R2R32The supplier of the unit must write software to enable his own testing of the unit during development, production and on any claimed unit.
CR-SYS-0137SYSDesign constraintLowNON-COMPLIANTR1R2R17R19R26R32ID Verification methods 12.1 Conformance to Requirement Specification A1 The supplier must do conformance test of all external and internal I/O.
CR-SYS-0138SYSDesign constraintLowNON-COMPLIANTR1R2R17R19R24R26R32This test must verify that all internal and external I/O fulfils the requirements in this specification.
CR-HW-0026HWDesign constraintLowNON-COMPLIANTR1R2R19R21A2 The supplier must perform full DV (Design Verification at B-sample level) and full PV (Product Validation at C-sample level) environmental test programs according to CVS40 and CVS41 (incl.
CR-SYS-0139SYSDesign constraintLowNON-COMPLIANTR1R2the suppler must carry out two full test rounds according to the Traton test requirements.
CR-SYS-0140SYSDesign constraintLowNON-COMPLIANTR1R2R19Additional tests initiated and performed by the supplier must be discussed with Traton.
CR-HW-0027HWDesign constraintLowNON-COMPLIANTR1R2A3 The supplier must test the connectors according to TB1787.
CR-SYS-0141SYSDesign constraintLowNON-COMPLIANTR1R2A4 The supplier must do EMC tests with the unit alone.
CR-SYS-0142SYSDesign constraintLowNON-COMPLIANTR1R2R21R26R32The supplier must certify the ECA according to UN ECE R10 (EMC), according to the latest revision with all amendments.
CR-SYS-0143SYSDesign constraintLowNON-COMPLIANTR1R2R7R19R32A5 The supplier must check that both prototypes and serial units fulfil the dimension requirement according to any relevant Traton supplied drawings.
CR-SYS-0144SYSDesign constraintLowNON-COMPLIANTR17R26R32A6 All prototypes and serial ECA’s shall fulfil requirements according to TB1822, IPC/EIA J-STD-001 class 3 and IPC-A-610 class 3.
CR-SYS-0145SYSDesign constraintLowNON-COMPLIANTR1R2R7R19However, dividing sample phases into several generations must be agreed upon between Traton and the supplier.
CR-SYS-0146SYSDesign constraintLowNON-COMPLIANTR26R32All samples shall be functionally tested before sent to Traton.
CR-SYS-0147SYSDesign constraintLowCOMPLIANTDeviations shall be reported as a part of the sample delivery.
CR-SYS-0148SYSDesign constraintLowNON-COMPLIANTR19Dimensional checks shall be performed for B and C-samples prior to delivery to Traton.
CR-SYS-0149SYSDesign constraintLowNON-COMPLIANTR1R2The supplier must use the sample denominations requested by Traton.
CR-SYS-0150SYSDesign constraintLowNON-COMPLIANTR1R2R19Unless otherwise stated, valid version is the latest available as of 1st May 2026.
CR-SYS-0151SYSDesign constraintLowNON-COMPLIANTR17P 1 Page Appendix B – Life length test The life time testing of the ECA shall consist of 6500000 repetitions of the test cycle described in ”I – Test cycle” Two different test profiles/setups can be used.
CR-SYS-0152SYSFunctionalLowNON-COMPLIANTR1R2R26Between the two movements the actuator should remain in the fully disengaged position.
CR-SYS-0153SYSFunctionalLowNON-COMPLIANTR1R2After the complete engagement the actuator should remain in this position until the next disengagement is requested.
CR-SYS-0154SYSDesign constraintLowNON-COMPLIANTR17R18R19• A function test rig shall be used for function tests between intervals • At 6.25M cycles a function test at -40C as well as the release frequency test is performed, before the rigs are put into run-to-failure mode • Run-to-failure mode implies cycling at intermediate load and RT/80C until failure • @Temp durability will start with 15/min frequency to verify if 30/min is feasible • One rig at RT shall run at 15/min as a reference unit for cycle acceleration.
CR-SW-0011SWDesign constraintLowNON-COMPLIANTR1R2R19R21R32TRATON Software Update Variant 2 (SUV2) sequence Foreword This Commercial Vehicle Standard (“CVS123-2”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.
CR-SYS-0155SYSDesign constraintLowCOMPLIANTThe User shall apply the latest version of this CVS123-2.
CR-SW-0012SWFunctionalHighNON-COMPLIANTR1R2R19The reason to why an ECU must implement two or more diagnostic servers is that it needs to support two or more different ECU configurations: one for which no application is installed and one or more for which applications are installed in the ECU.
CR-SYS-0156SYSDesign constraintLowNON-COMPLIANTR1R2R16R19R24R26It should be noted that a single server view is not completely achievable and that clients still need to be aware of two physical servers.
CR-SYS-0157SYSDesign constraintLowNON-COMPLIANTR1R2R19Clients may prefer to implement programming support using other service parameter values or even another set of programming steps than
CR-SYS-0158SYSDesign constraintLowNON-COMPLIANTR1R2For this reason, only the server is required to support the specified sequence.
CR-SYS-0159SYSDesign constraintLowNON-COMPLIANTR1R2R24It must be clearly separated from the application software.
CR-SYS-0160SYSDesign constraintLowNON-COMPLIANTR1R2For this reason, it is located in a separate memory area and must also be erasable and programmable independently of the application software.
CR-SYS-0161SYSDesign constraintLowCOMPLIANTshall be implemented in the boot software code.
CR-HW-0028HWDesign constraintLowNON-COMPLIANTR19Satisfied programming precondition A programming precondition agreed between supplier and vehicle manufacturer which, together with other agreed programming preconditions, shall be fulfilled before an ECU is made eligible for programming.
CR-SW-0013SWFunctionalHighNON-COMPLIANTR21The implementation of the client and the server shall be compliant with (ISO14229-1:2020) and the Traton Specification on Unified diagnostic Service (UDS) requirements (CVS124) with the clarifications, extensions and exceptions stated in this specification.
CR-SYS-0162SYSDesign constraintLowNON-COMPLIANTR16R21Requirements in (CVS124) which are not explicitly stated to apply to the application only (such as communication parameters) shall apply to the boot loader as well.
CR-SYS-0163SYSDesign constraintLowNON-COMPLIANTR26R32All deviations from this specification shall be agreed with the applicable vehicle manufacturer(s).
CR-SYS-0164SYSDesign constraintLowNON-COMPLIANTR19R21R26R32The programming requirements in this specification shall apply to the programming of all kinds of software modules (application, application data and boot loader), unless explicitly otherwise stated.
CR-SW-0014SWDesign constraintLowNON-COMPLIANTR5R16an ECU will not support boot loader reprogramming, the boot loader SW shall be in a protected area of the memory.
CR-SYS-0165SYSDesign constraintLowNON-COMPLIANTR5R19A SW or HW protection mechanism shall be used to protect the software from being accidentally erased or overwritten.
CR-SYS-0166SYSDesign constraintLowCOMPLIANTIf the microcontroller supports HW protection, this shall be used.
CR-SYS-0167SYSDesign constraintLowNON-COMPLIANTR19R26R32The server shall support programming of all application software and application data modules and any subset of such modules in a single sequence without any intermediate reset service requests.
CR-SW-0015SWDesign constraintLowNON-COMPLIANTR16R19Programming of a subset of modules may lead to that the consistency check at the end of a programming sequence fails but shall not lead to that those programmed modules need to be reprogrammed from the beginning.
CR-SYS-0168SYSDesign constraintLowCOMPLIANTBoot loader updating according to this specification shall be supported during development, from A-samples and onwards.
CR-SW-0016SWFunctionalLowNON-COMPLIANTR5R16R19R21A server shall be programmable according to this specification (i.e., not only using supplier tools) regardless of whether one or more DTCs are currently active, or one or more functions are currently degraded.
CR-SW-0017SWFunctionalMediumNON-COMPLIANTR5R19A server shall be programmable while integrated in the vehicle network and as a standalone server without further conditions and without further interventions by the diagnostic tester as per this specification.
CR-SW-0018SWDesign constraintMediumNON-COMPLIANTR9R17R21The solution for maintaining/reorganizing data (EEPROM data, operational data, adaptive data etc.) before and after reprogramming of software modules shall be discussed and agreed with the vehicle manufacturer.
CR-SYS-0169SYSDesign constraintLowCOMPLIANTThe supplier shall provide, for each committed software delivery, a document that describes the programming procedure together with any requirement exceptions and ECU specific behaviours.
CR-SYS-0170SYSDesign constraintLowNON-COMPLIANTR21Normal and worst-case performance values shall be documented for: • Total time for the programming sequence (programming steps prefixed “P1Pro”, see section Programming step of phase #1 – Download of application software and data).
CR-SYS-0171SYSDesign constraintLowCOMPLIANTThe supplier shall document the versioning concept for supplier specific DIDs.
CR-SW-0019SWFunctionalMediumNON-COMPLIANTR21System name (DID 0xF197), diagnostic address and bitrate shall be persisted in an application data module dedicated for boot parameters, referred to as “boot parameter module”.
CR-SYS-0172SYSDesign constraintLowCOMPLIANTWhen this module is programmed the parameter values in it shall override default parameter values persisted in the boot loader software module.
CR-HW-0029HWDesign constraintLowNON-COMPLIANTR1R2R7R17R24It should be possible to reuse the generic bootloader for future currently unknown purposes/applications without a need to create a new part number for the platform.
CR-SW-0020SWFunctionalMediumNON-COMPLIANTR16R17R21When the boot loader software in an ECU has not yet been parameterized (a boot parameter module has not been programmed) the boot loader software shall apply project specific default values, typically: • diagnostic address 0xA7 • baud rate 500 kb/s • DID 0xF197
CR-SYS-0173SYSDesign constraintLowCOMPLIANTDefault values for EOL parameters shall be implemented in a dedicated application data module, referred to as “EOL parameters module”.
CR-SYS-0174SYSDesign constraintLowNON-COMPLIANTR19The partitioning of the ECU software into modules shall be discussed and agreed with the vehicle manufacturer.
CR-CYBER-0036CYBERDesign constraintMediumNON-COMPLIANTR5A software released for integration test, production or service market shall be hashed so its integrity can be verified by the server.
CR-SYS-0175SYSDesign constraintLowNON-COMPLIANTR26Flash files delivered from the supplier shall never have to be modified by the vehicle manufacturer.
CR-CYBER-0037CYBERDesign constraintMediumCOMPLIANTThe supplier shall deliver the necessary information to verify the integrity of the flash files.
CR-CYBER-0038CYBERDesign constraintLowNON-COMPLIANTR1R2In case the supplier delivers encrypted flash files to the vehicle manufacturer, the supplier should also provide the necessary information so the flash files can be verified as part of flash files update procedure.
CR-SYS-0176SYSDesign constraintLowNON-COMPLIANTR16R18R19Whether or not the ECU shall be delivered from the supplier to the vehicle manufacturer with a pre-programmed application and pre-programmed application data shall be discussed and agreed with the vehicle manufacturer.
CR-SYS-0177SYSDesign constraintLowNON-COMPLIANTR10R19R32Regardless of if the ECU will be delivered from the supplier with a pre-programmed application and application data, the corresponding flash files shall be possible to request by vehicle manufacturer to be able to perform software verification at any time in vehicle manufacturer production site.
CR-SW-0021SWFunctionalLowCOMPLIANTWhen the application module is pre-programmed by the supplier, ECU and software identifiers 0xF187 and 0xF188 shall be set to product specific vehicle manufacturer defined values.
CR-SW-0022SWFunctionalLowNON-COMPLIANTR19Otherwise 0xF187 and 0xF188 shall be set to default values, see CVS124.
CR-SYS-0178SYSDesign constraintLowCOMPLIANTProgrammable servers shall support the full programming sequence described in this chapter.
CR-SYS-0179SYSDesign constraintLowNON-COMPLIANTR19R21Non-programmable servers shall support the pre-programming and post-programming steps of the programming sequence described in this chapter (phase 1 and 2).
CR-SYS-0180SYSDesign constraintLowNON-COMPLIANTR19The programming sequence described in this chapter shall be supported when a valid application is present as well as when no valid application is present in the ECU.
CR-SYS-0181SYSDesign constraintLowCOMPLIANTThe full set of addressing modes, SPRMIB values and other parameter values that the server shall support for each service are specified with implementation requirements in CVS124.
CR-SW-0023SWFunctionalLowCOMPLIANTTo enable access to diagnostic services in the programming sequence, an authentication sequence shall be performed between the client and the server by means of the Authentication 0x29 service.
CR-SW-0024SWFunctionalLowNON-COMPLIANTR21The server shall receive a diagnostic service authentication (0x29) with SubFunction deAuthenticate (0x00) message from the client to disable authorized access to diagnostic programming services after an update is considered fulfilled.
CR-CYBER-0039CYBERDesign constraintHighNON-COMPLIANTR1R2R7R17As example, the client may read certificate validity time and/or RBAC configuration file to verify if the appropriate entities are stored in the server.
CR-CYBER-0040CYBERDesign constraintMediumNON-COMPLIANTR1R2R7As example, the client may have identified that the RBAC configuration file requires update and perform the appropriate set to update the entities stored in the server.
CR-SW-0025SWDesign constraintLowNON-COMPLIANTR1R2R26Alternatively, it may be a client strategy to always update certain entities prior to a software update.
CR-SW-0026SWFunctionalLowNON-COMPLIANTR1R2R21Since Link Control is only applicable in production when no application has been programmed by the supplier, the application may return NRC 0x7F (serviceNotSupportedInActiveSession) to this service request and expect the client to proceed to the next step.
CR-SW-0027SWFunctionalMediumNON-COMPLIANTR7R10R21For the server to verify the integrity of the software, the information to verify shall be available to the server before step P1Pro6: Routine Control (erase Memory).
CR-CYBER-0041CYBERDesign constraintLowNON-COMPLIANTR10If the SW to be updated is encrypted, decryption keys shall be available to the server before step P1Pro9.
CR-SYS-0182SYSDesign constraintLowCOMPLIANTBefore the server executes the TransferData service, the server shall check if the data received during RequestDownload requests needs to be decrypted before writing the received data to non-volatile memory.
CR-CYBER-0042CYBERDesign constraintHighNON-COMPLIANTR1R2R16Implementation hint: The integrity information may contain parts of memory not programmed, regardless of this the server verifies the integrity according to the supplied information on SDSC, see 9.
CR-SYS-0183SYSDesign constraintLowNON-COMPLIANTR1R2If the application was started, it checks if application initialization is required.
CR-HW-0030HWDesign constraintLowNON-COMPLIANTR1R2R9R17R21If so, the server performs the required checks/reorganization measures for the data structures (EEPROM data, operational data, adaptive data etc.), executes the self-test and stores event memory entries, default values, DIDs F1AB, F1AA, F1A9 etc.
CR-SW-0028SWDesign constraintLowNON-COMPLIANTR1R2R21Implementation hint: The ECU application checks the reprogrammed flag (C3, see programming step P1Pro11) to see if application initialization is required.
CR-CYBER-0043CYBERDesign constraintMediumNON-COMPLIANTR1R2As example, the client may have identified that the new software requires an updated RBAC configuration file and therefore set the entity on the server via EMP.
CR-SYS-0184SYSDesign constraintLowCOMPLIANTECUs that will be programmed stand-alone at the vehicle manufacturer over DoCAN shall support 1 Mbit transfer speed.
CR-HW-0031HWDesign constraintLowNON-COMPLIANTR16R18R19Whether or not the ECU shall support stand-alone programming at the vehicle manufacturer premises shall be discussed and agreed with the vehicle manufacturer.
CR-SW-0029SWFunctionalMediumNON-COMPLIANTR5A server that is running in the application shall respond with the same diagnostic address after a switch to boot.
CR-HW-0032HWDesign constraintLowNON-COMPLIANTR19R24It shall be possible to downgrade server software modules as long as the programmed modules are compatible with each other and with the hardware configuration.
CR-SYS-0185SYSDesign constraintLowNON-COMPLIANTR19R32Application software and application data modules shall be programmable in any order.
CR-SYS-0186SYSDesign constraintLowNON-COMPLIANTR10R32The server shall be able to update an individual module independently from any other module.
CR-SYS-0187SYSDesign constraintLowNON-COMPLIANTR16cannot be met, a compression method shall be implemented.
CR-SYS-0188SYSDesign constraintLowNON-COMPLIANTR17R19The LZSS algorithm with a dictionary size of 1 023 bytes or a newer compression/decompression method with a higher compression ratio shall be used as the compression/decompression algorithm.
CR-SYS-0189SYSDesign constraintLowNON-COMPLIANTR17The use of alternative compression/decompression algorithms shall be agreed with the vehicle manufacturer.
CR-SYS-0190SYSDesign constraintLowNON-COMPLIANTR24It shall be possible to program the same software version repeatedly.
CR-HW-0033HWDesign constraintLowNON-COMPLIANTR16R17If at startup the ECU hardware/software is consistent and a programming request is not pending, the boot manager shall start and execute the application.
CR-SW-0030SWFunctionalLowNON-COMPLIANTR17R19Otherwise if at startup the ECU hardware/software is inconsistent the boot manager shall start and execute the boot loader and reset DIDs 0xF181, 0xF187 and 0xF188 and 0xF1A1 to default values.
CR-SYS-0191SYSDesign constraintLowCOMPLIANTIf at startup the boot manager starts and executes the application, the application shall read and apply the parameter values persisted in the boot parameter module.
CR-SYS-0192SYSDesign constraintLowNON-COMPLIANTR19Otherwise if at startup the boot manager starts and executes the boot loader and a valid boot parameter module has been successfully programmed, the boot loader shall read and apply these parameter values from the boot parameter module.
CR-SYS-0193SYSDesign constraintLowNON-COMPLIANTR19Otherwise if no boot parameter module has been successfully programmed, the boot loader shall apply the corresponding parameter values persisted in the boot loader module.
CR-SW-0031SWDesign constraintLowCOMPLIANTAfter reprogramming, the application shall store DIDs F1AB, F1AA, F1A9.
CR-SYS-0194SYSDesign constraintLowNON-COMPLIANTR19The technical implementation of the programming preconditions shall be agreed between the supplier and the vehicle manufacturer.
CR-HW-0034HWDesign constraintLowNON-COMPLIANTR5R19A programmable server shall guarantee re-programmability within the normal operating voltage range specified by [11] for 24V systems or [12] for 12V systems.
CR-SYS-0195SYSDesign constraintLowNON-COMPLIANTR5R16R18R19R21R26R32A server that is restarted for any reason or thrown back to DefaultSession due to lack of TesterPresent or unfulfilled preconditions shall always support programming from the start of the programming sequence (programming step P1Pre), i.e., shall not depend on any state from an interrupted programming sequence.
CR-VAL-0015VALDesign constraintLowCOMPLIANTThe server shall guarantee re-programmability in the event of error conditions during the programming process regardless of cause.
CR-SW-0032SWFunctionalLowNON-COMPLIANTR21The causes specified in (ISO14229-1:2020) shall be regarded as examples.
CR-SYS-0196SYSDesign constraintLowNON-COMPLIANTR19R21The server shall be re-programmable (standalone and in the vehicle) regardless of whether the application and application data is valid or has been corrupted.
CR-SW-0033SWFunctionalMediumCOMPLIANTDiagnostic services support shall be as per CVS124.
CR-CYBER-0044CYBERDesign constraintLowCOMPLIANTECU identification data support shall be as per CVS124.
CR-SYS-0197SYSDesign constraintLowNON-COMPLIANTR16R17R19R21R26R32R34When programmed in the vehicle manufacturer’s production facility the total time for programming of all modules shall not exceed 90 seconds with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2).
CR-SW-0034SWDesign constraintLowNON-COMPLIANTR1R2R16R24R26R32This does not apply to ECUs for which all software modules are pre-programmed in supplier premises, even if a software update capability is required in vehicle manufacturer production premises, e.g., for bug fixing.
CR-SYS-0198SYSDesign constraintLowNON-COMPLIANTR16R17R19R21R26R32R34When programmed in the workshop the total time for programming of all modules shall not exceed 10 minutes with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2).
CR-SW-0035SWFunctionalLowNON-COMPLIANTR7If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request.
CR-HW-0035HWDesign constraintLowNON-COMPLIANTR1R2R20In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint.
CR-SW-0036SWFunctionalLowNON-COMPLIANTR7R21If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).
CR-SW-0037SWFunctionalLowNON-COMPLIANTR32Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error.
CR-SW-0038SWFunctionalLowNON-COMPLIANTR19If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x24
CR-SYS-0199SYSDesign constraintLowNON-COMPLIANTR19R21(requestSequenceError) and shall accept programming to proceed from the state at which it was executing before this non-permitted service was requested.
CR-SYS-0200SYSDesign constraintLowCOMPLIANTFor each received RequestDownload request, the server shall check if there is a VerificationEntry match in SDSC.
CR-CYBER-0045CYBERDesign constraintLowNON-COMPLIANTR16R19R32The server shall check whether any part of the received data is encrypted or not by checking the address ranges for a match in EncryptionEntry defined in SDSC.
CR-SW-0039SWFunctionalLowNON-COMPLIANTR7R16The server shall not execute the new software until it can be verified using routine 0xFF01.
CR-SW-0040SWFunctionalLowCOMPLIANTThe server shall support service negative response as per ISO14229-1:2020.
CR-CYBER-0046CYBERDesign constraintLowCOMPLIANTIn case a software is encrypted, the server shall decrypt the software before decompression and software hash comparison verification are performed.
CR-SYS-0201SYSDesign constraintLowCOMPLIANTIn case a software is compressed, the server shall decompress the software before software hash comparison verification is performed.
CR-SYS-0202SYSDesign constraintLowNON-COMPLIANTR17R19The server shall verify the software hash after decryption and/or decompression are performed.
CR-SW-0041SWFunctionalLowCOMPLIANTThe server shall support request formatted according to ISO14229-1:2020.
CR-SW-0042SWFunctionalLowCOMPLIANTThe server shall support positive response formatted according to ISO14229-1:2020.
CR-SW-0043SWFunctionalLowNON-COMPLIANTR32If for any reason an error occurs during decryption of data, the server shall return NRC 0x10.
CR-SW-0044SWFunctionalLowCOMPLIANTThe server shall support parameter blockSequenceCounter formatted according to ISO14229-1:2020.
CR-SW-0045SWFunctionalLowCOMPLIANTThe server shall support parameter transferRequestParameterRecord formatted according to ISO14229-1:2020.
CR-SYS-0203SYSDesign constraintLowNON-COMPLIANTR16The server shall not support transferRequestParameterRecord parameter.
CR-SYS-0204SYSDesign constraintLowNON-COMPLIANTR16The server shall not support transferResponseParameterRecord parameter.
CR-SW-0046SWFunctionalLowCOMPLIANTThe server shall support service 0x84 according to CVS32.
CR-SW-0047SWFunctionalLowCOMPLIANTThe server shall support request formatted according to ISO14229-1:2020.
CR-SW-0048SWFunctionalLowCOMPLIANTThe server shall support positive response formatted according to ISO14229-1:2020.
CR-SYS-0205SYSDesign constraintLowCOMPLIANTThe server shall support negative response codes according to CVS32.
CR-SW-0049SWFunctionalLowCOMPLIANTThe server shall support parameter Administrative Parameter formatted according to ISO14229-1:2020.
CR-CYBER-0047CYBERDesign constraintLowNON-COMPLIANTR17R21The server shall support parameter Signature/Encryption Calculation (SIGENCRYPT) according to CVS32.
CR-SYS-0206SYSDesign constraintLowNON-COMPLIANTR21The server shall support parameter Anti-replay Counter (ANTIREPLAYCNT) according to CVS32.
CR-SYS-0207SYSDesign constraintLowCOMPLIANTThe server shall verify the programmed software module by calculating a checksum on the programmed data by matching this checksum with a pre-calculated checksum.
CR-SYS-0208SYSDesign constraintLowCOMPLIANTThe pre-calculated checksum shall be provided as part of the data submitted with the TransferData service request.
CR-SYS-0209SYSDesign constraintLowNON-COMPLIANTR19R21R26The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested.
CR-HW-0036HWDesign constraintLowNON-COMPLIANTR1R2R20In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint.
CR-SW-0050SWDesign constraintLowNON-COMPLIANTR16R18In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area.
CR-SW-0051SWFunctionalLowNON-COMPLIANTR7R21R32When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see section Software and data identification): • If boot software (any part) is erased, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).
CR-SW-0052SWFunctionalLowNON-COMPLIANTR16R18R21The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e., the erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase.
CR-SW-0053SWFunctionalLowNON-COMPLIANTR1R2R21E.g., 02, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements &
CR-SW-0054SWFunctionalLowNON-COMPLIANTR10R24This RoutineIdentifier shall be able to execute independent from programming sequence
CR-SW-0055SWFunctionalLowNON-COMPLIANTR1R2The client may opt to execute this routineIdentifier as a standalone procedure to check to perform a software consistency check.
CR-SYS-0210SYSDesign constraintLowNON-COMPLIANTR19The server shall check whether the individual modules are complete and compatible with one another.
CR-SYS-0211SYSFunctionalLowNON-COMPLIANTR17R19R21In addition, a check shall be made to determine whether the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data).
CR-SYS-0212SYSDesign constraintLowNON-COMPLIANTR2R17The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer.
CR-SYS-0213SYSDesign constraintLowCOMPLIANTThe consistency check shall be carried out solely by the server.
CR-CYBER-0048CYBERDesign constraintMediumCOMPLIANTThe server shall verify the integrity of the software as a part of the consistency check.
CR-CYBER-0049CYBERDesign constraintMediumCOMPLIANTThe integrity information shall be supplied to the server before the software is updated.
CR-CYBER-0050CYBERDesign constraintMediumCOMPLIANTThe integrity check shall be carried out solely by the server.
CR-SW-0056SWFunctionalMediumNON-COMPLIANTR19R21If the server set routineResult as 0x00 (CorrectResult) the server shall reject with NRC 0x24 the following diagnostic services and routines until a new SDSC is provided
CR-SW-0057SWFunctionalLowCOMPLIANTThe server shall hash the receipt number with the routineStatus routineResult parameter, in this respective order.
CR-SYS-0214SYSDesign constraintLowCOMPLIANTThe hash algorithm shall be SHA512.
CR-SYS-0215SYSDesign constraintLowCOMPLIANTThe server shall sign the hashed output using the receipt-keys.
CR-CYBER-0051CYBERDesign constraintLowCOMPLIANTThe server shall use ED25519 as signature algorithm.
CR-SW-0058SWFunctionalLowCOMPLIANTThe server shall return in the parameter routineResultProof the signed hash.
CR-SW-0059SWFunctionalLowCOMPLIANTThe client shall send the Servers routineStatus routineResult response to the backend.
CR-SYS-0216SYSDesign constraintLowCOMPLIANTOnce a SDSC has being accepted by the server, the server shall store in the NVM the receipt number sent over as part of the EMP request.
CR-SW-0060SWFunctionalMediumNON-COMPLIANTR7Once a SDSC has being accepted by the server, the server shall accept the following diagnostic services and routines: • Routine 0xFF00 Erase Memory
CR-SW-0061SWFunctionalLowNON-COMPLIANTR7The server shall support the routine negative response according to CVS33.
CR-SYS-0217SYSDesign constraintLowCOMPLIANTThe server shall support the parameter EMP message according to CVS33.
CR-CYBER-0052CYBERDesign constraintMediumNON-COMPLIANTR1R2R19R21The information required for the server for verifying software integrity and optionally decrypt the transported data from a trusted source, is described in a Software Data Security Container (SDSC).
CR-SYS-0218SYSDesign constraintLowCOMPLIANTThe server shall implement SDSC structure as defined in CVS154.
CR-HW-0037HWDesign constraintLowCOMPLIANTThe range start field shall be the memory address offset from the dataLocator field.
CR-SYS-0219SYSDesign constraintLowCOMPLIANTThe range length field shall be the number of bytes to be verified.
CR-SYS-0220SYSDesign constraintLowCOMPLIANTThe supplier shall propose for each software module an identification to be used in dataLocator field in SDSC.
CR-VAL-0016VALDesign constraintLowNON-COMPLIANTR19R26The vehicle manufacturer shall review and accept the proposals for every dataLocator.
CR-SYS-0221SYSDesign constraintLowNON-COMPLIANTR17R19The start address shall be used as an offset in the software module while the length can be utilized to know which areas of the software module are to be verified and/or decrypted.
CR-SYS-0222SYSDesign constraintLowCOMPLIANTBefore accepting the SDSC as valid, the server shall perform the sanity check of the received SDSC as defined in CVS154.
CR-SYS-0223SYSDesign constraintLowNON-COMPLIANTR17If the sanity check returns fail/invalid, the server shall reject SDSC as described in CVS34.
CR-SYS-0224SYSDesign constraintLowCOMPLIANTThe server shall validate each VerificationEntry found in the SDSC.
CR-SYS-0225SYSDesign constraintLowNON-COMPLIANTR2Software hashes in the SDSC shall be verified by the server considering the ranges which are stated in the SDSC.
CR-SYS-0226SYSDesign constraintLowCOMPLIANTThe Ranges dictates the data range that the server shall begin, and end read from NVM for hashing.
CR-HW-0038HWDesign constraintLowNON-COMPLIANTR7R19The Ranges can be one or several if there are gaps between memory areas which shall be excluded from the hash calculation for some reason.
CR-SYS-0227SYSDesign constraintLowCOMPLIANTWhen hashing software, the whole memory range, including erased-only bytes of a memory module, shall be possible to include in the hash calculation.
CR-SW-0062SWDesign constraintLowNON-COMPLIANTR2R17R19R21The byte value of an erased data byte (typically FF or 00) depends on the MCU/Flash memory and shall be specified by the software supplier as an input for the hashing process.
CR-HW-0039HWDesign constraintLowNON-COMPLIANTR10The server shall be able to verify that erased-only blocks covered in range of memory are erased.
CR-SYS-0228SYSDesign constraintLowNON-COMPLIANTR17R26R32When the server has verified all verificationEntries, a result OK/NOT_OK shall be returned.
CR-SYS-0229SYSDesign constraintLowNON-COMPLIANTR16If NOT_OK is returned, the server shall not accept the new software for execution.
CR-CYBER-0053CYBERDesign constraintMediumCOMPLIANTIf OK is returned, the server shall accept that installed software is valid in terms of integrity.
CR-SYS-0230SYSDesign constraintLowCOMPLIANTThe server may execute other checks to verify the software before concluding if the installed software shall be accepted.
CR-CYBER-0054CYBERDesign constraintLowNON-COMPLIANTR16For the received data, where a match is found in the EncryptionEntry of the DSC, the server shall initialize a cipher if not previously initialized.
CR-CYBER-0055CYBERDesign constraintLowNON-COMPLIANTR5R21An initialized data (i.e., cipher scheme) shall be kept active until no more received data matches the current EncryptionEntry.
CR-CYBER-0056CYBERDesign constraintLowCOMPLIANTThe cipher shall be reinitialized for each new Encryption entry.
CR-SYS-0231SYSDesign constraintLowCOMPLIANTAccording to best practise received data shall be decrypted “on the fly” before storing to NVM.
CR-SYS-0232SYSDesign constraintLowCOMPLIANTOther methods shall be agreed upon with OEM.
CR-SYS-0233SYSDesign constraintLowNON-COMPLIANTR1R2R19The received data to decrypt may only be parts of a software module and it will be based on the range defined.
CR-CYBER-0057CYBERDesign constraintLowNON-COMPLIANTR1R2R21#00BFFFFF #008B0000 #0092FFFF Module hashData #00AFAAAA #00AFAAAB When ECU recieves data that matches an address range in an EncryptionEntry (here in Module B), the server must decrypt the data received by TransferData request.
CR-CYBER-0058CYBERDesign constraintLowNON-COMPLIANTR1R2R19R21R34Module B is encrypted meaning that when the server receives data within a range (given as address and size in RequestDownload) the server must decrypt the data before storing it.
CR-SYS-0234SYSDesign constraintLowCOMPLIANTThe User shall apply the latest version of this CVS124.
CR-SYS-0235SYSDesign constraintLowNON-COMPLIANTR1R2R8R19R26R32R34Foreword This CVS124 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.
CR-SYS-0236SYSDesign constraintLowNON-COMPLIANTR32• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.
CR-SYS-0237SYSDesign constraintLowNON-COMPLIANTR5R16An implementation which does not include a particular option shall be prepared to interoperate with another implementation which does include the option, though perhaps with reduced functionality.
CR-SYS-0238SYSDesign constraintLowNON-COMPLIANTR16R21In the same vein an implementation which does include a particular option shall be prepared to interoperate with another implementation which does not include the option (except, of course, for the feature the option provides).
CR-SYS-0239SYSDesign constraintLowNON-COMPLIANTR1R2R16R19If valid data is not needed for the use-case and system at hand, default values should be used.
CR-SYS-0240SYSDesign constraintLowNON-COMPLIANTR9E Mandatory for ECUs which shall be compliant with OBD legislation Worldwide like ISO27145,J1979 etc C Conditional U User optional.
CR-SYS-0241SYSDesign constraintLowNON-COMPLIANTR19Shall be agreed between the supplier and the vehicle manufacturer.
CR-SW-0063REQ_UDS_0001SWFunctionalLowNON-COMPLIANTR19The implementation of the client and the server shall be compliant with ISO 14229-1 with the
CR-SYS-0242REQ_UDS_0002SYSDesign constraintLowNON-COMPLIANTR18R19R26R32All deviations and extensions shall be agreed with the applicable vehicle manufacturer and shall be documented.
CR-SW-0064REQ_UDS_0005SWDesign constraintLowNON-COMPLIANTR24This DID shall be stored under flash memory module in flash memory.
CR-SW-0065REQ_UDS_0232SWDesign constraintLowNON-COMPLIANTR24This DID shall be stored under dataset module stored in flash memory.
CR-SW-0066REQ_UDS_0233SWDesign constraintLowNON-COMPLIANTR24This DID shall be stored under dataset module stored in flash memory.
CR-SYS-0243SYSDesign constraintLowNON-COMPLIANTR18R19R26Minimum length shall be 8 bytes and the assigned value shall be unique for every unit provided by one supplier per project.
CR-SW-0067REQ_UDS_0236SWDesign constraintLowNON-COMPLIANTR24This DID shall be stored under flash memory module in flash memory.
CR-SYS-0244SYSDesign constraintLowNON-COMPLIANTR1R2The format should follow the pattern: Appl: <Diag.family> <Diag.generation> Boot: <Diag.family> <Diag.generation>_BOOT
CR-HW-0040REQ_UDS_0027HWDesign constraintLowNON-COMPLIANTR24This DID shall contain a snapshot of the mandatory lifetime ECU-runtime operational data
CR-SW-0068REQ_UDS_0029SWDesign constraintLowNON-COMPLIANTR19R24This DID shall report a snapshot of the mileage of the vehicle as received on CAN or other ECU-external source at the first reception of the signal with a good signal status after a software update.
CR-SW-0069REQ_UDS_0238SWDesign constraintLowNON-COMPLIANTR24This DID shall be stored under flash memory module in flash memory.
CR-SW-0070REQ_UDS_0040SWFunctionalMediumNON-COMPLIANTR5A default diagnostic session shall be supported.
CR-SW-0071REQ_UDS_0042SWFunctionalMediumNON-COMPLIANTR5A non-default diagnostic session referred to as “extendedDiagnosticSession” shall be supported.
CR-SW-0072REQ_UDS_0043SWFunctionalHighNON-COMPLIANTR16Diagnostic sessions not defined in this document shall be agreed with the vehicle manufacturer.
CR-SW-0073REQ_UDS_0046SWFunctionalLowNON-COMPLIANTR19The mapping of RoutineControl service routines to sessions shall be discussed and agreed with the vehicle manufacturer.
CR-CYBER-0059REQ_UDS_0047CYBERDesign constraintMediumNON-COMPLIANTR21The server shall implement support for RBAC (Role Based Access Control) based on CVS151.
CR-CYBER-0060REQ_UDS_0048CYBERDesign constraintMediumNON-COMPLIANTR2R19CVS31 and CVS32 requirements preconditions per service shall be defined by the RBAC Configuration file in the ECU.
CR-SW-0074SWFunctionalLowNON-COMPLIANTR16R21The conditions that shall be checked are • Vehicle speed ~ 0 • Engine speed ~ 0 (for vehicles with IC engines) • High Voltage system disengaged ( for vehicles with high Voltage battery system) • Gear Box in neutral • Parking brake engaged Diagnostics safe state is not intended for ensuring the vehicle safety rather its conditions that are checked to prevent executing Diagnostics services during vehicle operation
CR-SYS-0245REQ_UDS_0051SYSDesign constraintLowNON-COMPLIANTR19The server implementation shall comply with the following state diagram and the following state
CR-SYS-0246REQ_UDS_0338SYSDesign constraintLowNON-COMPLIANTR19R32The session transitions stated below shall be possible to request both physically or functionally
CR-SW-0075REQ_UDS_0052SWFunctionalLowCOMPLIANTProject specific DID shall be added to ranges defined as system supplier specific in ISO 14229
CR-SW-0076REQ_UDS_0055SWFunctionalLowNON-COMPLIANTR21The SPRMIB shall be supported for services as specified in (ISO 14229-1).
CR-SW-0077REQ_UDS_0056SWFunctionalLowNON-COMPLIANTR19Negative response codes specified in ISO 14229-1 Annex A.1 shall only be supported if explicitly specified by this specification or its normative references.
CR-SW-0078REQ_UDS_0342SWFunctionalLowCOMPLIANTNegative response code 0x22, conditionsNotCorrect , shall be used if a service request is denied due to insufficient rights according to the RBACC check.
CR-SW-0079REQ_UDS_0057SWFunctionalLowNON-COMPLIANTR5A DiagnosticSessionControl service request with parameter diagnosticSessionType set to ProgrammingSession shall be processed only if normal communication is currently switched off as a result of a previous call to the Communication Control service.
CR-SW-0080SWFunctionalLowNON-COMPLIANTR16R21The application shall respond with NRC 0x22 (conditionsNotCorrect) if communication has not been switched off.
CR-SYS-0247REQ_UDS_0059SYSDesign constraintLowNON-COMPLIANTR26R32Following an accepted request to switch to the ProgrammingSession, the application shall make all preparations to guarantee trouble-free programming operation.
CR-SW-0081SWFunctionalLowNON-COMPLIANTR26R32In this process, it shall end all routines and functions that influence programming and ensure that the server checked for safe state conditions at minimal.
CR-SYS-0248REQ_UDS_0061SYSDesign constraintLowCOMPLIANTPositive response shall be sent before the actual switch in case switching to Programming session.
CR-SW-0082REQ_UDS_0241SWFunctionalLowCOMPLIANTResponse parameter diagnosticSessionType shall be as per ISO 14229-1.
CR-SW-0083REQ_UDS_0242SWFunctionalLowCOMPLIANTResponse parameter sessionParameterRecord shall be as per ISO 14229-1.
CR-SW-0084REQ_UDS_0062SWFunctionalMediumNON-COMPLIANTR5R16An ECUReset shall not be executed if the vehicle safety can be compromised.
CR-SYS-0249REQ_UDS_0063SYSDesign constraintLowCOMPLIANTECU shall execute the reset only after sending a positive response to the ECU reset service
CR-SW-0085REQ_UDS_0065SWFunctionalLowNON-COMPLIANTR34The server shall be available for ECU identification within one second after sending positive response message to an ECUReset request.
CR-HW-0041REQ_UDS_0066HWDesign constraintLowNON-COMPLIANTR34After ECU reset, ECU shall be restarted and re-initialized within 2sec.
CR-SYS-0250REQ_UDS_0067SYSDesign constraintLowNON-COMPLIANTR19R34The maximum time it takes from the positive response is sent from the server until it responds to new requests shall be agreed with vehicle manufacturer and documented.
CR-SW-0086REQ_UDS_0069SWFunctionalLowNON-COMPLIANTR17R21The ECUReset service with requestParameter value 0x01 (hardReset) shall simulate the power-on / start-up sequence performed after a server has been previously disconnected from its power supply (i.e.
CR-SYS-0251SYSDesign constraintLowNON-COMPLIANTR16the disconnect from the battery shall not be simulated.
CR-SYS-0252SYSDesign constraintLowNON-COMPLIANTR16The implementation of hardReset shall first ensure that data corruption will not occur.
CR-SW-0087REQ_UDS_0070SWFunctionalHighNON-COMPLIANTR18R19R21The ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall simulate the turning of the ignition key off and back on and shall ensure that the values of non-volatile memory locations are preserved and the volatile memory will be initialized.
CR-SW-0088REQ_UDS_0071SWFunctionalLowNON-COMPLIANTR21R26The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that every server task is finished prior sending a positive response.
CR-SW-0089REQ_UDS_0072SWFunctionalLowNON-COMPLIANTR21The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that the volatile memory buffered data is stored into non volatile memory prior sending a positive response.
CR-SW-0090SWFunctionalLowNON-COMPLIANTR19The server shall send an ECUReset positive response message after the server tasks above are finished but before the server performs the actual resetType.
CR-SW-0091REQ_UDS_0245SWFunctionalLowCOMPLIANTResponse parameter resetType shall be as per ISO 14229-1.
CR-SW-0092REQ_UDS_0075SWFunctionalLowNON-COMPLIANTR16Servers involved in engine start shall not process CommunicationControl service requests until 2 seconds after terminal 15 goes active.
CR-SW-0093SWFunctionalLowNON-COMPLIANTR19R21If a request is received before this time has passed the server shall respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) (and process the request and send a final response when 2 seconds have passed) or NRC 0x22 (conditionsNotCorrect).
CR-SW-0094REQ_UDS_0076SWFunctionalHighCOMPLIANTWhen receiving CommunicationControl service request, Gateway server applications shall ensure quieting down of network to ECUs without diagnostic server which are present in their sub-buses
CR-FUSA-0006REQ_UDS_0077FUSAFunctionalMediumNON-COMPLIANTR19Safety conditions are project specific and shall be checked before accepting a request to disable communication.
CR-SW-0095SWDesign constraintLowNON-COMPLIANTR1R2R16R17R19R21Communication control service should not only be used to improve the bandwidth situation during flashing /parametrisation but also for inhibiting systems in vehicle (like engine start) to ensure safety.
CR-SYS-0253REQ_UDS_0081SYSDesign constraintLowNON-COMPLIANTR16R32If the parameter suppressPosRespMsgIndicationBit = true in a functionally addressed request message, the service request shall not influence any ongoing physically addressed service
CR-SYS-0254SYSDesign constraintLowNON-COMPLIANTR1R2R5R32A functionally addressed TesterPresent may arrive at any time during another request.
CR-SW-0096REQ_UDS_0249SWFunctionalLowNON-COMPLIANTR19Request format and parameter shall be as per ISO 14229-1.
CR-SW-0097REQ_UDS_0343SWFunctionalLowNON-COMPLIANTR16R21Servers shall reject a ControlDTCSetting service request (DTC setting type = off) with NRC 0x22 (conditionsNotCorrect) if programming preconditions are not satisfied.
CR-SW-0098REQ_UDS_0344SWFunctionalHighNON-COMPLIANTR16R18R19R21The execution of this service in the application shall only impact the DTC setting - diagnostic tests for safety and degradations shall not be impacted (shall work as normal).
CR-SYS-0255REQ_UDS_0082SYSDesign constraintLowNON-COMPLIANTR10R34The server shall be able to switch baud rate within one second.
CR-SYS-0256REQ_UDS_0083SYSDesign constraintLowCOMPLIANTThe boot loader shall inherit the selected baud rate if the LinkControl service request was received when the server was executing in the application.
CR-SYS-0257REQ_UDS_0084SYSDesign constraintLowCOMPLIANTPositive response shall be sent before the actual switch of the baud-rate takes place.
CR-HW-0042REQ_UDS_0087HWDesign constraintLowNON-COMPLIANTR9R21If ECU supports request containing more than one data identifier it shall be documented (like in CDD, ODX etc).
CR-SW-0099REQ_UDS_0255SWFunctionalLowCOMPLIANTDataIdentifier parameter definition shall be as per ISO 14229-1.
CR-SW-0100REQ_UDS_0089SWFunctionalLowNON-COMPLIANTR32The sequence of writing data records with service 0x2E WriteDataByIdentifier shall be independent of any specific order
CR-SW-0101REQ_UDS_0091SWFunctionalLowNON-COMPLIANTR19R21R26R32All changed data shall be valid and stored into non-volatile memory at the latest after an ECU Reset(0x11) subfunction 0x02 requested from client.
CR-SW-0102REQ_UDS_0092SWFunctionalHighNON-COMPLIANTR17R19R21R32If it is necessary to force an explicit transfer of buffered data into non-volatile memory then this shall be supported both with ECU-Reset Service subfunction 0x02 and ignition (IGN) key Off/On (power cycle).
CR-SW-0103SWFunctionalLowNON-COMPLIANTR19R21If this action is necessary then it shall be integrated implicitly into ECU Reset (0x11) Service subfunction 0x02.
CR-SW-0104REQ_UDS_0258SWFunctionalLowNON-COMPLIANTR19Request format and parameter shall be as per ISO 14229-1.
CR-SW-0105REQ_UDS_0262SWFunctionalLowCOMPLIANTgroupOfDTC parameter definition shall be as per ISO 14229-1.
CR-SW-0106REQ_UDS_0266SWFunctionalLowCOMPLIANTReportNumberOfDTCByStatusMask parameter format shall be as per ISO 14229-1.
CR-SW-0107REQ_UDS_0267SWFunctionalLowCOMPLIANTDTCStatusMask parameter format shall be as per ISO 14229-1.
CR-SYS-0258REQ_UDS_0097SYSDesign constraintLowNON-COMPLIANTR24It shall be mandatory to utilize SPNs & FMIs according to SAE J1939.
CR-SW-0108REQ_UDS_0268SWFunctionalLowCOMPLIANTDTCSnapshotRecordNumber parameter format shall be as per ISO 14229-1.
CR-SW-0109REQ_UDS_0269SWFunctionalLowCOMPLIANTResponse parameter FunctionalGroupIdentifier shall be as per ISO 14229-1.
CR-SW-0110REQ_UDS_0270SWFunctionalLowCOMPLIANTDTCSeverityMaskRecord parameter format shall be as per ISO 14229-1.
CR-SW-0111REQ_UDS_0271SWFunctionalLowCOMPLIANTDTCSeverityMask parameter format shall be as per ISO 14229-1.
CR-SW-0112REQ_UDS_0273SWFunctionalLowCOMPLIANTResponse parameter DTCStatusAvailabilityMask shall be as per ISO 14229-1.
CR-SW-0113REQ_UDS_0274SWFunctionalLowCOMPLIANTResponse parameter DTCFormatIdentifier shall be as per ISO 14229-1.
CR-SW-0114REQ_UDS_0275SWFunctionalLowCOMPLIANTResponse parameter DTCCount shall be as per ISO 14229-1.
CR-SW-0115REQ_UDS_0276SWFunctionalLowCOMPLIANTResponse parameter DTCAndStatusRecord shall be as per ISO 14229-1.
CR-SW-0116REQ_UDS_0277SWFunctionalLowCOMPLIANTResponse parameter DTCRecord shall be as per ISO 14229-1.
CR-VAL-0017VALDesign constraintLowNON-COMPLIANTR16If a mechanic is working on the vehicle, the driveline shall report Not Ready and place the vehicle in the state PropulsionNotReady.
CR-HW-0043HWDesign constraintLowNON-COMPLIANTR1R2R16R19R20R21R26Range tion #54 ECU start-up and alive reasons Bits 0-3 (start-up reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6-0xE: Reserved 0xF: Not available Bits 4-7 (alive reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6: Stay alive 0x7-0xE: Reserved 0xF: Not available Note 1: While the reason for keeping the ECU alive may change during execution startup reason and alive reason are always identical at ECU startup.
CR-SW-0117SWFunctionalLowNON-COMPLIANTR19R21dependent depend ent depende nt U #65+N+M- #66+N+M dataIdentifier 0x0000 – #67+N+M +P Data required by law or regulations Signal dependent depend ent depende nt C1 #68+N+M +P DTCSnapshotRecordNumber#2 (Latest Snapshot captured) 0x02 M #69+N+M +P DTCSnapshotRecordNumberOfIdentifiers#2 0x00 : 0xFF M #70+N+M +P : #70+2*(N +M+P) See specification for DTCSnapshotRecord[]#1 This latest snapshot shall contain the same type of data and format as DTCSnapshotRecord[]#1.
CR-SW-0118REQ_UDS_0304SWFunctionalLowNON-COMPLIANTR19DTCSnapshotRecordNumber#1 & DTCSnapshotRecordNumber#2 shall correspond to first time DTC happened and latest time DTC happened correspondingly.
CR-SW-0119SWFunctionalLowNON-COMPLIANTR21R26R32For these ECUs these bytes shall contain default value 0xFF (all bytes).
CR-SW-0120SWFunctionalLowNON-COMPLIANTR16R21R26R32Byte Description Range Resolu tion 0: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m #35..#38 Total vehicle distance at the latest DTC activation [4-byte int, big endian] in section 5.7.4.1 Not used for TRATON External engine and marine ECUsFor these ECUs these bytes shall contain default value 0xFF (all bytes).
CR-SW-0121SWFunctionalLowNON-COMPLIANTR17R21R26R320: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m 0xFFF FFFFF 5 m/bit 0xFF (all bytes) C #41+(2p+1) +1 DTCExtDataRecordNumber#4 This byte shall be set to value 0x14.
CR-SW-0122REQ_UDS_0278SWFunctionalLowCOMPLIANTResponse parameter FunctionalGroupIdentifier shall be as per ISO 14229-1.
CR-SW-0123REQ_UDS_0279SWFunctionalLowCOMPLIANTResponse parameter DTCSeverityAvailabilityMask shall be as per ISO 14229-1.
CR-SW-0124REQ_UDS_0280SWFunctionalLowCOMPLIANTResponse parameter DTCAndSeverityRecord shall be as per ISO 14229-1.
CR-SW-0125REQ_UDS_0282SWFunctionalLowCOMPLIANTNegative response codes shall be as per ISO 14229-1.
CR-SW-0126REQ_UDS_0102SWFunctionalLowCOMPLIANTThe data identifier ranges specified in ISO 14229-1 shall be followed.
CR-SW-0127REQ_UDS_0284SWFunctionalLowCOMPLIANTControlEnableMaskRecord parameter format shall be as per ISO 14229-1.
CR-SW-0128REQ_UDS_0106SWFunctionalLowCOMPLIANTRequest parameter routineIdentifier shall be as per ISO 14229-1.
CR-SW-0129REQ_UDS_0288SWFunctionalLowCOMPLIANTRequest parameter routineControlOptionRecord shall be as per ISO 14229-1.
CR-SW-0130REQ_UDS_0108SWFunctionalLowNON-COMPLIANTR7If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request.
CR-HW-0044HWDesign constraintLowNON-COMPLIANTR1R2R20In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint.
CR-SW-0131REQ_UDS_0109SWFunctionalLowNON-COMPLIANTR7R21If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).
CR-SW-0132REQ_UDS_0110SWFunctionalLowNON-COMPLIANTR32Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error.
CR-SW-0133REQ_UDS_0111SWFunctionalLowNON-COMPLIANTR19If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x12 (sub
CR-SW-0134REQ_UDS_0291SWFunctionalLowCOMPLIANTMemoryAddress parameter definition shall be as per ISO 14229-1.
CR-SW-0135REQ_UDS_0292SWFunctionalLowCOMPLIANTMemorySize parameter definition shall be as per ISO 14229-1.
CR-SW-0136REQ_UDS_0294SWFunctionalLowNON-COMPLIANTR19Refer to ISO 14229-1 for negative response format and codes shall be as per ISO 14229-1.
CR-SW-0137REQ_UDS_0296SWFunctionalLowCOMPLIANTMemoryAddress parameter definition shall be as per ISO 14229-1.
CR-SW-0138REQ_UDS_0297SWFunctionalLowCOMPLIANTMemorySize parameter definition shall be as per ISO 14229-1.
CR-SYS-0259REQ_UDS_0122SYSDesign constraintLowNON-COMPLIANTR16The transferRequestParameterRecord shall not be supported.
CR-SYS-0260REQ_UDS_0124SYSDesign constraintLowNON-COMPLIANTR16The transferRequestParameterRecord shall not be supported.
CR-SYS-0261REQ_UDS_0125SYSDesign constraintLowNON-COMPLIANTR24This service shall be used when transmitting data in a secured mode, see CVS32.
CR-SW-0139REQ_UDS_0126SWFunctionalLowCOMPLIANTData parameter definition shall be as per ISO 14229-1.
CR-SYS-0262REQ_UDS_0127SYSDesign constraintLowCOMPLIANTPositive response shall be as per CVS32.
CR-SYS-0263REQ_UDS_0128SYSDesign constraintLowCOMPLIANTNegative response shall be as per CVS32 5.5.17.3.1 Supported negative response codes
CR-SW-0140REQ_UDS_0129SWFunctionalLowNON-COMPLIANTR21Negative response format shall be as per ISO 14229-1 5.5.18 Authentication (0x29) service
CR-SW-0141REQ_UDS_0130SWFunctionalLowNON-COMPLIANTR19R21Authentication (0x29) service shall be used for authentication of client and server.
CR-SW-0142REQ_UDS_0133SWFunctionalLowNON-COMPLIANTR21The Authentication (0x29) service shall be implemented according to CVS31 .
CR-SYS-0264REQ_UDS_0139SYSDesign constraintLowNON-COMPLIANTR19For detailed error cases and the mapping to the corresponding NRCs the Authentication service implementation specification CVS31 shall be used.
CR-SYS-0265SYSDesign constraintLowNON-COMPLIANTR16If the file is not stored at the location the file shall be added.
CR-SW-0143SWFunctionalLowNON-COMPLIANTR21M 0x04 ReadFile This value shall be used to read the file (upload) at the location defined by the filePathAndName parameter.
CR-SW-0144SWFunctionalLowCOMPLIANTU 0x05 ReadDir This value shall be used to read the directory defined in the filePathAndName parameter.
CR-SW-0145SWFunctionalLowCOMPLIANTU 0x06 ResumeFile This value shall be used to resume downloading the file defined in the filePathAndName parameter at the returned filePosition indicator.
CR-HW-0045HWDesign constraintLowCOMPLIANTThe file specified in the filePathAndName shall already exist in the ECU’s file system.
CR-SW-0146REQ_UDS_0142SWFunctionalLowCOMPLIANTRefer to ISO 14229-1 for parameter sub-function format shall be as per ISO 14229-1.
CR-SW-0147REQ_UDS_0146SWFunctionalLowCOMPLIANTSupported negative response codes shall be as per ISO 14229-1.
CR-SYS-0266REQ_UDS_0147SYSDesign constraintLowCOMPLIANTThe programming preconditions shall be agreed with the vehicle manufacturer. Preconditions to
CR-FUSA-0007FUSAFunctionalLowNON-COMPLIANTR16R19Preconditions to be discussed with the vehicle manufacturer shall include but not be limited to Diag safe state conditions.
CR-SYS-0267REQ_UDS_0148SYSDesign constraintLowNON-COMPLIANTR34The decision on conditions of the programming precondition shall be based on minimum two independent sources of information.
CR-SYS-0268REQ_UDS_0149SYSDesign constraintLowNON-COMPLIANTR16If information is not available for checking a programming precondition the programming precondition shall be considered fulfilled.
CR-HW-0046HWDesign constraintLowNON-COMPLIANTR19R32If the ECU received the information related to any of the conditions during the same driving cycle then it shall use that information.
CR-SW-0148REQ_UDS_0150SWFunctionalLowNON-COMPLIANTR7R19R24R32This routine shall be supported in Extended session of both Application and Boot.
CR-SW-0149REQ_UDS_0151SWFunctionalLowNON-COMPLIANTR16Request parameter RoutineControlOptionRecord shall not be supported.
CR-SW-0150REQ_UDS_0152SWFunctionalLowNON-COMPLIANTR16R21Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported.
CR-SW-0151REQ_UDS_0156SWFunctionalLowNON-COMPLIANTR26R32If all preconditions are satisfied, no routineStatus byte shall be reported.
CR-SYS-0269REQ_UDS_0158SYSDesign constraintLowNON-COMPLIANTR19R21R26The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested.
CR-HW-0047HWDesign constraintLowNON-COMPLIANTR1R2R20In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint.
CR-SW-0152REQ_UDS_0159SWDesign constraintLowNON-COMPLIANTR16R18In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area.
CR-SW-0153REQ_UDS_0160SWFunctionalLowNON-COMPLIANTR19When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see
CR-SW-0154REQ_UDS_0161SWFunctionalLowNON-COMPLIANTR16R21The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e.
CR-HW-0048HWDesign constraintLowCOMPLIANTthe erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase.
CR-SW-0155REQ_UDS_0162SWFunctionalLowNON-COMPLIANTR7R24This routine shall be supported in Programming session.
CR-SW-0156REQ_UDS_0164SWFunctionalLowNON-COMPLIANTR16R21Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported 5.6.2.2 Request parameter addressAndLengthFormatIdentifier
CR-SW-0157SWFunctionalLowNON-COMPLIANTR1R2R2102, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements & &
CR-SW-0158REQ_UDS_0166SWFunctionalLowCOMPLIANTWhen the addressAndLengthFormatIdentifier is set to 0x01 the following defined module to index mapping shall apply for the memoryStartAddress: 1 – Boot loader 2 – Application 3 – Application Data 4 ...
CR-MECH-0040REQ_UDS_0169MECHDesign constraintLowNON-COMPLIANTR1R2R19The RoutineIdentifier may verify the authenticity of the received file package. See CVS123 and
CR-CYBER-0061REQ_UDS_0170CYBERDesign constraintLowNON-COMPLIANTR26R32If authenticity verification is valid the server shall initiate all necessary steps for installation of the received file.
CR-SW-0159REQ_UDS_0171SWFunctionalLowNON-COMPLIANTR32The server shall send a response to RoutineIdentifier 0x2401 Software Installation without any further inputs from the client.
CR-SW-0160REQ_UDS_0172SWFunctionalLowNON-COMPLIANTR19R21If authenticity verification fails the server shall send the positive response with AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) set to 0x02 (Authenticity Verification Failed) and SoftwareInstallationStatus bit 7-6 (InstallationStatus) set to 0x02 (Installation Failed).
CR-SW-0161REQ_UDS_0173SWFunctionalLowNON-COMPLIANTR7R24This routine shall be supported in Programming session.
CR-SW-0162REQ_UDS_0174SWFunctionalLowNON-COMPLIANTR16Request parameter RoutineControlOptionRecord shall not be supported.
CR-SW-0163REQ_UDS_0175SWFunctionalLowNON-COMPLIANTR21Positive responses to RoutineControl (Software Installation) service requests shall be formatted
CR-CYBER-0062REQ_UDS_0177CYBERDesign constraintLowNON-COMPLIANTR21AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall remain as 0x0 (Software Authenticity Invalid) until the verification completes.
CR-SW-0164REQ_UDS_0178SWFunctionalLowNON-COMPLIANTR21If no authenticity verification will take place as part of RoutineIdentifier, the AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall be changed to 0x1 (Authenticity Verification Successful).
CR-SYS-0270REQ_UDS_0180SYSDesign constraintLowNON-COMPLIANTR21SoftwareInstallationStatus bit 7-6 (InstallationStatus) shall remain as 0x0 (Installation On-going) until the installation completes.
CR-SYS-0271SYSDesign constraintLowCOMPLIANTInformation shall be provided in percentage.
CR-SYS-0272REQ_UDS_0182SYSDesign constraintLowCOMPLIANTTimeRemaningEstimative shall inform the time estimative to complete the installation of the file.
CR-SYS-0273SYSDesign constraintLowCOMPLIANTInformation shall be provided in seconds.
CR-SW-0165SWFunctionalLowNON-COMPLIANTR9R16R19R21Whereas the result of the dependency check is returned as part of a positive response, a negative response code (NRC) shall be returned if the normal conditions according to (ISO 14229-1) (authentication, service request length, parameter range check etc) for performing the service are not correct.
CR-SW-0166SWFunctionalLowNON-COMPLIANTR1R2R10R19R24This RoutineIdentifier value allows the client to start a consistency check of the server and should be able to execute independent from programming sequence.
CR-SYS-0274REQ_UDS_0183SYSDesign constraintLowNON-COMPLIANTR16R19The server shall check whether or not the individual modules are complete and compatible with
CR-SYS-0275SYSFunctionalLowNON-COMPLIANTR16R17R19R21In addition, a check shall be made to determine whether or not the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data).
CR-SYS-0276REQ_UDS_0184SYSDesign constraintLowNON-COMPLIANTR2R17The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer.
CR-SYS-0277REQ_UDS_0185SYSDesign constraintLowCOMPLIANTThe consistency check shall be carried out solely by the server.
CR-CYBER-0063REQ_UDS_0186CYBERDesign constraintMediumNON-COMPLIANTR19The server shall verify the authenticity and integrity of the software as a part of the consistency check.
CR-CYBER-0064REQ_UDS_0187CYBERDesign constraintMediumNON-COMPLIANTR19The authenticity and integrity information shall be supplied to the server before the software is updated.
CR-CYBER-0065REQ_UDS_0188CYBERDesign constraintMediumNON-COMPLIANTR19The authenticity and integrity check shall be carried out solely by the server.
CR-SW-0167REQ_UDS_0189SWFunctionalLowNON-COMPLIANTR7R24This routine shall be supported in Programming session.
CR-SW-0168REQ_UDS_0195SWFunctionalLowNON-COMPLIANTR7R19R24R26R32This routine shall be supported in all sessions of Application and Boot.
CR-SW-0169REQ_UDS_0197SWFunctionalLowNON-COMPLIANTR16R32DTC status bits shall not make use of any vehicle manufacturer specific reset condition (e.g.
CR-SYS-0278REQ_UDS_0198SYSDesign constraintLowNON-COMPLIANTR34The occurrence counter minimum value shall be zero (0).
CR-SYS-0279REQ_UDS_0199SYSDesign constraintLowNON-COMPLIANTR34The occurrence counter maximum value shall be 126.
CR-SYS-0280REQ_UDS_0200SYSDesign constraintLowCOMPLIANTThe occurrence counter default value shall be zero (0).
CR-SYS-0281REQ_UDS_0201SYSDesign constraintLowCOMPLIANTThe occurrence counter shall increment by one (1) only.
CR-SYS-0282REQ_UDS_0202SYSDesign constraintLowNON-COMPLIANTR16R34The occurrence counter shall increment if it’s value is not at it’s maximum value already.
CR-SW-0170REQ_UDS_0203SWFunctionalLowNON-COMPLIANTR19R32The occurrence counter shall increment at a change of DTC status bits 0 testFailed and 3 confirmedDTC both from 0 to 1.
CR-SW-0171REQ_UDS_0204SWFunctionalLowCOMPLIANTThe occurrence counter shall increment at a change of DTC status bit 0 testFailed from 0 to 1,
CR-SW-0172REQ_UDS_0205SWFunctionalLowCOMPLIANTThe occurrence counter shall increment at a change of DTC status bit 3 confirmedDTC from 0 to 1, if bit 0 testFailed is 1 already.
CR-SYS-0283REQ_UDS_0206SYSDesign constraintLowCOMPLIANTThe occurrence counter value 127 shall be defined as "errors with the counter".
CR-SW-0173REQ_UDS_0207SWFunctionalLowCOMPLIANTThe timestamp default value shall be a 0xFF in each data.
CR-SW-0174REQ_UDS_0210SWFunctionalLowNON-COMPLIANTR19R21The latest occurrence shall be updated at a change of DTC status bits 0 (testFailed) and 3
CR-SW-0175REQ_UDS_0210SWFunctionalLowNON-COMPLIANTR21The latest occurrence shall be updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already.
CR-SW-0176REQ_UDS_0211SWFunctionalLowCOMPLIANTIf occurrence counter is set to 1, the timestamp of the latest occurrence shall be set to 0xFF.
CR-SW-0177REQ_UDS_0212SWFunctionalLowNON-COMPLIANTR19R21The first occurrence shall be updated at the first change of DTC status bits 0 (testFailed) and 3 5.7.4 Vehicle distance at occurrence
CR-SYS-0284REQ_UDS_0213SYSDesign constraintLowNON-COMPLIANTR2R17R21The vehicle distance shall be represented by a four byte integer, big endian, with five meter per bit (5m/bit).
CR-SW-0178REQ_UDS_0214SWFunctionalLowNON-COMPLIANTR26R32If all sources of vehicle distance information present no current data, the distance information shall be set to 0xFF at all bytes.
CR-SW-0179REQ_UDS_0219SWFunctionalLowNON-COMPLIANTR26R32If all sources of operational hours information present no current data, the operational hours information shall be set to 0xFF at all bytes.
CR-SW-0180REQ_UDS_0223SWFunctionalMediumNON-COMPLIANTR34The server shall be available for complete diagnostic communication within two seconds after a power on.
CR-SW-0181REQ_UDS_0224SWFunctionalMediumNON-COMPLIANTR1R2R16R21R34If diagnostic data is not available in time the ECU should respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) for maximum allowed time.
CR-SW-0182SWFunctionalLowNON-COMPLIANTR1R2for Linux based systems still running in boot, the server should indicate with DID 0xF1AD that it is running in boot.
CR-SYS-0285REQ_UDS_0225SYSDesign constraintLowNON-COMPLIANTR18For P2Server, the minimum value shall be 0 ms, a maximum value shall be 50 ms.
CR-SYS-0286REQ_UDS_0226SYSDesign constraintLowCOMPLIANTFor P2Client, a value of 150 ms shall be used.
CR-SYS-0287REQ_UDS_0227SYSDesign constraintLowNON-COMPLIANTR18For P2*Server, the minimum value shall be 0ms, the maximum value shall be 4000ms.
CR-SW-0183REQ_UDS_0228SWFunctionalLowCOMPLIANTFor P2*Client, the value estimation given in ISO 14229-2 shall be used.
CR-SYS-0288REQ_UDS_0229SYSDesign constraintLowNON-COMPLIANTR34The value for P4_Server_max shall be maximum 30 seconds.
CR-SYS-0289REQ_UDS_0230SYSDesign constraintLowCOMPLIANTThe system supplier shall document the implemented value for P4_Server_max.
CR-SW-0184SWFunctionalMediumNON-COMPLIANTR1R2R19R21R32RBAC for diagnostics Foreword This Commercial Vehicle Standard (“CVS151”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.
CR-SYS-0290SYSDesign constraintLowCOMPLIANTThe User shall apply the latest version of this CVS151.
CR-SW-0185SWFunctionalHighestNON-COMPLIANTR1R2R211 Scope Concepts such as secure-update (CVS37) requires Role Based Access Control (RBAC) for diagnostics (UDS).
CR-SW-0186SWFunctionalMediumNON-COMPLIANTR1R2R7R17Before a client can execute diagnostics services that are under RBAC, the client must perform some type of authorization procedure towards the server/ECU.
CR-CYBER-0066CYBERDesign constraintLowCOMPLIANTEach RBACC shall only contain one role-configuration per each supported role.
CR-CYBER-0067CYBERDesign constraintLowNON-COMPLIANTR17R34If conflicting/overlapping rules are found within a role-configuration, the server shall enforce that deny rule takes precedence over the allow rule.
CR-SYS-0291SYSDesign constraintLowNON-COMPLIANTR17R19R26R32If a matching allow/deny rule is found and all the rule settings are fulfilled, the server shall accept/deny the request.
CR-SYS-0292SYSDesign constraintLowNON-COMPLIANTR16R19R26R32If a matching rule is found and not all the rule settings are fulfilled, the server shall consider the request rejected for that rule.
CR-CYBER-0068CYBERDesign constraintLowCOMPLIANTThe server shall deny a request if no matching rule is found on RBACC.
CR-CYBER-0069CYBERDesign constraintLowNON-COMPLIANTR1R2R26R32All RBACC ALLOW rules have a setting that dictates if a request, matching the rule, must be 14229-1:2020).
CR-CYBER-0070CYBERDesign constraintLowCOMPLIANTThe server shall evaluate each role-configuration independently from each other.
CR-SW-0187SWFunctionalLowNON-COMPLIANTR21The server shall require that requests are authenticated for allow rules, using e.g., SecuredDataTransmission 0x84 (see CVS31, ISO-14229-1:2020).
CR-CYBER-0071CYBERDesign constraintLowNON-COMPLIANTR19R21The server and client shall define the RBACC as per the following ASN.1 definition: RBACC ::= SEQUENCE { version OCTET STRING (SIZE(2)), rbacc-id OCTET STRING (SIZE(16)), role-configurations SEQUENCE (SIZE(0..MAX)) OF Role-configuration } Role-configuration ::= SEQUENCE { role INTEGER(0..MAX), pattern-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), pattern-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), did-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), did-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)) }
CR-SYS-0293SYSDesign constraintLowCOMPLIANTThe server shall support in the version field two octets.
CR-SYS-0294SYSDesign constraintLowNON-COMPLIANTR19The server shall support major version value 3 and minor version value 0.
CR-SYS-0295SYSDesign constraintLowNON-COMPLIANTR18R19If other versions shall be supported is out of the scope of this document and shall be agreed upon between projects in Traton.
CR-CYBER-0072CYBERDesign constraintLowCOMPLIANTBefore RBACC is stored, the server shall verify that the server supports the structure indicated in the version number.
CR-SYS-0296SYSDesign constraintLowNON-COMPLIANTR16If the version number does not comply with the server implementation, the server shall reject storing the data.
CR-SW-0188SWFunctionalLowCOMPLIANTThe server shall report the currently stored RBACC’s version via diagnostics.
CR-CYBER-0073CYBERDesign constraintLowCOMPLIANTThe server shall support 16 octets in the rbacc-id field.
CR-SW-0189SWFunctionalLowCOMPLIANTThe server shall report the currently stored RBACC’s rbacc-id via diagnostics.
CR-CYBER-0074CYBERDesign constraintLowCOMPLIANTThe server shall support role-configurations using 32-bit unsigned integer.
CR-SW-0190SWFunctionalMediumNON-COMPLIANTR26The server shall support for every entry in the pattern-rules one octet for the pattern rule settings followed by the diagnostic pattern of variable length.
CR-SYS-0297SYSDesign constraintLowNON-COMPLIANTR26The server shall support for every entry in the did-rules one octet which represents the did-rule settings followed by two octets that represent the DID.
CR-SYS-0298SYSDesign constraintLowCOMPLIANTThe byte order for DID shall be big endian.
CR-SYS-0299SYSDesign constraintLowNON-COMPLIANTR16R17R264 Read 0 == This rule is not applicable when the DID is being read 1 == This rule is applicable when the DID is being read 5 Write 0 == This rule is not applicable when the DID is being written 1 == This rule is applicable when the DID is being written 6 IO-control 0 == This rule is not applicable when the DID is being used for IO-control 1 == This rule is applicable when the DID is being used for IO-control 7 N/A Reserved for future use 3.9 rid-rules The server shall support for every entry in the rid-rules one octet which represents the rid-rule settings followed by two octets that represent the RID.
CR-CYBER-0075CYBERDesign constraintHighestNON-COMPLIANTR17R19R32If conflicting/overlapping rules are found between the client certificate D-RBACC extension and any rules in the RBAC-configuration in the RBACC, the server shall enforce the rules in the client certificate D-RBACC extension.
CR-CYBER-0076CYBERDesign constraintLowNON-COMPLIANTR21The server shall interpret the extnValue (see snipped above) as of one instance of a RBACC (see 3.3).
CR-SYS-0300SYSDesign constraintLowNON-COMPLIANTR1R2R7R16R17R19R21R24It can also be useful if you want to add or remove access rights from a client/tester, that needs access to one or several roles, but should not have access to everything (or should have more access) specified for the assigned roles.
CR-SW-0191SWFunctionalHighCOMPLIANTThe server shall exert the RBACC roles based on the ECU-diagnostics-Role extension on the client’s certificate.
CR-CYBER-0077CYBERDesign constraintMediumCOMPLIANTThe server shall implement RBAC internal logic as per Figure 4.
CR-CYBER-0078CYBERDesign constraintMediumCOMPLIANTThe server shall implement RBAC pattern rule evaluation logic as per Figure 5.
CR-SW-0192SWFunctionalLowNON-COMPLIANTR1R2R21E.g: For the evaluate pattern the rule setting Confidentiality is set to 0x01 (Confidentiality is required).
CR-CYBER-0079CYBERDesign constraintMediumCOMPLIANTThe server shall implement RBAC did rule evaluate as per Figure 6.
CR-CYBER-0080CYBERDesign constraintMediumCOMPLIANTThe server shall implement RBAC rid rule evaluate as per Figure 7.
CR-SW-0193SWFunctionalLowNON-COMPLIANTR1R2R10R17R26R32Meaning, role 0 is particularly useful for defining services, DIDs and RIDs that should be available to all clients/users, regardless of their diagnostics role and/or authorization/authentication status.
CR-CYBER-0081CYBERDesign constraintLowCOMPLIANTThe server shall allow requests that are contained in role 0 rules regardless of the client authentication state.
CR-SW-0194SWFunctionalLowNON-COMPLIANTR21The server shall allow request that are contained in role 0 rule regardless if the request is data authenticated e.g over e.g., SecuredDataTransmission 0x84 (See CVS31, ISO 14229-1:2020).
CR-CYBER-0082CYBERDesign constraintLowCOMPLIANTThe server shall allow request that are contained in role 0 rule regardless of the value of Confidentiality field setting.
CR-SW-0195SWFunctionalMediumNON-COMPLIANTR26The server shall always allow reception of UDS authenticate 0x29 requests regardless of the RBACC settings.
CR-SW-0196SWFunctionalLowNON-COMPLIANTR1R2R16For 0x29 requests a corresponding matching rule in the RBACC is not required for the server to accept the request.
CR-SW-0197SWFunctionalMediumCOMPLIANTThe server shall evaluate the reported internal service using the RBACC rules whenever it receives a UDS Service 0x84 requests.
CR-SW-0198SWFunctionalMediumNON-COMPLIANTR26The server shall always allow reception of UDS SecuredDataTransmission 0x84 requests regardless of the RBACC settings.
CR-SW-0199SWFunctionalLowNON-COMPLIANTR1R2R16R19For 0x84 requests a corresponding matching rule in the RBACC is not required for the server to accept the 0x84 request but the server must find a corresponding matching rule for the internal request contained in the 0x84 prior to execute it.
CR-SW-0200SWFunctionalMediumNON-COMPLIANTR26The server shall always allow reception of UDS TesterPresent 0x3E requests regardless of the RBACC settings.
CR-SW-0201SWFunctionalLowNON-COMPLIANTR1R2R16For 0x3E requests a corresponding matching rule in the RBACC is not required for the server to accept the request.
CR-CYBER-0083CYBERDesign constraintMediumNON-COMPLIANTR1R2R21Annex D DynamicallyDefineDataIdentifier When this service is being used, each DID included in the request must be evaluated against the rules that are applicable for the client (the rules in the client’s certificate and in the RBACC).
CR-SYS-0301SYSDesign constraintLowNON-COMPLIANTR1R2R19R26R32The client must have read access for all included DIDs and have access to the service themselves.
CR-SYS-0302SYSDesign constraintLowNON-COMPLIANTR7R19R21R26R32When the client is performing the actual read operation (ReadDataByIdentifier [7]), the conditions and rules for all DIDs, aliased by the dynamically defined identifier, must be met, otherwise the request shall be rejected with an appropriate NRC.
CR-SYS-0303SYSDesign constraintLowNON-COMPLIANTR1R2R17R19R21Since reading of DIDs can be allowed by either a pattern-rule (starting with 22 [7]) and/or a DID-rule, both the pattern-rules and the DID-rules must be parsed when evaluating each DID.
CR-CYBER-0084CYBERDesign constraintLowNON-COMPLIANTR1R2R19R21R32Data Security Container base definition Foreword This Commercial Vehicle Standard (“CVS154”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.
CR-SYS-0304SYSDesign constraintLowCOMPLIANTThe User shall apply the latest version of this CVS154.
CR-SYS-0305SYSDesign constraintLowNON-COMPLIANTR19The server shall support a DSC Metadata block containing version and id fields.
CR-SYS-0306SYSDesign constraintLowNON-COMPLIANTR19The server shall support the Major and Minor version as specified in 3.2.
CR-SYS-0307SYSDesign constraintLowCOMPLIANTThe server shall support a DSC containing verificationEntries.
CR-CYBER-0085CYBERDesign constraintLowCOMPLIANTThe server shall support a DSC containing encryptionEntries.
CR-SYS-0308SYSDesign constraintLowCOMPLIANTThe server shall support a DSC containing itemEntries.
CR-SYS-0309SYSDesign constraintLowCOMPLIANTThe server shall expect an ASN.1 SEQUENCE tag with length zero for verificationEntries that contains no VerificationEntry items in a DSC transmitted by the client.
CR-CYBER-0086CYBERDesign constraintLowCOMPLIANTThe server shall expect an ASN.1 SEQUENCE tag with length zero for encryptionEntries that contains no EncryptionEntry items in a DSC transmitted by the client.
CR-SYS-0310SYSDesign constraintLowCOMPLIANTThe server shall expect an ASN.1 SEQUENCE tag with length zero for ItemEntries that contains no items in a DSC transmitted by the client.
CR-CYBER-0087CYBERDesign constraintLowNON-COMPLIANTR21The server shall support an empty DSC containing only Metadata (version and id) and the empty sequences for verificationEntries, encryptionEntries and ItemEntries.
CR-CYBER-0088CYBERDesign constraintLowNON-COMPLIANTR5R16R19A DSC containing only version and id states that verification and encryption is not to be performed by the server, although the server shall have the support.
CR-SYS-0311SYSDesign constraintLowCOMPLIANTVerificationEntry hashCmp states that a hash comparison shall be used to verify the data.
CR-SYS-0312SYSDesign constraintLowNON-COMPLIANTR1R2R19However, the instance specification may state specialized actions: • Server processes each VerificationEntry one by one.
CR-SYS-0313SYSDesign constraintLowNON-COMPLIANTR21• hashAlgorithm: States which HashAlgorithm (see RFC 6234) shall be used for hashing the data to verify.
CR-CYBER-0089CYBERDesign constraintLowCOMPLIANT• dataRanges: sequence of Range items - Range: Information on which data chunks that shall be verified.
CR-SYS-0314SYSDesign constraintLowCOMPLIANTThe server shall support the SHA512 HashAlgorithm as referred in 3.2 ASN1 definition.
CR-SYS-0315SYSDesign constraintLowNON-COMPLIANTR2R32For crypto agility reasons, both of the choices shall be supported by the server.
CR-SYS-0316SYSDesign constraintLowNON-COMPLIANTR21The initial counter value shall be set to 0 (zero).
CR-SYS-0317SYSDesign constraintLowCOMPLIANTRange: Information on which data chunks that shall be decrypted.
CR-SYS-0318SYSDesign constraintLowNON-COMPLIANTR19The structure version for this document release shall be: Major ‘04’ and Minor ‘00’
CR-CYBER-0090CYBERDesign constraintLowNON-COMPLIANTR21The server shall have support for the ASN.1 contents as defined: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }
CR-SYS-0319SYSDesign constraintLowNON-COMPLIANTR26R32Upon reception of a DSC to the server, before the DSC is stored in NVM, the DSC shall be semantically verified by parsing all its content.
CR-SYS-0320SYSDesign constraintLowCOMPLIANTThe length of the version field shall be verified.
CR-SYS-0321SYSDesign constraintLowNON-COMPLIANTR19The version shall be verified with the servers supported Major and Minor version of the DSC logic for compliancy.
CR-SYS-0322SYSDesign constraintLowCOMPLIANTThe length of the id field shall be verified.
CR-SYS-0323SYSDesign constraintLowNON-COMPLIANTR2The hashAlgorithm shall be supported by the server.
CR-SYS-0324SYSDesign constraintLowNON-COMPLIANTR26The length of every referenceHash shall be consistent with the output size of the hash algorithm specified in the hashAlgorithm.
CR-CYBER-0091CYBERDesign constraintLowCOMPLIANTThe verification of servers support of specified dataRanges in the VerificationEntry, shall be stated for the DSC instance.
CR-CYBER-0092CYBERDesign constraintLowNON-COMPLIANTR2The EncryptionEntry algorithm shall be supported by the server.
CR-CYBER-0093CYBERDesign constraintHighNON-COMPLIANTR19The length of key and iv shall be verified accordingly to the algorithm stipulated in EncryptionEntry.
CR-CYBER-0094CYBERDesign constraintLowCOMPLIANTThe verification of servers support of specified dataRanges in the EncryptionEntry, shall be stated for the DSC instance.
CR-SYS-0325SYSDesign constraintLowNON-COMPLIANTR21If the DSC instance is rejected by the server (see Annex A) when transmitted with EMP, an error code shall be returned to the client.
CR-CYBER-0095CYBERDesign constraintLowNON-COMPLIANTR1R2R19R21The sequence tags for verificationEntries, encryptionEntries and itemEntries are required but empty (zero length).
CR-SYS-0326SYSDesign constraintLowCOMPLIANTThe User shall apply the latest version of this CVS31.
CR-SYS-0327SYSDesign constraintLowNON-COMPLIANTR1R2R8R19R26R32R34Foreword This CVS31 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.
CR-SYS-0328SYSDesign constraintLowNON-COMPLIANTR32• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.
CR-SW-02021.1SWFunctionalLowNON-COMPLIANTR16R19R20R21R32The purpose of this document is to clarify vehicle manufacture specific extensions and exceptions to the Authentication 0x29 service specified in ISO 14229-1:2020. CVS150 Cryptographic Specification CVS32 SecuredDataTransmis sion 0x84 CVS151 RBAC CVS33 Entity Management Protocol (EMP) CVS31 Authenticate 0x29 CVS124 Traton Specification on Unified diagnostic services (UDS) CVS30 X.509 Specification CVS34 EMP – Basic Entities Figure 1 – Overview of relation between specifications The following documents are normative and indispensable for the application of this document: • Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) • ISO 14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements Whenever a requirement in this specification or the Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) is non-compliant with one or more requirements in ISO 14229-1:2020 the requirements in this specification and (CVS124) take precedence. Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer. It is the vehicle manufacturer that decides if a deviation can be accepted or not. Multiple security concepts are available in the Authentication (ISO 14229-1:2020) service, however, only APCE (ISO 14229-1:2020) is supported by the concept described in this document, see Figure 2.
CR-SYS-0329SYSDesign constraintLowNON-COMPLIANTR19R32Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer.
CR-SYS-0330SYSDesign constraintLowNON-COMPLIANTR19Shall be agreed between the supplier and the vehicle manufacturer.
CR-SW-0203SWFunctionalLowNON-COMPLIANTR16R21The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message.
CR-SW-0204SWFunctionalLowCOMPLIANTIf such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response.
CR-CYBER-0096CYBERDesign constraintLowCOMPLIANTThe request for verifyCertificateBidirectional subfunction shall be formatted according to
CR-CYBER-0097CYBERDesign constraintLowCOMPLIANTIf upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request.
CR-CYBER-0098CYBERDesign constraintLowNON-COMPLIANTR2R7R19The column “Included in proofOfOwnershipServer”, present in several message-definition tables, indicates whether the corresponding field shall be covered by the proofOfOwnershipServer signature computed by the server and included in its response.
CR-CYBER-0099CYBERDesign constraintMediumCOMPLIANTIf the server verifies the client certificate as valid, the server shall create the requested client authentication pending state.
CR-SYS-0331SYSDesign constraintLowCOMPLIANTIf an authentication pending state already exists, the server shall replace the existing
CR-SYS-0332SYSDesign constraintLowNON-COMPLIANTR24This field shall consists of 32 octets.
CR-SW-0205SWFunctionalLowNON-COMPLIANTR21The challengeClient (ISO 14229-1:2020) shall be generated using a CRNG.
CR-SW-0206SWFunctionalLowCOMPLIANTThe expected range values of lengthOfCertificateClient shall be from 0x00C8 to 0x0800.
CR-CYBER-0100CYBERDesign constraintLowCOMPLIANTThe server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request.
CR-SW-0207SWFunctionalLowNON-COMPLIANTR16R21R34If the lengthOfCertificateClient value is not within the expected range, the server shall send negative response code 0x13 (incorrectMessageLengthOrInvalidFormat).
CR-SYS-0333SYSDesign constraintLowCOMPLIANTUpon positively responding, the server shall start the Authentication completion timer.
CR-SYS-0334SYSDesign constraintLowCOMPLIANTThe challengeServer field shall consists of 32 octets generated using a CRNG.
CR-CYBER-0101CYBERDesign constraintLowNON-COMPLIANTR17The proof/signature shall be generated according to the pseudo code below.
CR-SW-0208SWFunctionalLowNON-COMPLIANTR21If upon reception of verifyCertificateBidirectional request the Authentication delay timer is running, the server shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x37, indicating requiredTimeDelayNotExpired.
CR-SW-0209SWFunctionalHighNON-COMPLIANTR21If the server verifies the client certificate as invalid, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x10, indicating generalReject.
CR-SW-0210SWFunctionalLowNON-COMPLIANTR16R19R21If the server fails or cannot determine that the authentication pending state was stored, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
CR-CYBER-0102CYBERDesign constraintLowCOMPLIANTIf the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.
CR-HW-0049HWDesign constraintLowCOMPLIANTIf an existing authentication pending state is found, the server shall verify if the Authentication completion timer is currently running.
CR-HW-0050HWDesign constraintLowCOMPLIANTIf the Authentication completion timer is currently running, the server shall continue to process the client’s proofOfOwnership request.
CR-CYBER-0103CYBERDesign constraintLowCOMPLIANTIf the client proofOfOwnership signature verification fails, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.
CR-SYS-0335SYSDesign constraintLowNON-COMPLIANTR16R19If the server fails or cannot determine that the authentication state was stored, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.
CR-CYBER-0104CYBERDesign constraintLowCOMPLIANTIf the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.
CR-SYS-0336SYSDesign constraintLowCOMPLIANTIf an active authentication state already exists, the server shall replace the existing state with the newly established one.
CR-SYS-0337SYSDesign constraintLowCOMPLIANTThe proofOfOwnershipClient shall be generated according to the pseudo code below.
CR-CYBER-0105CYBERDesign constraintLowCOMPLIANTThe signature shall be generated according to the pseudo code below.
CR-SW-0211SWFunctionalLowNON-COMPLIANTR16R21If the server determines that the client does not have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.
CR-SW-0212SWFunctionalLowNON-COMPLIANTR19R21If the server determines that the client have an existing authentication pending state and the Authentication completion timer is expired, the server shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.
CR-SW-0213SWFunctionalLowNON-COMPLIANTR16R21If the server cannot determine if the client does have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
CR-SW-0214SWFunctionalLowNON-COMPLIANTR21If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server determines that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x10, indicating generalReject.
CR-SW-0215SWFunctionalLowNON-COMPLIANTR16R21If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server cannot determine that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
CR-SW-0216SWFunctionalLowNON-COMPLIANTR21If the server is deleting the authentication pending state as consequence of failure to store the authentication state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
CR-SYS-0338SYSDesign constraintLowNON-COMPLIANTR17The server shall delete/invalidate the client’s authentication prior to positively responding to the deAuthenticate request.
CR-SW-0217SWFunctionalLowNON-COMPLIANTR16R21If the server determines that the client is not currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x24, indicating a requestSequenceError.
CR-SW-0218SWFunctionalLowNON-COMPLIANTR16R21If the server cannot determine that the client is currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x94, indicating a ResourceTemporarilyNotAvailable.
CR-SW-0219SWFunctionalLowNON-COMPLIANTR10R16R19R21If the server is unable to delete the client's authentication state or cannot verify its presence, it shall respond to the deAuthenticate request with Negative Response Code (NRC) 0x94,
CR-SW-0220SWFunctionalLowNON-COMPLIANTR1R2R10R16R19If the server is unable to delete the client’s authentication state or cannot retrieve it due to internal errors, the server responds NRC 0x94.This informs the client that the authentication state may still exist on the server.
CR-CYBER-0106CYBERDesign constraintLowCOMPLIANTThe signature algorithm used throughout the authentication process shall be ED25519.
CR-CYBER-0107CYBERDesign constraintHighestCOMPLIANTThe client shall use the private key corresponding to the client certificate to generate the signatures.
CR-CYBER-0108CYBERDesign constraintHighestCOMPLIANTThe server shall use the private key corresponding to the server certificate to generate the signatures.
CR-CYBER-0109CYBERDesign constraintLowNON-COMPLIANTR19R21The format and the structure of the certificates shall be based on (CVS30).
CR-CYBER-0110CYBERDesign constraintHighestCOMPLIANTThe server shall reject a received client’s certificate, sent using the verifyCertificateBidirectional subFunction, if it matches the server’s own certificate.
CR-CYBER-0111CYBERDesign constraintHighestNON-COMPLIANTR1R2R16R17R24It should not be possible to “unlock” the server using its own key/certificate.
CR-CYBER-0112CYBERDesign constraintHighCOMPLIANTThe server shall verify the client certificate, sent using the verifyCertificateBidirectional subFunction, according to Figure 3.
CR-CYBER-0113CYBERDesign constraintHighCOMPLIANTThe server shall verify the Signature of the Client certificate using the AUTH-CA EMP entity public key.
CR-SW-0221SWFunctionalHighNON-COMPLIANTR16R21• If the server NodeUID is not found in the NodeUID extension, the server shall reject the certificate and generate NRC 0x10 (generalReject).
CR-SYS-0339SYSDesign constraintLowNON-COMPLIANTR16If the NodeUID extension is not detected, the operation shall continue as in
CR-SW-0222SWFunctionalHighCOMPLIANTThe ECU-Diagnostic role extension shall be included in the client certificate.
CR-SYS-0340SYSDesign constraintLowCOMPLIANTThe roles shall correspond to a bit pattern-octet string.
CR-CYBER-0114CYBERDesign constraintLowNON-COMPLIANTR1R2R19The interpretation of the roles should follow as the example below: • Role 1 -> 0000 0000 0000 0000 0000 0000 0000 0001 – 00 00 00 01 • Role 32 -> 1000 0000 0000 0000 0000 0000 0000 0000 – 80 00 00 00 • Role 2 and 4 -> 0000 0000 0000 0000 0000 0000 0000 1010 – 00 00 00 0A.
CR-SW-0223SWFunctionalLowNON-COMPLIANTR1R2R32While the ECU-Diagnostic Role extension specifies the roles assigned to a client, the D-RBACC extension may both grant additional permissions and restrict permissions beyond those derived from the client’s roles.
CR-CYBER-0115CYBERDesign constraintLowCOMPLIANTIf D-RBACC extension is detected, the server shall overrule the RBACC with the D-RBACC permissions.
CR-CYBER-0116CYBERDesign constraintLowNON-COMPLIANTR26R32• The server shall validate the D-RBACC by parsing all its content. If content is invalid,
CR-SW-0224SWFunctionalHighNON-COMPLIANTR21If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.
CR-CYBER-0117CYBERDesign constraintLowCOMPLIANT• The server shall verify that the D-RBACC version provided by the client is compatible with the server’s supported D-RBACC version.
CR-SW-0225SWFunctionalHighNON-COMPLIANTR21If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.
CR-SYS-0341SYSDesign constraintLowCOMPLIANTThe basicConstraints extension CA field shall be False.
CR-CYBER-0118CYBERDesign constraintHighestNON-COMPLIANTR21The Key Usage extension (RFC 5280) shall be included in the client certificate.
CR-CYBER-0119CYBERDesign constraintHighCOMPLIANTThe Key Usage extension shall contain DigitalSignature.
CR-CYBER-0120CYBERDesign constraintHighestNON-COMPLIANTR21The Extended Key Usage extension (RFC 5280) shall be included in the client certificate.
CR-SYS-0342SYSDesign constraintLowNON-COMPLIANTR21The extension ExtendedKeyUsage shall contain clientAuth (1.3.6.1.5.5.7.3.2).
CR-CYBER-0121CYBERDesign constraintLowNON-COMPLIANTR21The extension SignatureAlgorithm shall contain ED25519 (1.3.101.112).
CR-CYBER-0122CYBERDesign constraintHighNON-COMPLIANTR20The server shall validate the certificate so that: 𝑛𝑜𝑡𝐵𝑒𝑓𝑜𝑟𝑒 ≤ 𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒-𝑡𝑖𝑚𝑒 ≤ 𝑛𝑜𝑡𝐴𝑓𝑡𝑒𝑟
CR-SW-0226SWFunctionalMediumNON-COMPLIANTR21If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication pending state.
CR-HW-0051HWDesign constraintLowNON-COMPLIANTR19R21If a client and server have successfully completed the authentication process, the server shall invalidate the authentication state in the event of: • The server is reset (i.e server is power cycled).
CR-SW-0227SWFunctionalMediumNON-COMPLIANTR21If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication state.
CR-SYS-0343SYSDesign constraintLowNON-COMPLIANTR21R34The server’s authentication pending state shall contain the minimum of (non-exhaustive list): • Client address that issued the authentication request.
CR-SYS-0344SYSDesign constraintLowNON-COMPLIANTR21R34The server’s authentication state shall contain the minimum of (non-exhaustive list): • SessionKey.
CR-SYS-0345SYSDesign constraintLowCOMPLIANTThe server shall support only one authentication state.
CR-SYS-0346SYSDesign constraintLowCOMPLIANTThe server shall support only one authentication pending state.
CR-CYBER-0123CYBERDesign constraintLowCOMPLIANTThe private keys shall be generated using a CRNG.
CR-SYS-0347SYSDesign constraintLowCOMPLIANTThe sessionKey shall be generated according to the pseudo code below.
CR-SYS-0348SYSDesign constraintLowNON-COMPLIANTR21The server shall ensure that the sessionKey is exclusively used for the application responsible for communication over securedDataTransmission (CVS32).
CR-SYS-0349SYSDesign constraintLowNON-COMPLIANTR21Solution for a CRNG shall be according to (CVS150).
CR-SW-0228SWFunctionalLowNON-COMPLIANTR21R26The server shall always allow the Authentication 0x29 service (ISO 14229-1:2020) regardless of
CR-SYS-0350SYSDesign constraintLowCOMPLIANTOnly Passive time-based de-authentication shall be supported.
CR-SYS-0351SYSDesign constraintLowCOMPLIANTThe server shall start the timer (A3) after a valid proofOfOwnership has been received.
CR-SYS-0352SYSDesign constraintLowNON-COMPLIANTR26The server shall restart the timer (A3) every time a request is received by the same client.
CR-SYS-0353SYSDesign constraintLowNON-COMPLIANTR21If the A3 timer timeouts before a new request is received (from the same client), the server shall invalidate the authentication state.
CR-SYS-0354SYSDesign constraintLowCOMPLIANTThe parameter for passive timeout based deAuthenticate shall be decided in the project.
CR-SYS-0355SYSDesign constraintLowNON-COMPLIANTR1R2R16R19The A3 timer differs from S3 timer in terms of expected behavior during timeout and should not be implemented as a single timer.
CR-CYBER-0124CYBERDesign constraintLowNON-COMPLIANTR1R2R34The delay timer represents the required minimum time between verifyCertificateBidirectional
CR-SYS-0356SYSDesign constraintLowCOMPLIANTThe delay timer shall be set to 1 second.
CR-CYBER-0125CYBERDesign constraintLowNON-COMPLIANTR16If the delay timer is not running, the server shall start it as part of verifyCertificateBidirectional request.
CR-SYS-0357SYSDesign constraintLowNON-COMPLIANTR16R32If the server can determine that a delay is not running after reset, it shall accept a subsequent authentication request without any delay.
CR-SYS-0358SYSDesign constraintLowNON-COMPLIANTR16R32If the server cannot determine that a delay is not running after reset, it shall not accept a subsequent authentication request without any delay.
CR-SYS-0359SYSDesign constraintLowCOMPLIANTThe Authentication completion timer shall be set to 1 minute.
CR-SYS-0360SYSDesign constraintLowCOMPLIANTThe User shall apply the latest version of this CVS32.
CR-SYS-0361SYSDesign constraintLowNON-COMPLIANTR1R2R8R19R26R32R34Foreword This CVS32 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.
CR-SYS-0362SYSDesign constraintLowNON-COMPLIANTR32• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.
CR-SW-02291.3SWFunctionalMediumNON-COMPLIANTR1R2R7R9R19R26R32The mnemonics defined in the ISO14229-1:2020 [1] standard are reused throughout this document. Some paragraphs in this document includes pseudo code. The pseudo code make use of the following notation: 𝑋 || 𝑌 The concatenation of the octet strings 𝑋 and 𝑌 𝑋𝑠𝑒𝑟𝑣𝑒𝑟 𝑋 is owned by the Server 𝑋𝑐𝑙𝑖𝑒𝑛𝑡 𝑋 is owned by the Client The first occurrence of an abbreviation or term in this document will appear italicized to indicate that it is explained in section 1.4 Abbreviations or section 1.5 Terminology. All paragraphs from here on in this document are assigned unique tags, composed of a prefix and an identification number for non-ambiguous identification. SDT_REQ X identifies a requirement, and tag SDT_INFO X is used to denote informational text. Whether a requirement refers to client-side or server-side behavior is clear from the context and the requirement text itself. The keywords “shall”, “should”, “must” and so forth are used in this document and are to be interpreted in accordance with “Key words for use in RFCs to Indicate Requirement Levels” [10].
CR-CYBER-0126CYBERDesign constraintHighNON-COMPLIANTR1R2R9The keywords “shall”, “should”, “must” and so forth are used in this document and are to be interpreted in accordance with “Key words for use in RFCs to Indicate Requirement Levels” [10].
CR-SYS-0363SYSDesign constraintLowNON-COMPLIANTR21The implementation of SDT (SecuredDataTransmission) shall follow the information provided in
CR-SW-0230SWFunctionalLowCOMPLIANTWhenever a requirement in this document deviates from requirements in ISO14229-1 [1] the requirements of this document shall take precedence.
CR-SW-0231SWFunctionalHighNON-COMPLIANTR19R26R32one diagnostic server in the boot-loader and one in the application, shall support SDT in all execution states.
CR-SW-0232SWFunctionalLowNON-COMPLIANTR19The SDT server shall use the diagnostic tester address of the SDT client to identify the authentication state and hence the SecuredDataTransmissionKey.
CR-SYS-0364SYSDesign constraintLowNON-COMPLIANTR1R2R21(There may be more than one authentication state).
CR-SW-0233SWFunctionalLowNON-COMPLIANTR16R21The server shall not allow an SDT message with service 0x84 as the application layer service (service 0x84 encapsulated inside another service 0x84).
CR-SW-0234SWFunctionalLowCOMPLIANTThe server shall respond with application layer NRC 0x39, i.e.
CR-SYS-0365SYSDesign constraintLowNON-COMPLIANTR19the response shall be a properly formatted SDT positive 3 ISO 14299-1:2020 Clarifications and Deviations 3.1 Anti-replay Protection and Transaction Coherency Anti-replay protection for SDT messages is provided by the ANTIREPLAYCNT protocol element.
CR-SYS-0366SYSDesign constraintLowNON-COMPLIANTR19R32Both client and server shall maintain instances of the state variables PREQARC and PRESARC.
CR-SYS-0367SYSDesign constraintLowCOMPLIANTAt construction of an SDT request, the client shall increment PREQARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value.
CR-SYS-0368SYSDesign constraintLowNON-COMPLIANTR19R34At reception of an SDT request, the server shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PREQARC, and if the message can be otherwise verified, update PREQARC to reflect the new value, i.e.
CR-SYS-0369SYSDesign constraintLowCOMPLIANTAt construction of an SDT response, the server shall increment PRESARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value.
CR-SYS-0370SYSDesign constraintLowNON-COMPLIANTR19R34At reception of an SDT response, the client shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PRESARC, and if the message can be otherwise verified, update PRESARC to reflect the new value, i.e.
CR-SYS-0371SYSDesign constraintLowNON-COMPLIANTR1R2The client should populate the ANTIREPLAYCNT protocol element of the first request of an
CR-SYS-0372SYSDesign constraintLowNON-COMPLIANTR1R2The server should populate the ANTIREPLAYCNT protocol element of the first response of an SDT sequence with the value zero (0), and set PRESARC accordingly.
CR-SW-0235SWFunctionalLowNON-COMPLIANTR19R21R34If either PREQARC or PRESARC reaches the maximum value 65535 (0xFFFF), the client shall re-authenticate if it wishes to send more messages.
CR-SYS-0373SYSDesign constraintLowCOMPLIANTThe client shall maintain the state variable PREQTAG.
CR-CYBER-0127CYBERDesign constraintLowNON-COMPLIANTR19The CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305 shall be supported.
CR-CYBER-0128CYBERDesign constraintLowNON-COMPLIANTR17At SDT message reception, the recipient shall verify/decrypt the message using the CipherScheme indicated by the SIGENCRYPT protocol element.
CR-CYBER-0129CYBERDesign constraintLowCOMPLIANTIn case of a positive SDT response, the server shall respond to a client request with the same CipherScheme used in the request.
CR-CYBER-0130CYBERDesign constraintLowNON-COMPLIANTR1R2R34The client may alter the CipherScheme between SDT requests within the same SDT sequence.
CR-CYBER-0131CYBERDesign constraintHighNON-COMPLIANTR1R2Client and server should keep state variables that indicate which CipherScheme, and resulting key, was used in the previous SDT transaction.
CR-CYBER-0132CYBERDesign constraintLowNON-COMPLIANTR1R2R17At construction of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the client should re-run the KDF, and if and only if the authentication/encryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values.
CR-CYBER-0133CYBERDesign constraintLowNON-COMPLIANTR1R2R17At reception of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the server should re-run the KDF, and if and only if the verification/decryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values.
CR-CYBER-0134CYBERDesign constraintMediumNON-COMPLIANTR21Client Server PREQARC = X PREQTAG=TAG_X PSIGENCRYPT=3 PKEY=p..p Check: ANTIREPLAYCNT > PREQARC SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r decrypt(data, TAG_X+1)->ok Check: ANTIREPLAYCNT > PRESARC decrypt(data||PREQTAG, TAG_Y+1)->ok PRESARC = Y+1 PRESARC = Y+1 PREQARC = X PSIGENCRYPT=3 PKEY=p..p encrypt(data)->TAG_X+1 encrypt(data||TAG_X+1)->TAG_Y+1 S1 S2 S3 C1 C2 C3 SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r Figure 4 – Change of CipherScheme mid sequence 3.2.1 HKDF Key Derivation Client and server shall support the HKDF [2] key derivation function using HMAC-SHA512 [3].
CR-SW-0236SWFunctionalLowCOMPLIANTikm : The ikm argument to the HKDF function shall be the octet string containing the SecuredDataTransmissionKey from the service 0x29 authentication state.
CR-CYBER-0135CYBERDesign constraintLowNON-COMPLIANTR21salt: The salt argument to the HKDF function shall be set as the zero length octet string (null).
CR-SW-0237SWFunctionalLowNON-COMPLIANTR19info: The info argument to the HKDF function shall be set as the concatenation of the “SDT_0x84_KEY” octet string and the CipherScheme identifier.
CR-CYBER-0136CYBERDesign constraintLowCOMPLIANTThe L argument to the HKDF function shall be set to 64.
CR-CYBER-0137CYBERDesign constraintHighestCOMPLIANTOctets 0-31 of the okm shall be used as key by the client to encrypt, and the server to decrypt, the request.
CR-CYBER-0138CYBERDesign constraintHighestCOMPLIANTOctets 32-63 of the okm shall be used as key by the server to encrypt, and the client to decrypt, the response.
CR-CYBER-0139CYBERDesign constraintHighestNON-COMPLIANTR18R19R21Figure 5 – Use of HKDF output key material (okm) with SDT_CHACHA20_POLY1305 In subsequent sections (3.2.2.1 and 3.2.2.2) the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets.
CR-SYS-0374SYSDesign constraintLowNON-COMPLIANTR18𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT.
CR-SYS-0375SYSDesign constraintLowNON-COMPLIANTR19R21𝑃: The 𝑃 (Plaintext) argument shall be the octet string that is the concatenation of the INTMSGREQID and SRVSPECPARAM.
CR-SYS-0376SYSDesign constraintLowCOMPLIANT𝐶: When injected into, or extracted from an SDT message, the first octet of 𝐶 shall correspond to INTMSGREQID, and the remaining octets to SRVSPECPARAM.
CR-CYBER-0140CYBERDesign constraintMediumNON-COMPLIANTR19The client shall encrypt and authenticate the SDT request with the 𝐴 argument set to the
CR-SYS-0377SYSDesign constraintLowNON-COMPLIANTR20The client shall populate the APAR protocol element in the request so that bits 0, 4, 5 and 6 are set to true.
CR-SW-0238SWFunctionalLowNON-COMPLIANTR21The client shall populate the SIGLEN protocol element in the request with 16 (0x0010).
CR-SYS-0378SYSDesign constraintLowCOMPLIANTThe client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.
CR-SYS-0379SYSDesign constraintLowCOMPLIANTThe client shall store 𝑇𝐴𝐺 in its state variable PREQTAG.
CR-CYBER-0141CYBERDesign constraintLowNON-COMPLIANTR17R21𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑑𝑒𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝐶, 𝑇𝐴𝐺) → 𝑜𝑘/𝑛𝑜𝑘, 𝑃 The client shall decrypt and verify the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN, ANTIREPLAYCNT protocol elements of the response and the value stored in the state variable PREQTAG.
CR-CYBER-0142CYBERDesign constraintLowCOMPLIANTThe server shall decrypt and verify the SDT request with the 𝐴 argument set to the concatenated octet string comprised of the SDT, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements.
CR-CYBER-0143CYBERDesign constraintMediumNON-COMPLIANTR21𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑒𝑛𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝑃) → 𝐶, 𝑇𝐴𝐺 The server shall encrypt and authenticate the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the octet string carried by the SIGMACBYTE protocol element of the corresponding request.
CR-SYS-0380SYSDesign constraintLowNON-COMPLIANTR19R20The server shall populate the APAR protocol element in the response so that bits 4 and 5 are set to true.
CR-SW-0239SWFunctionalLowNON-COMPLIANTR21The server shall populate the SIGLEN protocol element in the request with 16 (0x0010).
CR-SYS-0381SYSDesign constraintLowCOMPLIANTThe server shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.
CR-SYS-0382SYSDesign constraintLowNON-COMPLIANTR1R2one octet, and the rest should go in the SRVSPECPARAM protocol element.
CR-CYBER-0144CYBERDesign constraintLowCOMPLIANTThe L argument to the HKDF function shall be set to 64.
CR-CYBER-0145CYBERDesign constraintMediumCOMPLIANTOctets 0-31 of the okm shall be used as key by the client to authenticate, and the server to verify, the request.
CR-CYBER-0146CYBERDesign constraintMediumCOMPLIANTOctets 32-63 of the okm shall be used as key by the server to authenticate, and the client to verify, the response.
CR-CYBER-0147CYBERDesign constraintHighestNON-COMPLIANTR18R19R21Figure 7 – Use of HKDF output key material (okm) with SDT_POLY1305 In subsequent sections (3.2.3.1 and 3.2.3.2), the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets.
CR-SYS-0383SYSDesign constraintLowNON-COMPLIANTR18𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT.
CR-SYS-0384SYSDesign constraintLowCOMPLIANTThe client shall authenticate the SDT request with the 𝐴 argument set to the octet string
CR-SYS-0385SYSDesign constraintLowNON-COMPLIANTR20The client shall populate the APAR protocol element in the request so that bits 0, 5 and 6 are set to true.
CR-SW-0240SWFunctionalLowNON-COMPLIANTR21The client shall populate the SIGLEN protocol element in the request with 16 (0x0010).
CR-SYS-0386SYSDesign constraintLowCOMPLIANTThe client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.
CR-SYS-0387SYSDesign constraintLowCOMPLIANTThe client shall store 𝑇𝐴𝐺 in its state variable PREQTAG.
CR-SYS-0388SYSDesign constraintLowNON-COMPLIANTR26R32The client shall verify the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string stored in the state variable PREQTAG.
CR-SYS-0389SYSDesign constraintLowNON-COMPLIANTR26R32The server shall verify the SDT request with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element.
CR-SYS-0390SYSDesign constraintLowNON-COMPLIANTR26R32The server shall authenticate the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string carried by the SIGMACBYTE protocol element of the corresponding request.
CR-SYS-0391SYSDesign constraintLowNON-COMPLIANTR20The server shall populate the APAR protocol element in the response so that bit 5 is set to true.
CR-SW-0241SWFunctionalLowNON-COMPLIANTR21The server shall populate the SIGLEN protocol element in the response with 16 (0x0010).
CR-SYS-0392SYSDesign constraintLowCOMPLIANTThe client shall populate the SIGMACBYTE protocol element in the response with 𝑇𝐴𝐺.
CR-SW-0242SWFunctionalMediumNON-COMPLIANTR1R2The SDT positive response may of course contain an encapsulated negative UDS response.
CR-SW-0243SWFunctionalLowCOMPLIANTOther than the NRCs 0x3A, 0x13 and 0x21, specified by ISO14229-1:2020 [1], the server shall support the NRC 0x34 “authenticationRequired”.
CR-CYBER-0148CYBERDesign constraintLowCOMPLIANTAt reception of an SDT request, if the security sub-layer is busy, the server shall respond with
CR-SW-0244SWFunctionalLowCOMPLIANTAt reception of an SDT request, if the requesting client is unauthenticated, the server shall respond with an SDT negative response using the NRC 0x34.
CR-SW-0245SWFunctionalLowNON-COMPLIANTR19At reception of an SDT request, if the request is too short or otherwise malformed, the server shall respond with an SDT negative response using the NRC 0x13.
CR-SW-0246SWFunctionalLowCOMPLIANTAt reception of an SDT request, if ANTIREPLAYCNT ≤ PREQARC, the server shall respond with an SDT negative response using the NRC 0x3A.
CR-SW-0247SWFunctionalLowCOMPLIANTAt reception of an SDT request, if PRESARC is exhausted, the server shall respond with an SDT negative response using the NRC 0x3A.
CR-SW-0248SWFunctionalLowNON-COMPLIANTR16At reception of an SDT request, if SIGENCRYPT is not supported, the server shall respond with an SDT negative response using the NRC 0x3A.
CR-SW-0249SWFunctionalLowCOMPLIANTAt reception of an SDT request, if APAR is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A.
CR-SW-0250SWFunctionalLowCOMPLIANTAt reception of an SDT request, if SIGLEN is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A.
CR-SW-0251SWFunctionalLowNON-COMPLIANTR17At reception of an SDT request, if the server fails to verify/decrypt the request, the server shall respond with an SDT negative response using the NRC 0x3A.
CR-SYS-0393SYSDesign constraintLowNON-COMPLIANTR17R21The server shall update its state, (set PREQARC to the value received in the ANTIREPLAYCNT protocol element in the SDT request), if and only if it successfully verifies/decrypts the SDT request.
CR-CYBER-0149CYBERDesign constraintMediumNON-COMPLIANTR17R21The server shall update its state, (increment PRESARC by one (1)), if and only if it can successfully authenticate/encrypt the SDT response (“S3”).
CR-CYBER-0150CYBERDesign constraintMediumNON-COMPLIANTR17R21The client shall update its state, (increment PREQARC by one (1), if and only if it can successfully authenticate/encrypt the SDT request (“C2”).
CR-SYS-0394SYSDesign constraintLowCOMPLIANTAt reception of an SDT response, if the client is unauthenticated, the client shall discard the
CR-SYS-0395SYSDesign constraintLowNON-COMPLIANTR19At reception of an SDT response, if the request is too short or otherwise malformed, the client shall discard the response.
CR-SYS-0396SYSDesign constraintLowCOMPLIANTAt reception of an SDT response, if ANTIREPLAYCNT ≤ PRESARC, the client shall discard the
CR-CYBER-0151CYBERDesign constraintLowNON-COMPLIANTR16At reception of an SDT response, if SIGENCRYPT is not supported, the client shall discard the
CR-CYBER-0152CYBERDesign constraintLowCOMPLIANTAt reception of an SDT response, if APAR is in conflict with SIGENCRYPT, the client shall discard the response.
CR-CYBER-0153CYBERDesign constraintLowCOMPLIANTAt reception of an SDT response, if SIGLEN is in conflict with SIGENCRYPT, the client shall discard the response.
CR-SYS-0397SYSDesign constraintLowNON-COMPLIANTR17At reception of an SDT response, if the client fails to verify/decrypt the response, the client shall discard the response.
CR-SYS-0398SYSDesign constraintLowNON-COMPLIANTR17R21The client shall update its state, (set PRESARC to the value received in the ANTIREPLAYCNT protocol element in the SDT response), if and only if it successfully verifies/decrypts the SDT response (“C3”).
CR-SW-0252SWFunctionalLowNON-COMPLIANTR21If the client determines an SDT request to be lost in transit, or, if it receives an SDT negative response with NRC BRR (0x21), the client shall • repeat the request byte for byte and leave state variables unchanged.

Stakeholder needs (202)

Need IDAreaStakeholderNeed statementDerived SSR(s)Prio
N-CYBER-001CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to implement the defined cybersecurity concept.SSR-CYBER-0001, SSR-CYBER-0002, SSR-CYBER-0003, SSR-CYBER-0002-2, SSR-CYBER-0003-2High
N-CYBER-002CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to provide the specified engineering evidence.SSR-CYBER-0004, SSR-CYBER-0005Low
N-CYBER-003CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to provide the cybersecurity risk-analysis evidence.SSR-CYBER-0006, SSR-CYBER-0007, SSR-CYBER-0008, SSR-CYBER-0009, SSR-CYBER-0010Medium
N-SYS-001SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to support the specified approval gate.SSR-SYS-0001, SSR-SYS-0002, SSR-SYS-0003, SSR-SYS-0004, SSR-SYS-0005, SSR-SYS-0006, SSR-SYS-0005-2, SSR-SYS-0005-3Medium
N-VAL-001VALKA project organizationThe KA project organization needs the ECA to provide the specified engineering evidence.SSR-VAL-0001, SSR-VAL-0002, SSR-VAL-0003, SSR-VAL-0004, SSR-VAL-0002-2Medium
N-CYBER-004CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the cybersecurity obligation defined in the traced customer requirements.SSR-CYBER-0011, SSR-CYBER-0012, SSR-CYBER-0013, SSR-CYBER-0014, SSR-CYBER-0015, SSR-CYBER-0016Low
N-CYBER-005CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the cybersecurity obligation defined in the traced customer requirements.SSR-CYBER-0017, SSR-CYBER-0018, SSR-CYBER-0019, SSR-CYBER-0020, SSR-CYBER-0021, SSR-CYBER-0022Low
N-CYBER-006CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the cybersecurity obligation defined in the traced customer requirements.SSR-CYBER-0023, SSR-CYBER-0024, SSR-CYBER-0025, SSR-CYBER-0026, SSR-CYBER-0027, SSR-CYBER-0028High
N-CYBER-007CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to undergo the specified cybersecurity testing.SSR-CYBER-0029High
N-SYS-002SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0007, SSR-SYS-0008, SSR-SYS-0009, SSR-SYS-0010, SSR-SYS-0011, SSR-SYS-0012Low
N-SYS-003SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0013, SSR-SYS-0014, SSR-SYS-0015, SSR-SYS-0016, SSR-SYS-0017, SSR-SYS-0018Low
N-SYS-004SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0019, SSR-SYS-0020, SSR-SYS-0021, SSR-SYS-0022, SSR-SYS-0023, SSR-SYS-0024Low
N-SYS-005SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0025, SSR-SYS-0026, SSR-SYS-0027, SSR-SYS-0028, SSR-SYS-0029, SSR-SYS-0030Low
N-SYS-006SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0031, SSR-SYS-0032, SSR-SYS-0033, SSR-SYS-0034, SSR-SYS-0035, SSR-SYS-0036Low
N-SYS-007SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0037, SSR-SYS-0038, SSR-SYS-0039, SSR-SYS-0040, SSR-SYS-0041, SSR-SYS-0042, SSR-SYS-0039-2Low
N-SYS-008SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0043, SSR-SYS-0044, SSR-SYS-0045, SSR-SYS-0046, SSR-SYS-0047, SSR-SYS-0048Low
N-SYS-009SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0049, SSR-SYS-0050, SSR-SYS-0051, SSR-SYS-0052, SSR-SYS-0053, SSR-SYS-0054Low
N-SYS-010SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0055, SSR-SYS-0056, SSR-SYS-0057, SSR-SYS-0058, SSR-SYS-0059, SSR-SYS-0060Low
N-SYS-011SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0061, SSR-SYS-0062, SSR-SYS-0063, SSR-SYS-0064, SSR-SYS-0065, SSR-SYS-0066Low
N-SYS-012SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0067, SSR-SYS-0068, SSR-SYS-0069, SSR-SYS-0070, SSR-SYS-0071, SSR-SYS-0072Low
N-SYS-013SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0073, SSR-SYS-0074, SSR-SYS-0075, SSR-SYS-0076, SSR-SYS-0077, SSR-SYS-0078Low
N-SYS-014SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0079, SSR-SYS-0080, SSR-SYS-0081, SSR-SYS-0082, SSR-SYS-0083, SSR-SYS-0084Low
N-SYS-015SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0085, SSR-SYS-0086, SSR-SYS-0087, SSR-SYS-0088, SSR-SYS-0089, SSR-SYS-0090Low
N-SYS-016SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0091, SSR-SYS-0092, SSR-SYS-0093, SSR-SYS-0094, SSR-SYS-0095, SSR-SYS-0096Low
N-SYS-017SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0097, SSR-SYS-0098, SSR-SYS-0099, SSR-SYS-0100, SSR-SYS-0101, SSR-SYS-0102, SSR-SYS-0099-2Low
N-SYS-018SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0103, SSR-SYS-0104, SSR-SYS-0105, SSR-SYS-0106, SSR-SYS-0107, SSR-SYS-0108Low
N-SYS-019SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0109, SSR-SYS-0110, SSR-SYS-0111, SSR-SYS-0112, SSR-SYS-0113, SSR-SYS-0114Low
N-SYS-020SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0115, SSR-SYS-0116, SSR-SYS-0117, SSR-SYS-0118, SSR-SYS-0119, SSR-SYS-0120Low
N-SYS-021SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0121, SSR-SYS-0122, SSR-SYS-0123, SSR-SYS-0124, SSR-SYS-0125, SSR-SYS-0126Low
N-SYS-022SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0127, SSR-SYS-0128, SSR-SYS-0129, SSR-SYS-0130, SSR-SYS-0131, SSR-SYS-0132, SSR-SYS-0128-2, SSR-SYS-0129-2Low
N-SYS-023SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0133, SSR-SYS-0134, SSR-SYS-0135, SSR-SYS-0136, SSR-SYS-0137, SSR-SYS-0138Low
N-SYS-024SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0139, SSR-SYS-0140, SSR-SYS-0141, SSR-SYS-0142, SSR-SYS-0143, SSR-SYS-0144Low
N-SYS-025SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0145, SSR-SYS-0146, SSR-SYS-0147, SSR-SYS-0148, SSR-SYS-0149, SSR-SYS-0150Low
N-SYS-026SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0151, SSR-SYS-0152, SSR-SYS-0153, SSR-SYS-0154, SSR-SYS-0155, SSR-SYS-0156Low
N-SYS-027SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0157, SSR-SYS-0158, SSR-SYS-0159, SSR-SYS-0160, SSR-SYS-0161, SSR-SYS-0162Low
N-SYS-028SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0163, SSR-SYS-0164, SSR-SYS-0165, SSR-SYS-0166, SSR-SYS-0167, SSR-SYS-0168, SSR-SYS-0165-2Low
N-SYS-029SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0169, SSR-SYS-0170, SSR-SYS-0171, SSR-SYS-0172, SSR-SYS-0173, SSR-SYS-0174Low
N-SYS-030SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0175, SSR-SYS-0176, SSR-SYS-0177, SSR-SYS-0178, SSR-SYS-0179, SSR-SYS-0180Low
N-SYS-031SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0181, SSR-SYS-0182, SSR-SYS-0183, SSR-SYS-0184, SSR-SYS-0185, SSR-SYS-0186Low
N-SYS-032SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0187, SSR-SYS-0188, SSR-SYS-0189, SSR-SYS-0190, SSR-SYS-0191, SSR-SYS-0192Low
N-SYS-033SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0193, SSR-SYS-0194, SSR-SYS-0195, SSR-SYS-0196, SSR-SYS-0197, SSR-SYS-0198, SSR-SYS-0197-2Low
N-SYS-034SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0199, SSR-SYS-0200, SSR-SYS-0201, SSR-SYS-0202, SSR-SYS-0203, SSR-SYS-0204Low
N-SYS-035SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0205, SSR-SYS-0206, SSR-SYS-0207, SSR-SYS-0208, SSR-SYS-0209, SSR-SYS-0210Low
N-SYS-036SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0211, SSR-SYS-0212, SSR-SYS-0213, SSR-SYS-0214, SSR-SYS-0215, SSR-SYS-0216, SSR-SYS-0214-2, SSR-SYS-0215-2Low
N-SYS-037SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0217, SSR-SYS-0218, SSR-SYS-0219, SSR-SYS-0220, SSR-SYS-0221, SSR-SYS-0222, SSR-SYS-0218-2, SSR-SYS-0220-2Low
N-SYS-038SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0223, SSR-SYS-0224, SSR-SYS-0225, SSR-SYS-0226, SSR-SYS-0227, SSR-SYS-0228, SSR-SYS-0228-2, SSR-SYS-0228-3Low
N-SYS-039SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0229, SSR-SYS-0230, SSR-SYS-0231, SSR-SYS-0232, SSR-SYS-0233, SSR-SYS-0234Low
N-SYS-040SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0235, SSR-SYS-0236, SSR-SYS-0237, SSR-SYS-0238Low
N-HW-001HWvehicle manufacturerThe vehicle manufacturer needs the ECA to provide the bill of materials.SSR-HW-0001Low
N-CYBER-008CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities.SSR-CYBER-0030Medium
N-CYBER-009CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-CYBER-0031, SSR-CYBER-0032, SSR-CYBER-0033, SSR-CYBER-0034, SSR-CYBER-0035, SSR-CYBER-0036, SSR-CYBER-0035-2High
N-CYBER-010CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-CYBER-0037, SSR-CYBER-0038Medium
N-MECH-001MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce the defined network-boundary controls.SSR-MECH-0001Low
N-SYS-041SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce the defined network-boundary controls.SSR-SYS-0239Low
N-HW-002HWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements.SSR-HW-0002, SSR-HW-0003, SSR-HW-0004, SSR-HW-0005, SSR-HW-0006, SSR-HW-0007Low
N-HW-003HWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements.SSR-HW-0008, SSR-HW-0009, SSR-HW-0010, SSR-HW-0011, SSR-HW-0012, SSR-HW-0013, SSR-HW-0009-2, SSR-HW-0013-2Low
N-HW-004HWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements.SSR-HW-0014, SSR-HW-0015, SSR-HW-0016, SSR-HW-0017, SSR-HW-0018, SSR-HW-0019, SSR-HW-0015-2Low
N-HW-005HWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements.SSR-HW-0020, SSR-HW-0021, SSR-HW-0022, SSR-HW-0023, SSR-HW-0024, SSR-HW-0025, SSR-HW-0023-2Low
N-CYBER-011CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to control cryptographic key handling.SSR-CYBER-0039, SSR-CYBER-0040, SSR-CYBER-0041, SSR-CYBER-0042, SSR-CYBER-0043, SSR-CYBER-0044Highest
N-CYBER-012CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to control cryptographic key handling.SSR-CYBER-0045, SSR-CYBER-0046, SSR-CYBER-0047, SSR-CYBER-0048, SSR-CYBER-0049, SSR-CYBER-0050, SSR-CYBER-0050-2Highest
N-CYBER-013CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to control cryptographic key handling.SSR-CYBER-0051, SSR-CYBER-0052, SSR-CYBER-0053, SSR-CYBER-0054, SSR-CYBER-0055, SSR-CYBER-0056, SSR-CYBER-0051-2, SSR-CYBER-0054-2Highest
N-SYS-042SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to control cryptographic key handling.SSR-SYS-0240, SSR-SYS-0241Low
N-CYBER-014CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-CYBER-0057, SSR-CYBER-0058, SSR-CYBER-0059, SSR-CYBER-0060Medium
N-CYBER-015CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to support vulnerability response.SSR-CYBER-0061, SSR-CYBER-0062, SSR-CYBER-0063, SSR-CYBER-0064, SSR-CYBER-0065Low
N-CYBER-016CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to support cybersecurity incident monitoring.SSR-CYBER-0066, SSR-CYBER-0067, SSR-CYBER-0068, SSR-CYBER-0069, SSR-CYBER-0070Medium
N-VAL-002VALKA project organizationThe KA project organization needs the ECA to meet the validation obligation defined in the traced customer requirements.SSR-VAL-0005, SSR-VAL-0006, SSR-VAL-0007, SSR-VAL-0008, SSR-VAL-0009, SSR-VAL-0010, SSR-VAL-0007-2, SSR-VAL-0009-2Low
N-VAL-003VALKA project organizationThe KA project organization needs the ECA to meet the validation obligation defined in the traced customer requirements.SSR-VAL-0011, SSR-VAL-0012, SSR-VAL-0013, SSR-VAL-0014, SSR-VAL-0014-2Low
N-VAL-004VALKA project organizationThe KA project organization needs the ECA to support the specified approval gate.SSR-VAL-0015Medium
N-SYS-043SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to support vulnerability response.SSR-SYS-0242Low
N-HW-006HWvehicle manufacturerThe vehicle manufacturer needs the ECA to control cryptographic key handling.SSR-HW-0026Low
N-CYBER-017CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to record the specified security events.SSR-CYBER-0071, SSR-CYBER-0072, SSR-CYBER-0071-2High
N-SYS-044SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SYS-0243, SSR-SYS-0243-2High
N-SYS-045SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SYS-0244, SSR-SYS-0245, SSR-SYS-0246, SSR-SYS-0247, SSR-SYS-0248, SSR-SYS-0249, SSR-SYS-0248-2, SSR-SYS-0249-2Medium
N-SYS-046SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SYS-0250, SSR-SYS-0251, SSR-SYS-0252, SSR-SYS-0253, SSR-SYS-0254, SSR-SYS-0255, SSR-SYS-0250-2, SSR-SYS-0250-3Low
N-SYS-047SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SYS-0256, SSR-SYS-0257, SSR-SYS-0258, SSR-SYS-0259, SSR-SYS-0260, SSR-SYS-0261, SSR-SYS-0261-2, SSR-SYS-0261-3Low
N-SYS-048SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SYS-0262, SSR-SYS-0263, SSR-SYS-0264, SSR-SYS-0265, SSR-SYS-0266, SSR-SYS-0267, SSR-SYS-0263-2, SSR-SYS-0263-3Low
N-SYS-049SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SYS-0268, SSR-SYS-0269, SSR-SYS-0270, SSR-SYS-0271, SSR-SYS-0272, SSR-SYS-0273, SSR-SYS-0268-2Low
N-SYS-050SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SYS-0274Low
N-MECH-002MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-MECH-0002, SSR-MECH-0003, SSR-MECH-0004, SSR-MECH-0005, SSR-MECH-0006, SSR-MECH-0007, SSR-MECH-0002-2, SSR-MECH-0002-3Medium
N-MECH-003MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-MECH-0008, SSR-MECH-0009, SSR-MECH-0010, SSR-MECH-0011, SSR-MECH-0012, SSR-MECH-0013, SSR-MECH-0008-2, SSR-MECH-0009-2Low
N-MECH-004MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-MECH-0014, SSR-MECH-0015, SSR-MECH-0016, SSR-MECH-0017, SSR-MECH-0014-2, SSR-MECH-0014-3, SSR-MECH-0016-2Medium
N-MECH-005MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the mechanical obligation defined in the traced customer requirements.SSR-MECH-0018, SSR-MECH-0019, SSR-MECH-0020, SSR-MECH-0021, SSR-MECH-0022, SSR-MECH-0023, SSR-MECH-0018-2, SSR-MECH-0018-3Medium
N-MECH-006MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the mechanical obligation defined in the traced customer requirements.SSR-MECH-0024, SSR-MECH-0025, SSR-MECH-0026, SSR-MECH-0027, SSR-MECH-0028, SSR-MECH-0029, SSR-MECH-0027-2, SSR-MECH-0028-2Low
N-MECH-007MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the mechanical obligation defined in the traced customer requirements.SSR-MECH-0030, SSR-MECH-0031, SSR-MECH-0032, SSR-MECH-0033, SSR-MECH-0034, SSR-MECH-0035, SSR-MECH-0030-2, SSR-MECH-0030-3Medium
N-SYS-051SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to operate within the specified electrical-supply limits.SSR-SYS-0275, SSR-SYS-0276Low
N-HW-007HWvehicle manufacturerThe vehicle manufacturer needs the ECA to acquire the specified sensor measurements.SSR-HW-0027Low
N-CYBER-018CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-CYBER-0073, SSR-CYBER-0074, SSR-CYBER-0075, SSR-CYBER-0076, SSR-CYBER-0073-2, SSR-CYBER-0075-2Medium
N-SYS-052SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SYS-0277, SSR-SYS-0278, SSR-SYS-0279, SSR-SYS-0280, SSR-SYS-0281, SSR-SYS-0282, SSR-SYS-0278-2, SSR-SYS-0278-3Low
N-SYS-053SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SYS-0283, SSR-SYS-0284, SSR-SYS-0285, SSR-SYS-0286, SSR-SYS-0287, SSR-SYS-0288, SSR-SYS-0286-2, SSR-SYS-0287-2Low
N-SYS-054SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SYS-0289, SSR-SYS-0290, SSR-SYS-0291, SSR-SYS-0292, SSR-SYS-0293, SSR-SYS-0294, SSR-SYS-0294-2Low
N-SYS-055SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SYS-0295, SSR-SYS-0296, SSR-SYS-0297, SSR-SYS-0298, SSR-SYS-0299, SSR-SYS-0300, SSR-SYS-0299-2, SSR-SYS-0300-2Low
N-SYS-056SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SYS-0301, SSR-SYS-0301-2Low
N-MECH-008MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to operate within the specified thermal limits.SSR-MECH-0036, SSR-MECH-0037, SSR-MECH-0036-2, SSR-MECH-0036-3Low
N-SYS-057SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0302, SSR-SYS-0303, SSR-SYS-0304, SSR-SYS-0305, SSR-SYS-0306, SSR-SYS-0307Low
N-SYS-058SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0308, SSR-SYS-0309, SSR-SYS-0310, SSR-SYS-0311, SSR-SYS-0312, SSR-SYS-0313Low
N-SYS-059SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements.SSR-SYS-0314Low
N-SYS-060SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to regulate clutch torque.SSR-SYS-0315, SSR-SYS-0316, SSR-SYS-0317, SSR-SYS-0317-2Highest
N-MECH-009MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to regulate actuator position.SSR-MECH-0038, SSR-MECH-0039Low
N-CYBER-019CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-CYBER-0077Low
N-SYS-061SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to operate within the specified thermal limits.SSR-SYS-0318Low
N-SW-001SWvehicle manufacturerThe vehicle manufacturer needs the ECA to regulate actuator position.SSR-SW-0001, SSR-SW-0002, SSR-SW-0001-2, SSR-SW-0001-3, SSR-SW-0002-2, SSR-SW-0002-3Low
N-SYS-062SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to regulate actuator position.SSR-SYS-0319, SSR-SYS-0320, SSR-SYS-0321Low
N-SW-002SWvehicle manufacturerThe vehicle manufacturer needs the ECA to regulate clutch torque.SSR-SW-0003High
N-SW-003SWvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-SW-0004, SSR-SW-0005Low
N-VAL-005VALKA project organizationThe KA project organization needs the ECA to exchange the specified network signals.SSR-VAL-0016, SSR-VAL-0017Low
N-SYS-063SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SYS-0322, SSR-SYS-0322-2Low
N-SW-004SWvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SW-0006, SSR-SW-0007, SSR-SW-0008, SSR-SW-0009, SSR-SW-0010, SSR-SW-0011Medium
N-SW-005SWvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SW-0012Low
N-SW-006SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0013, SSR-SW-0014, SSR-SW-0015, SSR-SW-0016, SSR-SW-0017, SSR-SW-0018, SSR-SW-0016-2Low
N-SW-007SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0019, SSR-SW-0020, SSR-SW-0021, SSR-SW-0022, SSR-SW-0023, SSR-SW-0024Low
N-SW-008SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0025, SSR-SW-0026, SSR-SW-0027, SSR-SW-0028, SSR-SW-0029, SSR-SW-0030, SSR-SW-0029-2Low
N-SW-009SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0031, SSR-SW-0032, SSR-SW-0033, SSR-SW-0034, SSR-SW-0035, SSR-SW-0036Low
N-SW-010SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0037, SSR-SW-0038, SSR-SW-0039, SSR-SW-0040, SSR-SW-0041, SSR-SW-0042, SSR-SW-0041-2Low
N-SW-011SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0043, SSR-SW-0044, SSR-SW-0045, SSR-SW-0046, SSR-SW-0047, SSR-SW-0048Low
N-SW-012SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0049, SSR-SW-0050, SSR-SW-0051, SSR-SW-0052, SSR-SW-0053, SSR-SW-0054Low
N-SW-013SWvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements.SSR-SW-0055, SSR-SW-0056, SSR-SW-0057, SSR-SW-0058, SSR-SW-0058-2Low
N-HW-008HWvehicle manufacturerThe vehicle manufacturer needs the ECA to operate within the specified thermal limits.SSR-HW-0028, SSR-HW-0029, SSR-HW-0029-2Low
N-HW-009HWvehicle manufacturerThe vehicle manufacturer needs the ECA to operate within the specified electrical-supply limits.SSR-HW-0030, SSR-HW-0031, SSR-HW-0032, SSR-HW-0033, SSR-HW-0034, SSR-HW-0031-2, SSR-HW-0033-2Low
N-SW-014SWvehicle manufacturerThe vehicle manufacturer needs the ECA to provide a verified secure-boot start-up sequence.SSR-SW-0059, SSR-SW-0059-2, SSR-SW-0059-3, SSR-SW-0059-4, SSR-SW-0059-5Medium
N-SYS-064SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-SYS-0323, SSR-SYS-0324, SSR-SYS-0325, SSR-SYS-0326, SSR-SYS-0327, SSR-SYS-0328Low
N-SYS-065SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-SYS-0329, SSR-SYS-0330, SSR-SYS-0331, SSR-SYS-0332, SSR-SYS-0333, SSR-SYS-0334Low
N-SW-015SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage diagnostic trouble codes.SSR-SW-0060, SSR-SW-0061, SSR-SW-0062, SSR-SW-0063, SSR-SW-0064, SSR-SW-0065, SSR-SW-0060-2, SSR-SW-0063-2High
N-SW-016SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage diagnostic trouble codes.SSR-SW-0066, SSR-SW-0067, SSR-SW-0068, SSR-SW-0069, SSR-SW-0070, SSR-SW-0071Low
N-SW-017SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage diagnostic trouble codes.SSR-SW-0072, SSR-SW-0073, SSR-SW-0074, SSR-SW-0075, SSR-SW-0076, SSR-SW-0077Low
N-SW-018SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage diagnostic trouble codes.SSR-SW-0078, SSR-SW-0079, SSR-SW-0080, SSR-SW-0081, SSR-SW-0082, SSR-SW-0083Low
N-SW-019SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage diagnostic trouble codes.SSR-SW-0084, SSR-SW-0085, SSR-SW-0086, SSR-SW-0087Low
N-SYS-066SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to record the specified security events.SSR-SYS-0335, SSR-SYS-0336, SSR-SYS-0337, SSR-SYS-0338, SSR-SYS-0336-2, SSR-SYS-0336-3, SSR-SYS-0336-4Low
N-HW-010HWvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-HW-0035, SSR-HW-0036, SSR-HW-0037, SSR-HW-0035-2Low
N-SYS-067SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-SYS-0339, SSR-SYS-0340, SSR-SYS-0341, SSR-SYS-0342, SSR-SYS-0343, SSR-SYS-0344, SSR-SYS-0339-2Low
N-SYS-068SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-SYS-0345, SSR-SYS-0346, SSR-SYS-0347, SSR-SYS-0348, SSR-SYS-0349, SSR-SYS-0350Low
N-SYS-069SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-SYS-0351, SSR-SYS-0352, SSR-SYS-0353, SSR-SYS-0354Low
N-FUSA-001FUSAvehicle manufacturerThe vehicle manufacturer needs the ECA to satisfy the allocated functional-safety objectives.SSR-FUSA-0001, SSR-FUSA-0002, SSR-FUSA-0003, SSR-FUSA-0004, SSR-FUSA-0001-2High
N-FUSA-002FUSAvehicle manufacturerThe vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains.SSR-FUSA-0005Medium
N-MECH-010MECHvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-MECH-0040Low
N-SW-020SWvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-SW-0088, SSR-SW-0089, SSR-SW-0090, SSR-SW-0091, SSR-SW-0092, SSR-SW-0093, SSR-SW-0088-2, SSR-SW-0088-3Medium
N-SW-021SWvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-SW-0094, SSR-SW-0095, SSR-SW-0096, SSR-SW-0097, SSR-SW-0098, SSR-SW-0099Low
N-SW-022SWvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-SW-0100, SSR-SW-0101, SSR-SW-0102, SSR-SW-0103, SSR-SW-0104, SSR-SW-0105Low
N-HW-011HWvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-HW-0038, SSR-HW-0039, SSR-HW-0040, SSR-HW-0041, SSR-HW-0042, SSR-HW-0043Low
N-HW-012HWvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-HW-0044, SSR-HW-0045Low
N-SYS-070SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities.SSR-SYS-0355, SSR-SYS-0356, SSR-SYS-0357, SSR-SYS-0358, SSR-SYS-0359, SSR-SYS-0360, SSR-SYS-0356-2, SSR-SYS-0356-3Low
N-SYS-071SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities.SSR-SYS-0361Low
N-SW-023SWvehicle manufacturerThe vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities.SSR-SW-0106, SSR-SW-0107, SSR-SW-0108, SSR-SW-0109, SSR-SW-0110, SSR-SW-0111, SSR-SW-0109-2, SSR-SW-0109-3High
N-SW-024SWvehicle manufacturerThe vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities.SSR-SW-0112, SSR-SW-0113, SSR-SW-0114High
N-SYS-072SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-SYS-0362, SSR-SYS-0363, SSR-SYS-0364, SSR-SYS-0365, SSR-SYS-0366, SSR-SYS-0367, SSR-SYS-0362-2Low
N-SYS-073SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-SYS-0368, SSR-SYS-0369, SSR-SYS-0370Low
N-SW-025SWvehicle manufacturerThe vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service.SSR-SW-0115, SSR-SW-0116, SSR-SW-0117, SSR-SW-0118, SSR-SW-0119, SSR-SW-0120High
N-SW-026SWvehicle manufacturerThe vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service.SSR-SW-0121, SSR-SW-0122, SSR-SW-0123, SSR-SW-0124, SSR-SW-0125, SSR-SW-0126Medium
N-SW-027SWvehicle manufacturerThe vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service.SSR-SW-0127, SSR-SW-0128, SSR-SW-0129, SSR-SW-0130, SSR-SW-0131, SSR-SW-0132Medium
N-SW-028SWvehicle manufacturerThe vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service.SSR-SW-0133, SSR-SW-0134, SSR-SW-0135Medium
N-HW-013HWvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-HW-0046Low
N-CYBER-020CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm.SSR-CYBER-0078, SSR-CYBER-0079, SSR-CYBER-0080, SSR-CYBER-0081, SSR-CYBER-0082, SSR-CYBER-0083Low
N-CYBER-021CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm.SSR-CYBER-0084, SSR-CYBER-0085, SSR-CYBER-0086, SSR-CYBER-0087, SSR-CYBER-0088, SSR-CYBER-0089Low
N-CYBER-022CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm.SSR-CYBER-0090, SSR-CYBER-0091, SSR-CYBER-0092, SSR-CYBER-0093, SSR-CYBER-0094, SSR-CYBER-0095, SSR-CYBER-0092-2High
N-CYBER-023CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm.SSR-CYBER-0096, SSR-CYBER-0097, SSR-CYBER-0098, SSR-CYBER-0099, SSR-CYBER-0100, SSR-CYBER-0101High
N-CYBER-024CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm.SSR-CYBER-0102, SSR-CYBER-0103, SSR-CYBER-0104, SSR-CYBER-0105, SSR-CYBER-0106, SSR-CYBER-0107, SSR-CYBER-0102-2, SSR-CYBER-0103-2Medium
N-CYBER-025CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm.SSR-CYBER-0108, SSR-CYBER-0109, SSR-CYBER-0110, SSR-CYBER-0111, SSR-CYBER-0112Medium
N-SW-029SWvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SW-0136, SSR-SW-0137, SSR-SW-0138, SSR-SW-0139, SSR-SW-0140, SSR-SW-0141Low
N-SW-030SWvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SW-0142, SSR-SW-0143, SSR-SW-0144, SSR-SW-0145, SSR-SW-0146, SSR-SW-0147Low
N-SW-031SWvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SW-0148, SSR-SW-0149, SSR-SW-0150, SSR-SW-0151, SSR-SW-0152, SSR-SW-0153Low
N-SW-032SWvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SW-0154, SSR-SW-0155, SSR-SW-0156, SSR-SW-0157, SSR-SW-0158, SSR-SW-0159Medium
N-SW-033SWvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SW-0160, SSR-SW-0161, SSR-SW-0162Low
N-CYBER-026CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to manage device certificates.SSR-CYBER-0113, SSR-CYBER-0114, SSR-CYBER-0115, SSR-CYBER-0116, SSR-CYBER-0117, SSR-CYBER-0118Highest
N-CYBER-027CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to manage device certificates.SSR-CYBER-0119, SSR-CYBER-0120, SSR-CYBER-0121, SSR-CYBER-0122, SSR-CYBER-0123, SSR-CYBER-0124Highest
N-CYBER-028CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to manage device certificates.SSR-CYBER-0125, SSR-CYBER-0126, SSR-CYBER-0127, SSR-CYBER-0128, SSR-CYBER-0129, SSR-CYBER-0130High
N-CYBER-029CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce role-based access control.SSR-CYBER-0131, SSR-CYBER-0132, SSR-CYBER-0133, SSR-CYBER-0134, SSR-CYBER-0135, SSR-CYBER-0136Medium
N-CYBER-030CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce role-based access control.SSR-CYBER-0137, SSR-CYBER-0138, SSR-CYBER-0139, SSR-CYBER-0140, SSR-CYBER-0141, SSR-CYBER-0142Medium
N-CYBER-031CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce role-based access control.SSR-CYBER-0143, SSR-CYBER-0144, SSR-CYBER-0145Medium
N-SW-034SWvehicle manufacturerThe vehicle manufacturer needs the ECA to establish a secured diagnostic session.SSR-SW-0163, SSR-SW-0164, SSR-SW-0165, SSR-SW-0166, SSR-SW-0167, SSR-SW-0168, SSR-SW-0165-2Medium
N-SW-035SWvehicle manufacturerThe vehicle manufacturer needs the ECA to establish a secured diagnostic session.SSR-SW-0169, SSR-SW-0170, SSR-SW-0171, SSR-SW-0172, SSR-SW-0173, SSR-SW-0174High
N-SW-036SWvehicle manufacturerThe vehicle manufacturer needs the ECA to establish a secured diagnostic session.SSR-SW-0175, SSR-SW-0176, SSR-SW-0177, SSR-SW-0178, SSR-SW-0179, SSR-SW-0180, SSR-SW-0175-2Low
N-SW-037SWvehicle manufacturerThe vehicle manufacturer needs the ECA to establish a secured diagnostic session.SSR-SW-0181, SSR-SW-0182Medium
N-SW-038SWvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-SW-0183, SSR-SW-0184, SSR-SW-0185, SSR-SW-0186, SSR-SW-0187, SSR-SW-0188, SSR-SW-0185-2, SSR-SW-0185-3High
N-SW-039SWvehicle manufacturerThe vehicle manufacturer needs the ECA to protect memory integrity.SSR-SW-0189, SSR-SW-0190, SSR-SW-0191, SSR-SW-0192, SSR-SW-0193, SSR-SW-0194, SSR-SW-0194-2Low
N-HW-014HWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage diagnostic trouble codes.SSR-HW-0047, SSR-HW-0047-2, SSR-HW-0047-3Low
N-HW-015HWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-HW-0048Low
N-SYS-074SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to establish a secured diagnostic session.SSR-SYS-0371, SSR-SYS-0372, SSR-SYS-0373, SSR-SYS-0374, SSR-SYS-0375, SSR-SYS-0376, SSR-SYS-0371-2Low
N-SW-040SWvehicle manufacturerThe vehicle manufacturer needs the ECA to perform authenticated software update.SSR-SW-0195, SSR-SW-0196, SSR-SW-0197, SSR-SW-0198, SSR-SW-0199, SSR-SW-0196-2Low
N-SW-041SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-SW-0200, SSR-SW-0201, SSR-SW-0202, SSR-SW-0203, SSR-SW-0204, SSR-SW-0205, SSR-SW-0200-2Low
N-SW-042SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-SW-0206, SSR-SW-0207, SSR-SW-0208, SSR-SW-0209, SSR-SW-0210, SSR-SW-0211Low
N-SW-043SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-SW-0212, SSR-SW-0213, SSR-SW-0214, SSR-SW-0215, SSR-SW-0216Low
N-SW-044SWvehicle manufacturerThe vehicle manufacturer needs the ECA to exchange the specified network signals.SSR-SW-0217Low
N-SW-045SWvehicle manufacturerThe vehicle manufacturer needs the ECA to operate within the specified electrical-supply limits.SSR-SW-0218, SSR-SW-0219, SSR-SW-0218-2, SSR-SW-0218-3Low
N-SW-046SWvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce role-based access control.SSR-SW-0220, SSR-SW-0221, SSR-SW-0222, SSR-SW-0223, SSR-SW-0224, SSR-SW-0225Highest
N-SW-047SWvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce role-based access control.SSR-SW-0226, SSR-SW-0227, SSR-SW-0228, SSR-SW-0229, SSR-SW-0230, SSR-SW-0231, SSR-SW-0230-2Medium
N-SW-048SWvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce role-based access control.SSR-SW-0232Low
N-SW-049SWvehicle manufacturerThe vehicle manufacturer needs the ECA to enter the defined safe state on detected faults.SSR-SW-0233, SSR-SW-0233-2Low
N-SW-050SWvehicle manufacturerThe vehicle manufacturer needs the ECA to enforce the defined network-boundary controls.SSR-SW-0234High
N-FUSA-003FUSAvehicle manufacturerThe vehicle manufacturer needs the ECA to meet the functional-safety obligation defined in the traced customer requirements.SSR-FUSA-0006Medium
N-SYS-075SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SYS-0377, SSR-SYS-0378, SSR-SYS-0379, SSR-SYS-0380, SSR-SYS-0381, SSR-SYS-0382Low
N-SYS-076SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SYS-0383, SSR-SYS-0384, SSR-SYS-0385, SSR-SYS-0386, SSR-SYS-0387, SSR-SYS-0388Low
N-SYS-077SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SYS-0389, SSR-SYS-0390, SSR-SYS-0391, SSR-SYS-0392, SSR-SYS-0393, SSR-SYS-0394Low
N-SYS-078SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-SYS-0395, SSR-SYS-0396, SSR-SYS-0397Low
N-FUSA-004FUSAvehicle manufacturerThe vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities.SSR-FUSA-0007Low
N-CYBER-032CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to manage calibration parameters.SSR-CYBER-0146, SSR-CYBER-0147, SSR-CYBER-0148Low
N-SW-051SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage device certificates.SSR-SW-0235, SSR-SW-0236, SSR-SW-0237, SSR-SW-0238, SSR-SW-0239, SSR-SW-0240High
N-SW-052SWvehicle manufacturerThe vehicle manufacturer needs the ECA to manage device certificates.SSR-SW-0241, SSR-SW-0242, SSR-SW-0243, SSR-SW-0244, SSR-SW-0245, SSR-SW-0241-2High
N-SW-053SWvehicle manufacturerThe vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm.SSR-SW-0246, SSR-SW-0247, SSR-SW-0248, SSR-SW-0249Low
N-CYBER-033CYBERvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-CYBER-0149, SSR-CYBER-0150, SSR-CYBER-0151, SSR-CYBER-0152, SSR-CYBER-0153Low
N-SYS-079SYSvehicle manufacturerThe vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service.SSR-SYS-0398Low
N-SW-054SWvehicle manufacturerThe vehicle manufacturer needs the ECA to implement the defined cybersecurity concept.SSR-SW-0250, SSR-SW-0250-2, SSR-SW-0250-3, SSR-SW-0250-4Low
N-HW-016HWvehicle manufacturerThe vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access.SSR-HW-0049, SSR-HW-0050, SSR-HW-0051Low
N-SW-055SWvehicle manufacturerThe vehicle manufacturer needs the ECA to control cryptographic key handling.SSR-SW-0251, SSR-SW-0252Low

System requirements — SSR (1077)

Each SSR refines a customer requirement into a self-contained ECA obligation, authored and independently checked by writer and verifier sub-agents (INCOSE GtWR v4). 688/1077 (64%) pass the automated GtWR rule engine; 66 are marked needs-clarification where the source is truncated or non-normative, each with a specific question. Complete Jira summaries are in the export.

SSR IDStatusAreaCategoryASILPrioV-methodRequirement statementParent needTraces to customerManaged unknowns / clarification
SSR-CYBER-0001CYBERDesign constraintQMLowReviewThe ECA supplier shall document in the cybersecurity concept the scope of the risk analysis, the risks identified during the risk analysis, the cybersecurity goals, the cybersecurity requirements, the mitigation strategies, and the validation and verification strategies.N-CYBER-001CR-CYBER-0001
SSR-CYBER-0002splitCYBERDesign constraintQMLowReviewThe ECA supplier shall describe the cybersecurity concept.N-CYBER-001REQ_SEC_0003
SSR-CYBER-0002-2splitCYBERDesign constraintQMLowReviewThe ECA supplier shall describe how the cybersecurity concept is implemented in the ECA hardware and in the ECA software.N-CYBER-001REQ_SEC_0003
SSR-CYBER-0003splitCYBERDesign constraintQMHighReviewThe ECA supplier shall document the accepted residual risk in the cybersecurity concept.N-CYBER-001REQ_SEC_0024
SSR-CYBER-0003-2splitCYBERDesign constraintQMHighReviewThe ECA supplier shall agree the cybersecurity concept with the vehicle manufacturer.N-CYBER-001REQ_SEC_0024
SSR-CYBER-0004CYBERDesign constraintQMLowReviewThe ECA supplier shall provide documentation describing the strategies and methods used for embedded systems cybersecurity.N-CYBER-002REQ_SEC_0001
SSR-CYBER-0005CYBERDesign constraintQMLowReviewThe ECA supplier shall provide documentation of the verification and validation methods for the cybersecurity features.N-CYBER-002REQ_SEC_0004
SSR-CYBER-0006CYBERDesign constraintQMMediumReviewFor each release, the ECA supplier shall perform a risk assessment based on a threat and vulnerability analysis that covers each vehicle manufacturer-specific adaptation.N-CYBER-003REQ_SEC_0002
SSR-CYBER-0007CYBERDesign constraintQMLowReviewFor each risk identified in the cybersecurity risk analyses, the ECA supplier shall make a risk treatment decision to avoid, reduce, share, or retain the risk.N-CYBER-003CR-CYBER-0006
SSR-CYBER-0008needs clarificationCYBERDesign constraintQMLowReviewThe ECA shall verify the data chunks identified by each Range item in the dataRanges sequence.N-CYBER-003CR-CYBER-0089CLARIFY: Should this CVS154 data-dictionary entry be captured as a verification requirement (the ECA verifies the data chunks identified by each Range in dataRanges), or is it purely a data-structure definition to be referenced rather than a standalone requirement?; Source is a CVS154 data-dictionary definition of 'dataRanges' (sequence of Range items); the concrete data chunks are defined per DSC instance, not in this item.
SSR-CYBER-0009CYBERDesign constraintQMLowReviewThe ECA supplier shall state, for the DSC instance, whether the ECA supports the specified dataRanges in the VerificationEntry.N-CYBER-003CR-CYBER-0091
SSR-CYBER-0010CYBERDesign constraintQMLowTestThe ECA supplier shall state, for the DSC instance, whether the ECA supports the specified dataRanges in the EncryptionEntry.N-CYBER-003CR-CYBER-0094
SSR-SYS-0001SYSDesign constraintQMMediumTestThe ECA supplier shall propose the method and the scope to the vehicle manufacturer for approval.N-SYS-001CR-SYS-0001
SSR-SYS-0002SYSDesign constraintQMMediumTestThe ECA supplier shall propose the methods to the vehicle manufacturer for approval.N-SYS-001CR-SYS-0003
SSR-SYS-0003SYSDesign constraintQMLowTestThe ECA supplier shall propose the methods to the vehicle manufacturer for approval.N-SYS-001CR-SYS-0008
SSR-SYS-0004SYSDesign constraintQMMediumTestThe ECA supplier shall propose the methods, including a stipulated notification time of TBD, to the vehicle manufacturer for approval.N-SYS-001CR-SYS-0015Notification time is not quantified by the customer ('reasonable notification time'); the value (TBD) must be agreed with the vehicle manufacturer.
SSR-SYS-0005splitSYSDesign constraintQMMediumTestEach part included in the ECA shall fulfil the applicable sections of Part 9 in Annex B to the latest ADR applicable at the time of type approval.N-SYS-0019.2
SSR-SYS-0005-2splitSYSDesign constraintQMMediumTestThe ECA shall comply with ECE Regulation No. 105 as amended at the time of type approval.N-SYS-0019.2
SSR-SYS-0005-3splitSYSDesign constraintQMMediumTestThe ECA shall comply with European Directive 2008/68/EC as amended at the time of type approval.N-SYS-0019.2
SSR-SYS-0006needs clarificationSYSDesign constraintQMLowTestWhere type approval is required, the ECA shall comply with ECE Regulation No. TBD.N-SYS-001CR-SYS-0123CLARIFY: Which ECE Regulation number(s) must the ECA and its components comply with for type approval? The source statement is truncated at 'ECE Regulation No.'.; The applicable ECE Regulation number is missing; the customer statement is truncated at 'ECE Regulation No.'.
SSR-VAL-0001VALDesign constraintQMLowReviewThe ECA supplier shall provide documentation of the method and the results to the vehicle manufacturer.N-VAL-001CR-VAL-0001
SSR-VAL-0002splitVALDesign constraintQMMediumReviewWhen the vehicle manufacturer requests documentation or evidence, the ECA supplier shall provide the requested documentation and evidence.N-VAL-001REQ_SEC_0041
SSR-VAL-0002-2splitVALDesign constraintQMMediumReviewWhen the vehicle manufacturer performs or orders a compliance audit, the ECA supplier shall support the compliance audit.N-VAL-001REQ_SEC_0041
SSR-VAL-0003needs clarificationVALDesign constraintQMLowReviewThe ECA supplier shall provide documentation of the ECA product.N-VAL-001CR-VAL-0005CLARIFY: What specific product documentation does Traton require? The source statement (clause 2.12) is truncated after 'Documentation of the product, i.e.'.; The specific product documentation items are missing; the source is truncated after 'Documentation of the product, i.e.'.
SSR-VAL-0004VALDesign constraintQMLowReviewThe ECA supplier shall provide documentation for the ESD bits and the related faults.N-VAL-001CR-VAL-0009
SSR-CYBER-0011CYBERDesign constraintQMLowReviewThe ECA supplier shall evaluate each risk identified in the cybersecurity risk analyses.N-CYBER-004REQ_SEC_0022
SSR-CYBER-0012CYBERDesign constraintQMLowReviewThe ECA shall implement cybersecurity controls that reduce each identified risk to the acceptable residual risk level of TBD.N-CYBER-004REQ_SEC_0023The acceptable residual risk level is not quantified by the customer ('sufficiently'); the target level (TBD) must be agreed with the vehicle manufacturer.
SSR-CYBER-0013CYBERDesign constraintQMLowReviewThe ECA supplier shall maintain traceability between each cybersecurity control and the requirement from which it was derived.N-CYBER-004CR-CYBER-0008
SSR-CYBER-0014CYBERDesign constraintQMLowReviewThe ECA supplier shall provide test reports detailing the results of the verification and validation of the cybersecurity features.N-CYBER-004REQ_SEC_0005
SSR-CYBER-0015CYBERDesign constraintQMLowReviewThe ECA shall isolate the software components, the hardware components, and the data to reduce the effect of a cybersecurity breach.N-CYBER-004REQ_SEC_0009
SSR-CYBER-0016CYBERDesign constraintQMLowReviewThe ECA shall support secure injection of data by the vehicle manufacturer in accordance with the specification provided by the vehicle manufacturer.N-CYBER-004REQ_SEC_0027
SSR-CYBER-0017CYBERDesign constraintQMLowReviewThe ECA shall conform to the harmonized Security Access specification provided by the vehicle manufacturer.N-CYBER-005REQ_SEC_0015
SSR-CYBER-0018CYBERDesign constraintQMLowReviewWhen the ECA is decommissioned, the ECA shall keep the risk to the road user and to the vehicle manufacturer within the acceptable level.N-CYBER-005CR-CYBER-0031
SSR-CYBER-0019CYBERDesign constraintQMLowReviewThe ECA shall support the ECU identification data in accordance with CVS124.N-CYBER-005CR-CYBER-0044
SSR-CYBER-0020CYBERDesign constraintQMLowTestThe ECA shall use ED25519 as the signature algorithm.N-CYBER-005CR-CYBER-0051
SSR-CYBER-0021CYBERDesign constraintQMLowTestIf the authenticity verification is valid, the ECA shall initiate installation of the received file.N-CYBER-005REQ_UDS_0170
SSR-CYBER-0022CYBERDesign constraintQMLowTestUntil the authenticity verification completes, the ECA shall keep the AuthenticityStatus field in bits 7-6 of AuthenticityVerificationStatus set to 0x0, indicating Software Authenticity Invalid.N-CYBER-005REQ_UDS_0177
SSR-CYBER-0023needs clarificationCYBERDesign constraintQMLowReviewThe ECA shall conform to the Data Security Container base definition specified in CVS154.N-CYBER-006CR-CYBER-0084CLARIFY: CR-CYBER-0084 is the CVS154 foreword (Data Security Container base definition scope), not a testable obligation. Should it be captured as a general conformance requirement to CVS154 or dropped as non-normative boilerplate?; Source is the CVS154 foreword/scope text, not a specific obligation; the applicable normative clauses of CVS154 are elsewhere in the standard.
SSR-CYBER-0024CYBERDesign constraintQMLowTestThe ECA shall generate the proof or the signature according to the specified pseudo code.N-CYBER-006CR-CYBER-0101The referenced pseudo code ('below') is not included in this item and must be taken from the source document.
SSR-CYBER-0025CYBERDesign constraintQMLowTestThe ECA shall generate the signature according to the specified pseudo code.N-CYBER-006CR-CYBER-0105The referenced pseudo code ('below') is not included in this item and must be taken from the source document.
SSR-CYBER-0026CYBERDesign constraintQMLowTestThe ECA shall represent each access role as a single bit within a 32-bit role field, where role number N corresponds to bit number N minus one, expressed as a four-byte value.N-CYBER-006CR-CYBER-0114
SSR-CYBER-0027CYBERDesign constraintQMLowTestThe ECA shall set the SignatureAlgorithm extension to ED25519 with the object identifier 1.3.101.112.N-CYBER-006CR-CYBER-0121
SSR-CYBER-0028needs clarificationCYBERDesign constraintQMHighReviewThe ECA supplier shall interpret the requirement-level keywords used in this document in accordance with Key words for use in RFCs to Indicate Requirement Levels.N-CYBER-006CR-CYBER-0126CLARIFY: CR-CYBER-0126 is a keyword-interpretation convention (shall/should/must per RFC 2119), not a system requirement. Should it be retained as a documentation convention note or dropped from the requirement set?
SSR-CYBER-0029CYBERDesign constraintQMHighReviewThe ECA supplier shall allow the vehicle manufacturer to perform penetration testing on the ECA.N-CYBER-007REQ_SEC_0040
SSR-SYS-0007SYSDesign constraintQMLowReviewThe ECA supplier shall provide an inventory of the software and the protocols, including the version of each.N-SYS-002REQ_SEC_0007
SSR-SYS-0008SYSDesign constraintQMLowTestThe ECA supplier shall agree the selection of the cryptographic methods and their use with the vehicle manufacturer.N-SYS-002REQ_SEC_0020
SSR-SYS-0009SYSDesign constraintQMLowTestThe ECA supplier shall harden each network service implemented in the ECA.N-SYS-002REQ_SEC_0010The hardening baseline/standard is not specified by the customer; the applicable hardening measures should be agreed with the vehicle manufacturer.
SSR-SYS-0010SYSDesign constraintQMLowTestThe ECA shall expose only the network and communication services that have been agreed with the vehicle manufacturer.N-SYS-002REQ_SEC_0011
SSR-SYS-0011SYSDesign constraintQMLowTestFor the series-production ECA, the ECA supplier shall remove or disable each interface used for development purposes.N-SYS-002REQ_SEC_0014
SSR-SYS-0012SYSDesign constraintQMLowTestThe ECA supplier shall agree the details with the vehicle manufacturer.N-SYS-002CR-SYS-0010
SSR-SYS-0013SYSDesign constraintQMLowTestThe ECA shall protect the data specified by the vehicle manufacturer from manipulation.N-SYS-003REQ_SEC_0028
SSR-SYS-0014SYSDesign constraintQMLowTestThe ECA shall protect the data specified by the vehicle manufacturer from disclosure.N-SYS-003REQ_SEC_0029
SSR-SYS-0015SYSDesign constraintQMLowTestThe ECA shall protect the intellectual property of the vehicle manufacturer from disclosure.N-SYS-003REQ_SEC_0006
SSR-SYS-0016SYSDesign constraintQMLowInspectionThe ECA supplier shall address end-of-life and decommissioning of the ECA in the ECA design.N-SYS-003CR-SYS-0018
SSR-SYS-0017SYSDesign constraintQMLowInspectionThe ECA supplier shall determine the ECA variant type based on the delivery agreement and the brand involved.N-SYS-003CR-SYS-0022
SSR-SYS-0018SYSDesign constraintQMLowTestThe ECA supplier shall verify the ECA mechanics in an overall durability test as stated in Appendix B.N-SYS-0032.11Appendix B durability test content is referenced but not provided in the source.
SSR-SYS-0019SYSDesign constraintQMLowTestThe ECA supplier shall perform testing to verify each requirement stated in the requirement specification.N-SYS-004CR-SYS-0025
SSR-SYS-0020SYSDesign constraintQMLowTestThe surface roughness of the ECA opposite to surface B shall be equal to or finer than Ra 3.2 µm.N-SYS-004CR-SYS-0027
SSR-SYS-0021SYSDesign constraintQMLowTestThe ECA supplier shall test the ECA step response in accordance with the description and Figure 10 - Step response test cycle of the referenced specification.N-SYS-004CR-SYS-0046
SSR-SYS-0022SYSDesign constraintQMLowTestThe ECA shall run the 4-second release frequency test cycle defined in Figure 11 continuously for 5 hours while remaining free of degradation and failure.N-SYS-004CR-SYS-0047
SSR-SYS-0023SYSDesign constraintQMLowReviewThe ECA supplier shall agree the strategy with Traton.N-SYS-004CR-SYS-0050The specific strategy referred to by 'the strategy' is defined in surrounding context not included in the source.
SSR-SYS-0024SYSDesign constraintQMLowTestThe ECA shall comply with TB4684.N-SYS-004CR-SYS-0053
SSR-SYS-0025needs clarificationSYSDesign constraintQMLowReviewThe ECA supplier shall comply fully with the referenced specification.N-SYS-005CR-SYS-0054CLARIFY: What does 'It' refer to - which document, standard, or specification shall be followed to its full extent?; The referent of 'It' is not identified in the source.
SSR-SYS-0026needs clarificationSYSDesign constraintQMLowReviewThe ECA supplier shall obtain approval from Traton for each specific case.N-SYS-005CR-SYS-0056CLARIFY: Which specific cases require Traton approval in CR-SYS-0056? The source statement 'Specific cases shall be approved with Traton' does not identify the configurations, deviations, or conditions it applies to.; The 'specific cases' requiring Traton approval are not defined in the item and cannot be resolved from the context neighbours.
SSR-SYS-0027SYSDesign constraintQMLowTestThe ECA shall report the FCCP value via CAN in accordance with reference 14.14.N-SYS-005CR-SYS-0063
SSR-SYS-0028SYSDesign constraintQMLowReviewThe ECA shall report supplier code 5 via CAN.N-SYS-0056.10
SSR-SYS-0029SYSDesign constraintQMLowTestWhen the ECA performs a self-adjustment procedure that is independent of an RPC request or a TC request, the ECA shall send 0x5 as the actuator control state.N-SYS-0056.14.5
SSR-SYS-0030SYSDesign constraintQMLowTestWhen the ECA performs its shut-down routine, the ECA shall send 0xA as the actuator control state.N-SYS-005CR-SYS-0073
SSR-SYS-0031SYSDesign constraintQMLowTestThe ECA shall comply with CVS120 as defined in reference 14.12.N-SYS-0066.20
SSR-SYS-0032SYSDesign constraintQMLowTestThe ECA shall calculate the current value for each actuator phase using a moving mean filter.N-SYS-006CR-SYS-0077
SSR-SYS-0033SYSDesign constraintQMLowTestThe ECA shall handle data corruption while preserving stored data and function.N-SYS-006CR-SYS-0083
SSR-SYS-0034SYSDesign constraintQMLowTestIf a single failure occurs, the ECA shall maintain electrical isolation between the Wake-up line and terminal 30.N-SYS-006CR-SYS-0087
SSR-SYS-0035SYSDesign constraintQMLowReviewThe ECA supplier shall agree the redundancies related to improper shutdown with Traton.N-SYS-006CR-SYS-0091The specific redundancies for improper shutdown are defined in surrounding context not included in the source.
SSR-SYS-0036SYSDesign constraintQMLowInspectionBy default, the ECA shall leave the components unpopulated.N-SYS-006CR-SYS-0099The specific components are defined in surrounding context not included in the source.
SSR-SYS-0037SYSDesign constraintQMLowInspectionThe conformal coating or lacquer of the ECA shall cover the entire PCB and each solder joint.N-SYS-007CR-SYS-0104
SSR-SYS-0038needs clarificationSYSDesign constraintQMLowReviewThe ECA supplier shall specify the type of conformal coating or lacquer in the initial offer.N-SYS-007CR-SYS-0106CLARIFY: In CR-SYS-0106, what must be specified in the initial offer? The source fragment 'shall be specified in the initial offer' lacks a subject; the surrounding context concerns conformal coating and lacquer, so please confirm whether the coating or lacquer type is the item to be specified.; The subject of 'shall be specified in the initial offer' (what must be specified) is not stated in the item; inferred as the conformal coating or lacquer type from the coating context.
SSR-SYS-0039splitSYSDesign constraintQMLowInspectionThe visual appearance of the ECA final coating shall be consistent with the latest version of IPC-A-610.N-SYS-007CR-SYS-0107Source is a merged fragment; identifiers 'HDBK-001' and 'HDBK-830' are likely 'IPC-HDBK-001' and 'IPC-HDBK-830' but the prefix is not confirmed in the source.
SSR-SYS-0039-2splitSYSDesign constraintQMLowInspectionThe ECA conformal coating shall be applied in accordance with HDBK-001, IPC-CC-830 and HDBK-830.N-SYS-007CR-SYS-0107
SSR-SYS-0040SYSDesign constraintQMLowInspectionThe ECA shall be free of water-based and silicone lacquers.N-SYS-007CR-SYS-0108
SSR-SYS-0041SYSDesign constraintQMLowReviewThe ECA shall position the membrane so that the membrane is protected against blunt force, falling dust and dripping salt-water.N-SYS-007CR-SYS-0110
SSR-SYS-0042SYSDesign constraintQMLowTestThe ECA shall keep the top of the membrane and the membrane cavity free of accumulated water.N-SYS-007CR-SYS-0111
SSR-SYS-0043SYSDesign constraintQMLowInspectionThe ECA shall be free of BGA capsules.N-SYS-008CR-SYS-0112
SSR-SYS-0044SYSDesign constraintQMLowTestThe ECA shall be maintenance-free throughout its service life.N-SYS-0088.5
SSR-SYS-0045SYSDesign constraintQMLowInspectionThe ECA supplier shall provide the maintenance window cover as a spare part.N-SYS-0088.8
SSR-SYS-0046SYSDesign constraintQMLowReviewThe ECA supplier shall define the spare parts or repair kits in agreement with Traton.N-SYS-008CR-SYS-0119
SSR-SYS-0047needs clarificationSYSDesign constraintQMLowReviewThe ECA supplier shall provide the item defined in section 4.17 of the referenced specification as a spare part.N-SYS-008CR-SYS-0120CLARIFY: In CR-SYS-0120, which item (referenced as '4.17') must be provided as a spare part? The source fragment lacks the subject; please identify the component defined in section 4.17.; The component to be provided as a spare part (referenced as '4.17') is not identified in the item and cannot be resolved from the context neighbours.
SSR-SYS-0048SYSDesign constraintQMLowTestThe ECA shall be lead-free.N-SYS-008CR-SYS-0122
SSR-SYS-0049SYSDesign constraintQMLowTestThe ECA shall fulfil the general requirements for Electronic Control Units stated in CVS40 and CVS41.N-SYS-00910.1
SSR-SYS-0050SYSDesign constraintQMLowTestThe ECA shall achieve the protection required by CVS40 and CVS41 independently of software.N-SYS-00910.2
SSR-SYS-0051SYSDesign constraintQMLowReviewThe ECA supplier shall agree the accepted behaviour for this case with Traton.N-SYS-009CR-SYS-0127The specific case/scenario referred to by 'this case' is defined in surrounding context not included in the source.
SSR-SYS-0052SYSDesign constraintQMLowTestThe ECA supplier shall perform the test before and after exposure.N-SYS-009CR-SYS-0128The specific test and exposure referred to are defined in surrounding context not included in the source.
SSR-SYS-0053SYSDesign constraintQMLowTestThe ECA shall allow the test to be performed during exposure.N-SYS-009CR-SYS-0129The specific test and exposure referred to are defined in surrounding context not included in the source.
SSR-SYS-0054SYSDesign constraintQMLowReviewWhere reduced versions of test procedure II are agreed with Traton, the ECA supplier shall use the reduced versions during the applicable tests.N-SYS-009CR-SYS-0130
SSR-SYS-0055SYSDesign constraintQMLowTestEach plastic material of the ECA shall be a self-extinguishing material rated to UL94.N-SYS-01010.5.33
SSR-SYS-0056needs clarificationSYSDesign constraintQMLowTestEach tab header of the ECA shall be a self-extinguishing material.N-SYS-010CR-SYS-0132CLARIFY: This appears to be a truncated duplicate of the flammability requirement (10.5.33). Which standard was intended after '(i.e.' - is it UL94, and does this requirement duplicate CR-SYS-0055?; The material/flammability standard is truncated in the source (text ends at '(i.e.').
SSR-SYS-0057SYSDesign constraintQMLowReviewWhen Traton requests support during the vehicle ESD test, the ECA supplier shall support Traton in resolving each issue originating from the ECA.N-SYS-01010.7.27
SSR-SYS-0058needs clarificationSYSDesign constraintQMLowReviewThe ECA supplier shall systematically identify each possible cause.N-SYS-010CR-SYS-0135CLARIFY: In CR-SYS-0135, what is 'this purpose' for which possible causes must be systematically identified? The dangling opener references a preceding objective that was not included; please confirm the activity (for example, fault or issue root-cause analysis) this applies to.; The antecedent of 'For this purpose' (the objective or event whose causes must be identified) is not present in the item or context neighbours.
SSR-SYS-0059SYSDesign constraintQMLowReviewThe ECA supplier shall provide software that enables testing of the ECA during development, during production and on each claimed ECA.N-SYS-01012.3
SSR-SYS-0060SYSDesign constraintQMLowTestThe ECA supplier shall perform a conformance test of each external and internal I/O of the ECA.N-SYS-010CR-SYS-0137
SSR-SYS-0061SYSDesign constraintQMLowTestThe ECA supplier shall verify that each internal and external I/O of the ECA fulfils the requirements in this specification.N-SYS-011CR-SYS-0138
SSR-SYS-0062SYSDesign constraintQMLowTestThe ECA supplier shall carry out two full test rounds according to the Traton test requirements.N-SYS-011CR-SYS-0139
SSR-SYS-0063SYSDesign constraintQMLowReviewWhere the ECA supplier initiates and performs additional tests, the ECA supplier shall discuss the additional tests with Traton.N-SYS-011CR-SYS-0140
SSR-SYS-0064SYSDesign constraintQMLowTestThe ECA supplier shall perform EMC tests on the ECA alone.N-SYS-011CR-SYS-0141
SSR-SYS-0065SYSDesign constraintQMLowTestThe ECA supplier shall certify the ECA according to the latest revision of UN ECE R10, including each amendment.N-SYS-011CR-SYS-0142
SSR-SYS-0066SYSDesign constraintQMLowInspectionThe ECA supplier shall check that the prototype and serial ECAs fulfil the dimension requirements in each applicable Traton-supplied drawing.N-SYS-011CR-SYS-0143
SSR-SYS-0067SYSDesign constraintQMLowInspectionEach prototype and serial ECA shall fulfil the requirements of TB1822, IPC/EIA J-STD-001 class 3 and IPC-A-610 class 3.N-SYS-012CR-SYS-0144
SSR-SYS-0068SYSDesign constraintQMLowReviewWhere sample phases are divided into several generations, the ECA supplier shall agree the division with Traton.N-SYS-012CR-SYS-0145
SSR-SYS-0069SYSDesign constraintQMLowTestThe ECA supplier shall functionally test each sample before sending the sample to Traton.N-SYS-012CR-SYS-0146
SSR-SYS-0070SYSDesign constraintQMLowInspectionThe ECA supplier shall report each deviation as part of the sample delivery.N-SYS-012CR-SYS-0147
SSR-SYS-0071SYSDesign constraintQMLowInspectionThe ECA supplier shall perform dimensional checks on each B-sample and each C-sample prior to delivery to Traton.N-SYS-012CR-SYS-0148
SSR-SYS-0072SYSDesign constraintQMLowInspectionThe ECA supplier shall use the sample denominations requested by Traton.N-SYS-012CR-SYS-0149
SSR-SYS-0073SYSDesign constraintQMLowReviewThe ECA supplier shall apply, for each referenced document without a stated version, the latest version available as of 1 May 2026.N-SYS-013CR-SYS-0150
SSR-SYS-0074SYSDesign constraintQMLowReviewThe ECA supplier shall apply the latest released version of the CVS123-2 specification.N-SYS-013CR-SYS-0155
SSR-SYS-0075needs clarificationSYSDesign constraintQMLowReviewThe ECA shall expose its two physical servers to the diagnostic client.N-SYS-013CR-SYS-0156CLARIFY: CR-SYS-0156 is phrased as an explanatory note ('a single server view is not completely achievable and clients still need to be aware of two physical servers'). What is the binding obligation on the ECA? Please confirm whether the ECA must expose two physical servers, or whether this is context for a client-side requirement.; The binding obligation on the ECA is unclear; the source is a note stating that a single-server view is not fully achievable and that clients must be aware of two physical servers.
SSR-SYS-0076SYSDesign constraintQMLowReviewThe ECA shall support the programming sequence specified in CVS123-2.N-SYS-013CR-SYS-0158
SSR-SYS-0077SYSDesign constraintQMLowTestThe ECA shall keep the boot loader separated from the application software.N-SYS-013CR-SYS-0159Antecedent 'It' is not stated in the source; interpreted as the boot loader from the surrounding programming/boot-loader context.
SSR-SYS-0078needs clarificationSYSDesign constraintQMLowTestThe ECA shall implement the specified boot-software function in the boot software code.N-SYS-013CR-SYS-0161CLARIFY: In CR-SYS-0161, what must be implemented in the boot software code? The source fragment 'shall be implemented in the boot software code' lacks a subject; please identify the function or feature (the antecedent 'it' in the surrounding boot-loader text).; The subject of 'shall be implemented in the boot software code' is not stated; it is the antecedent of 'it' in the surrounding boot-loader description, which is not included.
SSR-SYS-0079SYSDesign constraintQMLowReviewThe ECA supplier shall agree each deviation from the specification with the applicable vehicle manufacturer.N-SYS-014CR-SYS-0163
SSR-SYS-0080SYSDesign constraintQMLowReviewWhere the specification does not state otherwise, the ECA supplier shall apply the programming requirements of the specification to the programming of each software module, including the application software, the application data, and the boot loader.N-SYS-014CR-SYS-0164
SSR-SYS-0081SYSDesign constraintQMLowTestThe ECA shall protect the stored software against accidental erasure and overwriting by means of a software or hardware protection mechanism.N-SYS-014CR-SYS-0165
SSR-SYS-0082SYSDesign constraintQMLowTestIf the microcontroller supports hardware protection, the ECA shall use that hardware protection.N-SYS-014CR-SYS-0166
SSR-SYS-0083SYSDesign constraintQMLowTestThe ECA shall support boot loader updating in accordance with the specification during development from the A-sample stage onwards.N-SYS-014CR-SYS-0168
SSR-SYS-0084SYSDesign constraintQMLowInspectionThe ECA supplier shall provide, for each committed software delivery, a document that describes the programming procedure, the requirement exceptions, and the ECA-specific behaviours.N-SYS-014CR-SYS-0169
SSR-SYS-0085SYSDesign constraintQMLowReviewThe ECA supplier shall document the versioning concept for the supplier-specific DIDs.N-SYS-015CR-SYS-0171
SSR-SYS-0086SYSDesign constraintQMLowReviewThe ECA supplier shall agree the partitioning of the ECA software into modules with the vehicle manufacturer.N-SYS-015CR-SYS-0174
SSR-SYS-0087SYSDesign constraintQMLowReviewThe ECA supplier shall agree with the vehicle manufacturer whether the ECA is delivered with a pre-programmed application and pre-programmed application data.N-SYS-015CR-SYS-0176
SSR-SYS-0088SYSDesign constraintQMLowReviewWhere the ECA is a programmable server, the ECA shall support the complete programming sequence described in the specification.N-SYS-015CR-SYS-0178
SSR-SYS-0089SYSDesign constraintQMLowReviewWhere the ECA is a non-programmable server, the ECA shall support the phase 1 pre-programming step and the phase 2 post-programming step of the programming sequence described in the specification.N-SYS-015CR-SYS-0179
SSR-SYS-0090SYSDesign constraintQMLowReviewThe ECA shall support the programming sequence described in the specification regardless of whether a valid application is present in the ECA.N-SYS-015CR-SYS-0180
SSR-SYS-0091SYSDesign constraintQMLowTestIf the application has been started, the ECA shall check whether application initialization is required.N-SYS-016CR-SYS-0183
SSR-SYS-0092SYSDesign constraintQMLowTestThe ECA shall allow the application software module and the application data module to be programmed in any order.N-SYS-016CR-SYS-0185
SSR-SYS-0093needs clarificationSYSDesign constraintQMLowTestIf the applicable precondition cannot be met, the ECA shall implement a compression method.N-SYS-016CR-SYS-0187CLARIFY: The source is truncated ('cannot be met, a compression method shall be implemented'). What is the precondition that, when it cannot be met, requires a compression method to be implemented (for example a memory-size or download-time limit)?; The condition that 'cannot be met' is truncated in the source; likely a memory-size or download-time constraint but not stated.
SSR-SYS-0094SYSDesign constraintQMLowTestThe ECA shall use, as the compression and decompression algorithm, the LZSS algorithm with a dictionary size of 1023 bytes or a newer compression and decompression method with a higher compression ratio.N-SYS-016CR-SYS-0188
SSR-SYS-0095SYSDesign constraintQMLowReviewWhere an alternative compression and decompression algorithm is used, the ECA supplier shall agree its use with the vehicle manufacturer.N-SYS-016CR-SYS-0189
SSR-SYS-0096SYSDesign constraintQMLowTestThe ECA shall allow the same software version to be programmed repeatedly.N-SYS-016CR-SYS-0190
SSR-SYS-0097SYSDesign constraintQMLowReviewThe ECA supplier shall agree the technical implementation of the programming preconditions with the vehicle manufacturer.N-SYS-017CR-SYS-0194
SSR-SYS-0098SYSDesign constraintQMLowTestThe ECA shall be re-programmable both standalone and in the vehicle regardless of whether the application and the application data are valid or corrupted.N-SYS-017CR-SYS-0196
SSR-SYS-0099needs clarificationSYSDesign constraintQMLowTestWhen a non-permitted service is requested during programming, the ECA shall resume programming from the state at which it was executing before that non-permitted service was requested.N-SYS-017CR-SYS-0199CLARIFY: The source is truncated, starting with '(requestSequenceError) and shall accept programming to proceed ...'. Please confirm the full requirement: on which non-permitted service request shall the ECA return the requestSequenceError NRC, and confirm it shall then continue programming from the pre-request state.; The clause preceding '(requestSequenceError)' is truncated; the exact trigger and full wording of the negative-response behaviour are not stated.
SSR-SYS-0099-2splitSYSDesign constraintQMLowTestThe ECA shall respond to the non-permitted service request with the requestSequenceError negative response code.N-SYS-017CR-SYS-0199
SSR-SYS-0100SYSDesign constraintQMLowTestIf the software is compressed, the ECA shall decompress the software before performing the software hash comparison verification.N-SYS-017CR-SYS-0201
SSR-SYS-0101SYSDesign constraintQMLowTestThe ECA shall verify the software hash after decryption, decompression, or both have been performed.N-SYS-017CR-SYS-0202
SSR-SYS-0102SYSDesign constraintQMLowReviewThe ECA shall support the negative response codes defined in CVS32.N-SYS-017CR-SYS-0205
SSR-SYS-0103SYSDesign constraintQMLowReviewThe ECA shall check whether the software modules are complete and mutually compatible.N-SYS-018CR-SYS-0210
SSR-SYS-0104SYSDesign constraintQMLowReviewThe ECA supplier shall determine the method used to check compatibility and consistency in consultation with the vehicle manufacturer.N-SYS-018CR-SYS-0212
SSR-SYS-0105SYSDesign constraintQMLowReviewThe ECA shall be solely responsible for carrying out the consistency check.N-SYS-018CR-SYS-0213
SSR-SYS-0106SYSDesign constraintQMLowTestThe ECA shall use SHA512 as the hash algorithm.N-SYS-018CR-SYS-0214
SSR-SYS-0107SYSDesign constraintQMLowReviewThe ECA shall sign the hashed output using the receipt-keys.N-SYS-018CR-SYS-0215
SSR-SYS-0108SYSDesign constraintQMLowReviewThe ECA shall implement the SDSC structure as defined in CVS154.N-SYS-018CR-SYS-0218
SSR-SYS-0109SYSDesign constraintQMLowTestThe ECA shall set the range length field to the number of bytes to be verified.N-SYS-019CR-SYS-0219
SSR-SYS-0110SYSDesign constraintQMLowReviewThe ECA supplier shall propose, for each software module, an identification to be used in the dataLocator field in the SDSC.N-SYS-019CR-SYS-0220
SSR-SYS-0111SYSDesign constraintQMLowReviewBefore accepting the received SDSC as valid, the ECA shall perform the sanity check of the received SDSC as defined in CVS154.N-SYS-019CR-SYS-0222
SSR-SYS-0112SYSDesign constraintQMLowReviewIf the sanity check returns fail or invalid, the ECA shall reject the SDSC as described in CVS34.N-SYS-019CR-SYS-0223
SSR-SYS-0113SYSDesign constraintQMLowTestThe ECA shall validate each VerificationEntry found in the SDSC.N-SYS-019CR-SYS-0224
SSR-SYS-0114SYSDesign constraintQMLowTestThe ECA shall verify each software hash in the SDSC considering the ranges stated in the SDSC.N-SYS-019CR-SYS-0225
SSR-SYS-0115SYSDesign constraintQMLowReviewWhen the ECA has verified each verificationEntry, the ECA shall return a result of OK or NOT_OK.N-SYS-020CR-SYS-0228
SSR-SYS-0116SYSDesign constraintQMLowTestIf a NOT_OK result is returned, the ECA shall prevent the new software from being executed.N-SYS-020CR-SYS-0229
SSR-SYS-0117SYSDesign constraintQMLowTestWhere additional software verification checks are implemented, the ECA shall execute them before determining whether the installed software is accepted.N-SYS-020CR-SYS-0230
SSR-SYS-0118SYSDesign constraintQMLowReviewThe ECA supplier shall agree each method other than the methods specified in CVS123-2 with the vehicle manufacturer.N-SYS-020CR-SYS-0232
SSR-SYS-0119SYSDesign constraintQMLowTestThe ECA shall decrypt the received data according to the defined range, where the received data may comprise only part of a software module.N-SYS-020CR-SYS-0233
SSR-SYS-0120SYSDesign constraintQMLowReviewThe ECA supplier shall apply the latest released version of the CVS124 specification.N-SYS-020CR-SYS-0234
SSR-SYS-0121needs clarificationSYSDesign constraintQMLowReviewWhere the CVS124 specification is applicable to the ECA, the ECA supplier shall apply it.N-SYS-021CR-SYS-0235CLARIFY: This item is the CVS124 foreword ('contains requirement specification for TRATON GROUP ... may be used by all within TRATON Group, if applicable') and carries no obligation on the ECA. Should it be dropped as informative, or is a specific applicability requirement intended?; Source is a foreword; no measurable ECA obligation is stated.
SSR-SYS-0122needs clarificationSYSDesign constraintQMLowReviewTBD - the source is a definition of 'Affiliate' and states no obligation on the ECA or the supplier.N-SYS-021CR-SYS-0236CLARIFY: This item is a contractual definition of 'Affiliate' (including 'control shall mean ownership of at least 50% ...'). Please confirm it is a glossary/definition entry to be excluded from the system requirements rather than a requirement.; Definitional 'shall' is not an obligation; no ECA or supplier requirement is present in the source.
SSR-SYS-0123SYSDesign constraintQMLowTestWhere a particular option is absent from the ECA, the ECA shall interoperate with an implementation that includes that option.N-SYS-021CR-SYS-0237
SSR-SYS-0124SYSDesign constraintQMLowTestWhere the ECA includes a particular option, the ECA shall interoperate with an implementation that lacks that option, except for the feature that the option provides.N-SYS-021CR-SYS-0238
SSR-SYS-0125SYSDesign constraintQMLowTestIf valid data is not required for the applicable use case and system, the ECA shall use the default values.N-SYS-021CR-SYS-0239
SSR-SYS-0126needs clarificationSYSDesign constraintQMLowReviewWhere the ECA is required to comply with worldwide OBD legislation, the ECA shall support each service classified as mandatory.N-SYS-021CR-SYS-0240CLARIFY: This text is a legend defining classification codes (E = mandatory, C = conditional, U = user optional) rather than one requirement. Does the ECA fall under worldwide OBD legislation, and which specific services/DIDs are classified E, C and U for this ECA?
SSR-SYS-0127needs clarificationSYSDesign constraintQMLowReviewThe ECA supplier shall agree the data value with the vehicle manufacturer.N-SYS-022CR-SYS-0241CLARIFY: In CR-SYS-0241, what must be agreed between the supplier and the vehicle manufacturer? The source fragment has no subject; the surrounding CVS124 text concerns data values and defaults, so please identify the specific item.; The subject of 'Shall be agreed between the supplier and the vehicle manufacturer' (what must be agreed) is not stated in the item; the surrounding CVS124 context concerns data values and defaults.
SSR-SYS-0128splitSYSDesign constraintQMLowReviewThe ECA supplier shall agree each deviation and each extension with the applicable vehicle manufacturer.N-SYS-022REQ_UDS_0002
SSR-SYS-0128-2splitSYSDesign constraintQMLowReviewThe ECA supplier shall document each deviation and each extension.N-SYS-022REQ_UDS_0002
SSR-SYS-0129splitSYSDesign constraintQMLowTestThe ECA assigned value shall have a minimum length of 8 bytes.N-SYS-022CR-SYS-0243The 'assigned value' is the customer's term for a per-unit identifier defined in CVS124; the exact identifier name is not specified in the item.
SSR-SYS-0129-2splitSYSDesign constraintQMLowTestThe ECA supplier shall assign a unique value to each unit provided within one project.N-SYS-022CR-SYS-0243
SSR-SYS-0130SYSDesign constraintQMLowTestThe ECA shall execute the ECU reset only after it has sent a positive response to the ECU reset service request.N-SYS-022REQ_UDS_0063
SSR-SYS-0131splitSYSDesign constraintQMLowReviewThe ECA supplier shall agree with the vehicle manufacturer the maximum time from the ECA sending a positive response until the ECA responds to new requests.N-SYS-022REQ_UDS_0067The maximum time value is not stated in the source; it is to be agreed with the vehicle manufacturer (TBD).
SSR-SYS-0131-2splitSYSDesign constraintQMLowReviewThe ECA supplier shall document the agreed maximum time from the ECA sending a positive response until the ECA responds to new requests.N-SYS-022REQ_UDS_0067
SSR-SYS-0132SYSDesign constraintQMLowTestThe ECA shall perform an actual disconnect from the battery.N-SYS-022CR-SYS-0251
SSR-SYS-0133SYSDesign constraintQMLowTestWhen executing a hardReset, the ECA shall preserve data integrity.N-SYS-023CR-SYS-0252
SSR-SYS-0134SYSDesign constraintQMLowTestWhen a functionally addressed TesterPresent is received during another request, the ECA shall accept it.N-SYS-023CR-SYS-0254
SSR-SYS-0135SYSDesign constraintQMLowTestThe ECA shall switch the baud rate within one second.N-SYS-023REQ_UDS_0082quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0136SYSDesign constraintQMLowTestIf the LinkControl service request was received while the ECA was executing in the application, the ECA shall inherit the selected baud rate in the boot loader.N-SYS-023REQ_UDS_0083
SSR-SYS-0137SYSDesign constraintQMLowTestThe ECA shall send the positive response before switching the baud rate.N-SYS-023REQ_UDS_0084
SSR-SYS-0138SYSDesign constraintQMLowReviewThe ECA shall use SPNs and FMIs in accordance with SAE J1939.N-SYS-023REQ_UDS_0097
SSR-SYS-0139SYSDesign constraintQMLowTestWhen transmitting data in a secured mode, the ECA shall use the service specified in CVS32.N-SYS-024REQ_UDS_0125
SSR-SYS-0140SYSDesign constraintQMLowTestThe ECA shall provide the positive response in accordance with CVS32.N-SYS-024REQ_UDS_0127
SSR-SYS-0141SYSDesign constraintQMLowTestThe ECA shall provide the negative response in accordance with the supported negative response codes defined in CVS32 section 5.5.17.3.1.N-SYS-024REQ_UDS_0128
SSR-SYS-0142SYSDesign constraintQMLowTestIf the file is not stored at the location, the ECA shall add the file.N-SYS-024CR-SYS-0265
SSR-SYS-0143SYSDesign constraintQMLowReviewThe ECA supplier shall agree each programming precondition with the vehicle manufacturer.N-SYS-024REQ_UDS_0147The set of programming preconditions is not stated in the source; it is to be agreed with the vehicle manufacturer (TBD).
SSR-SYS-0144SYSDesign constraintQMLowTestThe ECA shall base the decision on the conditions of a programming precondition on a minimum of two independent sources of information.N-SYS-024REQ_UDS_0148quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0145SYSDesign constraintQMLowTestIf information for checking a programming precondition is unavailable, the ECA shall consider the programming precondition fulfilled.N-SYS-025REQ_UDS_0149
SSR-SYS-0146SYSDesign constraintQMLowTestWhile the software installation is on-going, the ECA shall set the InstallationStatus in bits 7 to 6 of SoftwareInstallationStatus to 0x0.N-SYS-025REQ_UDS_0180
SSR-SYS-0147SYSDesign constraintQMLowTestThe ECA shall provide the information as a percentage.N-SYS-025CR-SYS-0271
SSR-SYS-0148SYSDesign constraintQMLowTestThe ECA shall report the estimated time to complete the installation of the file in the TimeRemaningEstimative parameter.N-SYS-025REQ_UDS_0182
SSR-SYS-0149SYSDesign constraintQMLowTestThe ECA shall provide the information in seconds.N-SYS-025CR-SYS-0273
SSR-SYS-0150needs clarificationSYSDesign constraintQMLowReviewThe ECA shall check whether each module is complete and compatible.N-SYS-025REQ_UDS_0183CLARIFY: The source sentence is truncated at 'compatible with' - compatible/consistent with what (e.g., the other modules, the target hardware, or the vehicle configuration)?
SSR-SYS-0151SYSDesign constraintQMLowReviewThe ECA supplier shall determine the method used to check compatibility or consistency in consultation with the vehicle manufacturer.N-SYS-026REQ_UDS_0184The compatibility or consistency check method is not stated in the source; it is to be determined by the ECA supplier with the vehicle manufacturer (TBD).
SSR-SYS-0152SYSDesign constraintQMLowReviewThe ECA shall carry out the consistency check by itself.N-SYS-026REQ_UDS_0185
SSR-SYS-0153SYSDesign constraintQMLowTestThe ECA shall limit the occurrence counter to a minimum value of 0.N-SYS-026REQ_UDS_0198quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0154SYSDesign constraintQMLowTestThe ECA shall limit the occurrence counter to a maximum value of 126.N-SYS-026REQ_UDS_0199quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0155SYSDesign constraintQMLowTestThe ECA shall use a default occurrence counter value of 0.N-SYS-026REQ_UDS_0200
SSR-SYS-0156SYSDesign constraintQMLowTestThe ECA shall increment the occurrence counter by 1 only.N-SYS-026REQ_UDS_0201
SSR-SYS-0157SYSDesign constraintQMLowReviewIf the occurrence counter value is below the maximum value, the ECA shall increment the occurrence counter.N-SYS-027REQ_UDS_0202quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0158SYSDesign constraintQMLowTestThe ECA shall define the occurrence counter value 127 as indicating errors with the counter.N-SYS-027REQ_UDS_0206
SSR-SYS-0159SYSDesign constraintQMLowTestThe ECA P2Server time shall be within the range of 0 ms to 50 ms.N-SYS-027REQ_UDS_0225
SSR-SYS-0160SYSDesign constraintQMLowTestThe ECA shall use a value of 150 ms for P2Client.N-SYS-027REQ_UDS_0226
SSR-SYS-0161SYSDesign constraintQMLowTestThe ECA P2*Server time shall be within the range of 0 ms to 4000 ms.N-SYS-027REQ_UDS_0227
SSR-SYS-0162SYSDesign constraintQMLowTestThe ECA shall limit the P4_Server_max timing parameter to a maximum value of 30 s.N-SYS-027REQ_UDS_0229quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0163SYSDesign constraintQMLowReviewThe ECA supplier shall document the implemented value for P4_Server_max.N-SYS-028REQ_UDS_0230The implemented value for P4_Server_max is not stated in the source; it is to be documented by the ECA supplier (TBD).
SSR-SYS-0164SYSDesign constraintQMLowReviewThe ECA supplier shall apply the latest version of CVS151.N-SYS-028CR-SYS-0290
SSR-SYS-0165splitSYSDesign constraintQMLowReviewIf a matching allow rule is found and each rule setting is fulfilled, the ECA shall accept the request.N-SYS-028CR-SYS-0291
SSR-SYS-0165-2splitSYSDesign constraintQMLowReviewIf a matching deny rule is found and each rule setting is fulfilled, the ECA shall deny the request.N-SYS-028CR-SYS-0291
SSR-SYS-0166SYSDesign constraintQMLowReviewIf a matching rule is found and one or more of the rule settings are unfulfilled, the ECA shall consider the request rejected for that rule.N-SYS-028CR-SYS-0292
SSR-SYS-0167SYSDesign constraintQMLowReviewThe ECA shall support two octets in the version field.N-SYS-028CR-SYS-0293
SSR-SYS-0168SYSDesign constraintQMLowReviewThe ECA shall support major version value 3 and minor version value 0.N-SYS-028CR-SYS-0294
SSR-SYS-0169SYSDesign constraintQMLowReviewWhere support of a version other than major version 3 and minor version 0 is required, the ECA supplier shall agree the scope of that version support with the relevant Traton project.N-SYS-029CR-SYS-0295Which specific versions beyond major version 3 and minor version 0 must be supported is out of scope of the source document and remains TBD pending agreement between the relevant Traton projects.
SSR-SYS-0170SYSDesign constraintQMLowReviewIf the version number is incompatible with the ECA implementation, the ECA shall reject the request to store the data.N-SYS-029CR-SYS-0296
SSR-SYS-0171SYSDesign constraintQMLowReviewThe ECA shall support, for each entry in the did-rules, one octet representing the did-rule settings followed by two octets representing the DID.N-SYS-029CR-SYS-0297
SSR-SYS-0172SYSDesign constraintQMLowReviewThe ECA shall support, for each entry in the rid-rules, one octet that represents the rid-rule settings followed by two octets that represent the RID.N-SYS-029CR-SYS-0299
SSR-SYS-0173SYSDesign constraintQMLowTestThe ECA shall permit the request only where the client has read access to each included DID and has access to the service itself.N-SYS-029CR-SYS-0301
SSR-SYS-0174SYSDesign constraintQMLowReviewThe ECA supplier shall apply the latest version of CVS154.N-SYS-029CR-SYS-0304
SSR-SYS-0175SYSDesign constraintQMLowReviewThe ECA shall support a DSC Metadata block containing version and id fields.N-SYS-030CR-SYS-0305
SSR-SYS-0176SYSDesign constraintQMLowReviewThe ECA shall support the Major and Minor version as specified in section 3.2.N-SYS-030CR-SYS-0306
SSR-SYS-0177SYSDesign constraintQMLowReviewThe ECA shall support a DSC containing verificationEntries.N-SYS-030CR-SYS-0307
SSR-SYS-0178SYSDesign constraintQMLowReviewThe ECA shall support a DSC containing itemEntries.N-SYS-030CR-SYS-0308
SSR-SYS-0179SYSDesign constraintQMLowReviewWhen a DSC transmitted by the client contains a verificationEntries field with no VerificationEntry items, the ECA shall expect an ASN.1 SEQUENCE tag with length zero for that field.N-SYS-030CR-SYS-0309
SSR-SYS-0180SYSDesign constraintQMLowReviewWhen a DSC transmitted by the client contains an ItemEntries field with no items, the ECA shall expect an ASN.1 SEQUENCE tag with length zero for that field.N-SYS-030CR-SYS-0310
SSR-SYS-0181SYSDesign constraintQMLowTestWhere the VerificationEntry hashCmp option is selected, the ECA shall verify the data by hash comparison.N-SYS-031CR-SYS-0311
SSR-SYS-0182SYSDesign constraintQMLowReviewWhere the instance specification states specialized actions, the ECA shall process each VerificationEntry one by one.N-SYS-031CR-SYS-0312
SSR-SYS-0183SYSDesign constraintQMLowTestThe ECA shall use the HashAlgorithm specified by the hashAlgorithm field, as defined in RFC 6234, to hash the data to be verified.N-SYS-031CR-SYS-0313
SSR-SYS-0184SYSDesign constraintQMLowReviewThe ECA shall support the SHA512 HashAlgorithm as defined in the ASN.1 definition in section 3.2.N-SYS-031CR-SYS-0314
SSR-SYS-0185needs clarificationSYSDesign constraintQMLowReviewThe ECA shall support both of the specified choices.N-SYS-031CR-SYS-0315CLARIFY: The source states 'both of the choices' without identifying them in this excerpt. Which two choices must the ECA support (for example, the two HashAlgorithm options of a specific ASN.1 CHOICE), and where are they defined?
SSR-SYS-0186SYSDesign constraintQMLowTestThe ECA shall set the initial value of the counter to 0.N-SYS-031CR-SYS-0316
SSR-SYS-0187SYSDesign constraintQMLowTestThe ECA shall decrypt the data chunks identified by the Range field.N-SYS-032CR-SYS-0317
SSR-SYS-0188SYSDesign constraintQMLowReviewThe ECA shall set the structure version for this document release to Major '04' and Minor '00'.N-SYS-032CR-SYS-0318
SSR-SYS-0189SYSDesign constraintQMLowTestThe ECA shall verify the length of the version field.N-SYS-032CR-SYS-0320
SSR-SYS-0190SYSDesign constraintQMLowTestThe ECA shall verify the length of the id field.N-SYS-032CR-SYS-0322
SSR-SYS-0191SYSDesign constraintQMLowReviewThe ECA shall support the hashAlgorithm.N-SYS-032CR-SYS-0323
SSR-SYS-0192SYSDesign constraintQMLowTestThe ECA shall verify that the length of each referenceHash is consistent with the output size of the hash algorithm specified by the hashAlgorithm field.N-SYS-032CR-SYS-0324
SSR-SYS-0193SYSDesign constraintQMLowReviewIf the ECA rejects a DSC instance that was transmitted with EMP, the ECA shall return an error code to the client.N-SYS-033CR-SYS-0325
SSR-SYS-0194SYSDesign constraintQMLowTestThe ECA supplier shall apply the latest version of CVS31.N-SYS-033CR-SYS-0326
SSR-SYS-0195needs clarificationSYSDesign constraintQMLowTestThe ECA supplier shall apply CVS31 as a requirement specification for the ECA.N-SYS-033CR-SYS-0327CLARIFY: This text is the CVS31 Foreword describing the document's scope and applicability within the TRATON Group; it states no verifiable ECA obligation. Should it be treated as informative (dropped), or is a specific applicability requirement intended?; quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0196needs clarificationSYSDesign constraintQMLowReviewThe term 'Affiliate' shall mean any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, where 'control' means ownership of at least 50% of the voting rights or of the interest in the issued share capital, including any branch.N-SYS-033CR-SYS-0328CLARIFY: This is a contractual glossary definition of 'Affiliate' and 'control'; it defines terms rather than stating a verifiable ECA obligation. Confirm it should be recorded as a definition rather than a system requirement.
SSR-SYS-0197splitSYSDesign constraintQMLowReviewThe ECA supplier shall document each deviation from the specification.N-SYS-033CR-SYS-0329
SSR-SYS-0197-2splitSYSDesign constraintQMLowReviewThe vehicle manufacturer shall review each documented deviation from the specification.N-SYS-033CR-SYS-0329
SSR-SYS-0198needs clarificationSYSDesign constraintQMLowReviewThe ECA supplier shall agree the TBD subject item with the vehicle manufacturer.N-SYS-033CR-SYS-0330CLARIFY: In CVS31 page 6 (CR-SYS-0330), what specific item, parameter, value, or scope must be agreed between the ECA supplier and the vehicle manufacturer?; The subject of the agreement (what parameter, scope, deviation, or item must be agreed) is not recoverable from the customer statement or the context neighbours (TBD).
SSR-SYS-0199SYSDesign constraintQMLowTestThe ECA shall represent the field using 32 octets.N-SYS-034CR-SYS-0332
SSR-SYS-0200SYSDesign constraintQMLowTestThe client shall generate the proofOfOwnershipClient according to the pseudo code specified in the source specification.N-SYS-034CR-SYS-0337
SSR-SYS-0201needs clarificationSYSDesign constraintQMLowTestIf the NodeUID extension is not detected, the ECA shall continue the operation as specified for the case in which the NodeUID extension is absent.N-SYS-034CR-SYS-0339CLARIFY: The source sentence is truncated ('...continue as in'). Which section or case defines how the operation continues when the NodeUID extension is not detected?
SSR-SYS-0202SYSDesign constraintQMLowTestThe ECA shall represent the roles as a bit-pattern octet string.N-SYS-034CR-SYS-0340
SSR-SYS-0203SYSDesign constraintQMLowTestThe ECA shall set the CA field of the basicConstraints extension to False.N-SYS-034CR-SYS-0341
SSR-SYS-0204SYSDesign constraintQMLowTestThe ECA shall include the clientAuth object identifier 1.3.6.1.5.5.7.3.2 in the ExtendedKeyUsage extension.N-SYS-034CR-SYS-0342
SSR-SYS-0205SYSDesign constraintQMLowTestThe ECA shall implement the cryptographic random number generator (CRNG) in accordance with CVS150.N-SYS-035CR-SYS-0349
SSR-SYS-0206SYSDesign constraintQMLowReviewWhen a valid proofOfOwnership has been received, the ECA shall start the A3 timer.N-SYS-035CR-SYS-0351
SSR-SYS-0207SYSDesign constraintQMLowReviewWhen a request is received from the same client, the ECA shall restart the A3 timer.N-SYS-035CR-SYS-0352
SSR-SYS-0208SYSDesign constraintQMLowTestThe ECA shall implement the A3 timer separately from the S3 timer.N-SYS-035CR-SYS-0355
SSR-SYS-0209SYSDesign constraintQMLowTestThe ECA shall set the delay timer to 1 second.N-SYS-035CR-SYS-0356
SSR-SYS-0210SYSDesign constraintQMLowTestThe ECA supplier shall apply the latest version of CVS32.N-SYS-035CR-SYS-0360
SSR-SYS-0211needs clarificationSYSDesign constraintQMLowTestThe ECA supplier shall apply CVS32 as a requirement specification for the ECA.N-SYS-036CR-SYS-0361CLARIFY: This text is the CVS32 Foreword describing the document's scope and applicability within the TRATON Group; it states no verifiable ECA obligation. Should it be treated as informative (dropped), or is a specific applicability requirement intended?; quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0212needs clarificationSYSDesign constraintQMLowReviewThe term 'Affiliate' shall mean any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, where 'control' means ownership of at least 50% of the voting rights or of the interest in the issued share capital, including any branch.N-SYS-036CR-SYS-0362CLARIFY: This is a contractual glossary definition of 'Affiliate' and 'control'; it defines terms rather than stating a verifiable ECA obligation. Confirm it should be recorded as a definition rather than a system requirement.
SSR-SYS-0213needs clarificationSYSDesign constraintQMLowTestThe ECA shall implement Secured Data Transmission (SDT) in accordance with the referenced specification.N-SYS-036CR-SYS-0363CLARIFY: The source sentence is truncated ('...follow the information provided in'). Which document or section governs the SDT implementation?
SSR-SYS-0214splitSYSDesign constraintQMLowReviewThe ECA shall maintain instances of the state variables PREQARC and PRESARC.N-SYS-036CR-SYS-0366
SSR-SYS-0214-2splitSYSDesign constraintQMLowReviewThe client shall maintain instances of the state variables PREQARC and PRESARC.N-SYS-036CR-SYS-0366
SSR-SYS-0215splitSYSDesign constraintQMLowTestWhen constructing an SDT request, the client shall increment PREQARC by one.N-SYS-036CR-SYS-0367
SSR-SYS-0215-2splitSYSDesign constraintQMLowTestWhen constructing an SDT request, the client shall populate the ANTIREPLAYCNT protocol element with the resulting PREQARC value.N-SYS-036CR-SYS-0367
SSR-SYS-0216splitSYSDesign constraintQMLowReviewWhen constructing an SDT response, the ECA shall increment PRESARC by one.N-SYS-036CR-SYS-0369
SSR-SYS-0216-2splitSYSDesign constraintQMLowReviewWhen constructing an SDT response, the ECA shall populate the ANTIREPLAYCNT protocol element with the resulting PRESARC value.N-SYS-036CR-SYS-0369
SSR-SYS-0217needs clarificationSYSDesign constraintQMLowTestWhen constructing the first request of an SDT sequence, the client shall populate the ANTIREPLAYCNT protocol element with TBD.N-SYS-037CR-SYS-0371CLARIFY: The source sentence is truncated ('...first request of an'). What value shall the ANTIREPLAYCNT protocol element of the first request of an SDT sequence be populated with (for example, zero, by analogy with the first response)?; TBD: value for the ANTIREPLAYCNT protocol element of the first request of an SDT sequence - not stated in the truncated source (likely zero, by analogy with the first response in SSR-SYS-0218).
SSR-SYS-0218splitSYSDesign constraintQMLowReviewWhen constructing the first response of an SDT sequence, the ECA shall populate the ANTIREPLAYCNT protocol element with the value zero.N-SYS-037CR-SYS-0372
SSR-SYS-0218-2splitSYSDesign constraintQMLowReviewWhen constructing the first response of an SDT sequence, the ECA shall set PRESARC to zero.N-SYS-037CR-SYS-0372
SSR-SYS-0219SYSDesign constraintQMLowTestThe client shall maintain the state variable PREQTAG.N-SYS-037CR-SYS-0373
SSR-SYS-0220splitSYSDesign constraintQMLowTestThe ECA shall construct the N argument as an octet string of length 12 octets.N-SYS-037CR-SYS-0374
SSR-SYS-0220-2splitSYSDesign constraintQMLowTestThe ECA shall set the first 10 octets of the N argument to 6E6F6E73656E73652121.N-SYS-037CR-SYS-0374
SSR-SYS-0220-3splitSYSDesign constraintQMLowTestThe ECA shall set the remaining 2 octets of the N argument to the ANTIREPLAYCNT value.N-SYS-037CR-SYS-0374
SSR-SYS-0221SYSDesign constraintQMLowTestThe ECA shall set the plaintext argument P to the octet string formed by concatenating the INTMSGREQID and the SRVSPECPARAM.N-SYS-037CR-SYS-0375
SSR-SYS-0222SYSDesign constraintQMLowTestThe client shall populate the APAR protocol element in the request with bits 0, 4, 5, and 6 set to true.N-SYS-037CR-SYS-0377
SSR-SYS-0223SYSDesign constraintQMLowTestThe client shall populate the SIGMACBYTE protocol element in the request with TAG.N-SYS-038CR-SYS-0378
SSR-SYS-0224SYSDesign constraintQMLowTestThe client shall store TAG in its state variable PREQTAG.N-SYS-038CR-SYS-0379
SSR-SYS-0225SYSDesign constraintQMLowReviewThe ECA shall populate the APAR protocol element in the response with bits 4 and 5 set to true.N-SYS-038CR-SYS-0380
SSR-SYS-0226SYSDesign constraintQMLowReviewThe ECA shall populate the SIGMACBYTE protocol element in the request with TAG.N-SYS-038CR-SYS-0381
SSR-SYS-0227needs clarificationSYSDesign constraintQMLowTestThe ECA shall place the remaining octets in the SRVSPECPARAM protocol element.N-SYS-038CR-SYS-0382CLARIFY: The source is a sentence fragment ('one octet, and the rest should go in the SRVSPECPARAM protocol element'): which data field is split, what element receives the first octet, and which entity (the ECA/server or the off-board client) places the remaining octets into the SRVSPECPARAM protocol element?; Which data field is being split into 'one octet' plus a remainder; What element receives the first octet; Whether the actor is the ECA (server) or the off-board client
SSR-SYS-0228splitSYSDesign constraintQMLowTestThe ECA shall construct the N argument as an octet string of length 12 octets.N-SYS-038CR-SYS-0383
SSR-SYS-0228-2splitSYSDesign constraintQMLowTestThe ECA shall set the first 10 octets of the N argument to 6E6F6E73656E73652121.N-SYS-038CR-SYS-0383
SSR-SYS-0228-3splitSYSDesign constraintQMLowTestThe ECA shall set the remaining 2 octets of the N argument to the ANTIREPLAYCNT value.N-SYS-038CR-SYS-0383
SSR-SYS-0229SYSDesign constraintQMLowTestThe client shall populate the APAR protocol element of the request with bits 0, 5 and 6 set to true.N-SYS-039CR-SYS-0385
SSR-SYS-0230SYSDesign constraintQMLowTestThe client shall populate the SIGMACBYTE protocol element of the request with TAG.N-SYS-039CR-SYS-0386
SSR-SYS-0231SYSDesign constraintQMLowTestThe client shall store TAG in the state variable PREQTAG.N-SYS-039CR-SYS-0387
SSR-SYS-0232SYSDesign constraintQMLowTestThe client shall verify the SDT response with the A argument set to the octet string comprising the protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string stored in the state variable PREQTAG.N-SYS-039CR-SYS-0388
SSR-SYS-0233SYSDesign constraintQMLowReviewThe ECA shall verify the SDT request with the A argument set to the octet string comprising the protocol elements of the SDT response, excluding the SIGMACBYTE protocol element.N-SYS-039CR-SYS-0389
SSR-SYS-0234SYSDesign constraintQMLowReviewThe ECA shall populate the APAR protocol element of the response with bit 5 set to true.N-SYS-039CR-SYS-0391
SSR-SYS-0235SYSDesign constraintQMLowTestThe client shall populate the SIGMACBYTE protocol element of the response with TAG.N-SYS-040CR-SYS-0392
SSR-SYS-0236SYSDesign constraintQMLowTestWhen the client receives an SDT response, if the request is too short or malformed, the client shall discard the response.N-SYS-040CR-SYS-0395Definition of 'too short' (protocol minimum length is qualitative in the source)
SSR-SYS-0237SYSDesign constraintQMLowTestWhen the client receives an SDT response, if ANTIREPLAYCNT is less than or equal to PRESARC, the client shall discard the response.N-SYS-040CR-SYS-0396Source sentence was truncated at 'discard the'; object 'response' inferred from sibling requirements CR-SYS-0395/0397
SSR-SYS-0238SYSDesign constraintQMLowTestWhen the client receives an SDT response, if the client fails to verify or decrypt the response, the client shall discard the response.N-SYS-040CR-SYS-0397
SSR-HW-0001HWDesign constraintQMLowInspectionThe ECA supplier shall provide a hardware bill of materials that lists the part number and version of each hardware component used in the product.N-HW-001REQ_SEC_0025
SSR-CYBER-0030CYBERDesign constraintQMMediumReviewThe ECA supplier shall establish, together with the vehicle manufacturer, a cybersecurity Development Interface Agreement that assigns the responsibilities for the distributed cybersecurity activities.N-CYBER-008REQ_SEC_0042
SSR-CYBER-0031CYBERDesign constraintQMMediumTestThe ECA shall verify the integrity and authenticity of the vehicle-manufacturer-specified set of data stored within the ECA.N-CYBER-009REQ_SEC_0008quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-CYBER-0032CYBERDesign constraintQMHighTestThe ECA shall verify the integrity according to the information supplied in the SDSC, including memory regions that are not programmed.N-CYBER-009CR-CYBER-0042
SSR-CYBER-0033CYBERDesign constraintQMMediumTestThe ECA shall verify the integrity of the software as part of the consistency check.N-CYBER-009CR-CYBER-0048
SSR-CYBER-0034CYBERDesign constraintQMMediumTestThe ECA shall be the only entity that carries out the integrity check.N-CYBER-009CR-CYBER-0050
SSR-CYBER-0035splitCYBERDesign constraintQMMediumReviewThe ECA shall obtain the information required to verify software integrity from the Software Data Security Container provided by the trusted source.N-CYBER-009CR-CYBER-0052
SSR-CYBER-0035-2splitCYBERDesign constraintQMMediumReviewWhere decryption is enabled, the ECA shall obtain the information required to decrypt the transported data from the Software Data Security Container provided by the trusted source.N-CYBER-009CR-CYBER-0052
SSR-CYBER-0036CYBERDesign constraintQMMediumTestIf OK is returned, the ECA shall accept the installed software as valid in terms of integrity.N-CYBER-009CR-CYBER-0053
SSR-CYBER-0037CYBERDesign constraintQMMediumTestThe ECA shall verify the authenticity and integrity of the software as part of the consistency check.N-CYBER-010REQ_UDS_0186
SSR-CYBER-0038CYBERDesign constraintQMMediumTestThe ECA shall be the only entity that carries out the authenticity and integrity check.N-CYBER-010REQ_UDS_0188
SSR-MECH-0001MECHDesign constraintQMLowInspectionThe ECA shall apply ingress and egress filtering as boundary controls on each communication interface.N-MECH-001REQ_SEC_0012
SSR-SYS-0239SYSDesign constraintQMLowTestThe ECA shall make the communication boundary controls configurable by the vehicle manufacturer.N-SYS-041REQ_SEC_0013
SSR-HW-0002HWDesign constraintQMLowTestWhile in series production, the ECA shall provide only the hardware interfaces and protocols specified by the vehicle manufacturer.N-HW-002REQ_SEC_0026
SSR-HW-0003HWDesign constraintQMLowTestWhere the ECA is returned from the field, the ECA shall support field-return analysis.N-HW-002REQ_SEC_0047
SSR-HW-0004HWDesign constraintQMLowTestWhere the ECA is enabled for field-return analysis, the ECA shall prevent its use as a spare part.N-HW-002REQ_SEC_0049
SSR-HW-0005HWDesign constraintQMLowTestThe ECA shall permit reuse by a third party only where system support from the vehicle manufacturer is provided.N-HW-002CR-HW-0006
SSR-HW-0006HWDesign constraintQMLowTestThe ECA shall report the current system state.N-HW-0026.14
SSR-HW-0007HWDesign constraintQMLowTestThe ECA shall execute a safe boot sequence that prevents unwanted or undefined behaviour during and after a loss of power or a corruption of stored data.N-HW-0027.3Precise, testable definition of 'unwanted or undefined behaviour' (source is qualitative)
SSR-HW-0008HWDesign constraintQMLowTestThe ECA shall implement short-circuit protection in hardware.N-HW-003CR-HW-0014
SSR-HW-0009splitHWDesign constraintQMLowInspectionThe ECA tab headers shall comply with TB1787.N-HW-003CR-HW-0016The self-extinguishing material class or example given after 'i.e.' in clause 7.9 is truncated in the source and is not available (TBD).
SSR-HW-0009-2splitHWDesign constraintQMLowInspectionThe ECA tab headers shall be made of a self-extinguishing material.N-HW-003CR-HW-0016
SSR-HW-0010HWDesign constraintQMLowTestThe ECA shall draw all power it uses from the battery connection.N-HW-003CR-HW-0018
SSR-HW-0011HWDesign constraintQMLowTestThe ECA shall meet the quiescent-current limit specified in CVS41 independent of the input and output conditions.N-HW-003CR-HW-0019
SSR-HW-0012HWDesign constraintQMLowTestThe ECA shall control the power-up sequence to the µP.N-HW-003CR-HW-0020
SSR-HW-0013splitHWDesign constraintQMLowTestThe ECA shall exhibit a failure rate of no more than 0 ppm at 0 km, 200 ppm/year during years 1 to 5, 400 ppm/year during years 6 to 10, and 1000 ppm/year during years 11 to 15.N-HW-003CR-HW-0023CLARIFY: Source section 8.7 ('External vulnerable components might need to be replaceable') was concatenated into this failure-rate requirement and is stated tentatively: is replaceability of external vulnerable components mandatory, and which components count as 'vulnerable'?; Whether replaceability of external vulnerable components (source 8.7) is mandatory - source uses 'might need to'; Which external components are classified as 'vulnerable'
SSR-HW-0013-2splitHWDesign constraintQMLowTestWhere the ECA uses external vulnerable components, the ECA shall make each such component replaceable.N-HW-003CR-HW-0023
SSR-HW-0014HWDesign constraintQMLowDTThe ECA shall comply with STD4158, the Scania Black List of prohibited chemical substances, in addition to CVS55 regarding the recycling and environmental requirements.N-HW-004CR-HW-0024The source uses the plural 'the following standards' but lists only STD4158; whether additional standards were intended is TBD (possible source truncation).
SSR-HW-0015splitHWDesign constraintQMLowDTThe ECA supplier shall perform the full design-verification environmental test programme at B-sample level according to CVS40 and CVS41.N-HW-004CR-HW-0026CLARIFY: The source ends mid-phrase at 'CVS40 and CVS41 (incl.': what additional scope was intended after 'incl.'?; Source truncated at 'CVS40 and CVS41 (incl.'; any additional included scope of the test programmes is unknown
SSR-HW-0015-2splitHWDesign constraintQMLowDTThe ECA supplier shall perform the full product-validation environmental test programme at C-sample level according to CVS40 and CVS41.N-HW-004CR-HW-0026
SSR-HW-0016HWDesign constraintQMLowInspectionThe ECA supplier shall test the connectors according to TB1787.N-HW-004CR-HW-0027
SSR-HW-0017HWDesign constraintQMLowTestThe ECA shall be made eligible for programming only after each programming precondition agreed between the ECA supplier and the vehicle manufacturer has been fulfilled.N-HW-004CR-HW-0028
SSR-HW-0018HWDesign constraintQMLowReviewThe ECA supplier shall agree with the vehicle manufacturer whether the ECA supports stand-alone programming at the vehicle manufacturer premises.N-HW-004CR-HW-0031
SSR-HW-0019HWDesign constraintQMLowTestIf, at startup, the ECA hardware and software are consistent and no programming request is pending, the ECA shall start and execute the application.N-HW-004CR-HW-0033
SSR-HW-0020HWDesign constraintQMLowTestThe ECA shall populate the DID with a snapshot of the mandatory lifetime ECA-runtime operational data.N-HW-005REQ_UDS_0027
SSR-HW-0021HWDesign constraintQMLowTestWhen the ECA is reset, the ECA shall restart and re-initialise within 2 s.N-HW-005REQ_UDS_0066quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-HW-0022HWDesign constraintQMLowInspectionWhere the ECA supports a request containing more than one data identifier, the ECA supplier shall document that support.N-HW-005REQ_UDS_0087
SSR-HW-0023splitHWDesign constraintQMLowTestThe ECA shall encode the ECU start-up reason in bits 0-3 and the ECU alive reason in bits 4-7 of the start-up and alive reasons data element number 54, in accordance with the value definitions in CVS124, page 49.N-HW-005CR-HW-0043
SSR-HW-0023-2splitHWDesign constraintQMLowTestAt ECU start-up, the ECA shall set the start-up reason and the alive reason to identical values.N-HW-005CR-HW-0043
SSR-HW-0024HWDesign constraintQMLowTestThe file specified by the filePathAndName parameter shall already exist in the ECA file system.N-HW-005CR-HW-0045
SSR-HW-0025HWDesign constraintQMLowTestIf the ECA received the information related to any of the conditions during the same driving cycle, the ECA shall use the received information.N-HW-005CR-HW-0046
SSR-CYBER-0039CYBERDesign constraintQMHighTestThe ECA shall allow the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECA according to the vehicle manufacturer specification.N-CYBER-011REQ_SEC_0016
SSR-CYBER-0040CYBERDesign constraintQMMediumReviewIn production vehicle systems, the ECA shall use secrets, public keys and other data for cybersecurity controls that differ from those used in the pre-production phases.N-CYBER-011REQ_SEC_0019
SSR-CYBER-0041CYBERDesign constraintQMHighestTestThe client shall generate the signatures using the private key corresponding to the client certificate.N-CYBER-011CR-CYBER-0107
SSR-CYBER-0042CYBERDesign constraintQMHighestTestThe ECA shall generate the signatures using the private key corresponding to the server certificate.N-CYBER-011CR-CYBER-0108
SSR-CYBER-0043CYBERDesign constraintQMHighestTestThe client certificate shall include the Key Usage extension defined in RFC 5280.N-CYBER-011CR-CYBER-0118
SSR-CYBER-0044CYBERDesign constraintQMHighTestThe Key Usage extension shall contain DigitalSignature.N-CYBER-011CR-CYBER-0119
SSR-CYBER-0045CYBERDesign constraintQMHighestTestThe client certificate shall include the Extended Key Usage extension defined in RFC 5280.N-CYBER-012CR-CYBER-0120
SSR-CYBER-0046CYBERDesign constraintQMLowTestEach private key shall be generated using a CRNG.N-CYBER-012CR-CYBER-0123
SSR-CYBER-0047CYBERDesign constraintQMMediumTestThe ECA shall support the HKDF key derivation function using HMAC-SHA512.N-CYBER-012CR-CYBER-0134
SSR-CYBER-0048CYBERDesign constraintQMLowTestThe salt argument to the HKDF function shall be set to the zero-length octet string.N-CYBER-012CR-CYBER-0135
SSR-CYBER-0049CYBERDesign constraintQMLowTestThe L argument to the HKDF function shall be set to 64.N-CYBER-012CR-CYBER-0136
SSR-CYBER-0050splitCYBERDesign constraintQMHighestTestThe ECA shall decrypt the request using octets 0-31 of the okm as the key.N-CYBER-012CR-CYBER-0137
SSR-CYBER-0050-2splitCYBERDesign constraintQMHighestTestThe client shall encrypt the request using octets 0-31 of the okm as the key.N-CYBER-012CR-CYBER-0137
SSR-CYBER-0051splitCYBERDesign constraintQMHighestTestThe ECA shall encrypt the response using octets 32-63 of the okm as the key.N-CYBER-013CR-CYBER-0138
SSR-CYBER-0051-2splitCYBERDesign constraintQMHighestTestThe client shall decrypt the response using octets 32-63 of the okm as the key.N-CYBER-013CR-CYBER-0138
SSR-CYBER-0052CYBERDesign constraintQMHighestTestWhere SDT_CHACHA20_POLY1305 is used, the ECA shall set the K argument to a key octet string of 32 octets.N-CYBER-013CR-CYBER-0139
SSR-CYBER-0053CYBERDesign constraintQMLowTestThe L argument to the HKDF function shall be set to 64.N-CYBER-013CR-CYBER-0144
SSR-CYBER-0054splitCYBERDesign constraintQMMediumTestThe ECA shall verify the request using octets 0-31 of the okm as the key.N-CYBER-013CR-CYBER-0145
SSR-CYBER-0054-2splitCYBERDesign constraintQMMediumTestThe client shall authenticate the request using octets 0-31 of the okm as the key.N-CYBER-013CR-CYBER-0145
SSR-CYBER-0055splitCYBERDesign constraintQMMediumTestThe ECA shall authenticate the response using octets 32-63 of the okm as the key.N-CYBER-013CR-CYBER-0146
SSR-CYBER-0055-2splitCYBERDesign constraintQMMediumTestThe client shall verify the response using octets 32-63 of the okm as the key.N-CYBER-013CR-CYBER-0146
SSR-CYBER-0056CYBERDesign constraintQMHighestTestWhere SDT_POLY1305 is used, the ECA shall set the K argument to a key octet string of 32 octets.N-CYBER-013CR-CYBER-0147
SSR-SYS-0240SYSDesign constraintQMLowTestThe ECA shall contain only the secrets agreed between the vehicle manufacturer and the ECA supplier.N-SYS-042REQ_SEC_0021
SSR-SYS-0241SYSDesign constraintQMLowTestWhile in field operation, the ECA shall keep the field-return analysis secrets disabled.N-SYS-042REQ_SEC_0048
SSR-CYBER-0057CYBERDesign constraintQMLowReviewThe ECA shall provide the capability to update its software.N-CYBER-014REQ_SEC_0043
SSR-CYBER-0058CYBERDesign constraintQMMediumReviewThe ECA supplier shall deliver the information required to verify the integrity of the flash files.N-CYBER-014CR-CYBER-0037
SSR-CYBER-0059CYBERDesign constraintQMMediumTestThe ECA shall update its software only after the integrity information has been supplied to it.N-CYBER-014CR-CYBER-0049
SSR-CYBER-0060CYBERDesign constraintQMMediumTestThe ECA shall update its software only after the authenticity and integrity information has been supplied to it.N-CYBER-014REQ_UDS_0187
SSR-CYBER-0061CYBERDesign constraintQMLowReviewWhen a cybersecurity patch becomes available, the ECA supplier shall inform the vehicle manufacturer of the patch.N-CYBER-015REQ_SEC_0030
SSR-CYBER-0062CYBERDesign constraintQMLowReviewWhen a vulnerability is identified during the product lifecycle, the ECA supplier shall communicate the vulnerability to the vehicle manufacturer within TBD.N-CYBER-015REQ_SEC_0033Reporting timeframe is unspecified: 'promptly' has no stated value and is to be agreed with the vehicle manufacturer (see CR-VAL-0004).
SSR-CYBER-0063CYBERDesign constraintQMLowReviewWhen a vulnerability has been identified and reported, the ECA supplier shall agree with the vehicle manufacturer on the initial response to the vulnerability.N-CYBER-015REQ_SEC_0034
SSR-CYBER-0064CYBERDesign constraintQMLowReviewAfter the initial vulnerability report, the ECA supplier shall provide additional information about the identified vulnerability within TBD.N-CYBER-015REQ_SEC_0035'Adequate time' has no stated value; the follow-up timeframe is to be agreed with the vehicle manufacturer.
SSR-CYBER-0065CYBERDesign constraintQMLowReviewThe ECA supplier shall include in the vulnerability information the affected hardware or software component versions, the nature of the vulnerability, the description of the affected cybersecurity goal, the technical conditions to exploit the vulnerability, the impact of the exploitation, and the means to remove the vulnerability.N-CYBER-015CR-CYBER-0029
SSR-CYBER-0066CYBERDesign constraintQMMediumReviewThe ECA supplier shall obtain the vehicle manufacturer's approval of the incident response process.N-CYBER-016REQ_SEC_0044
SSR-CYBER-0067CYBERDesign constraintQMLowReviewWhen a cybersecurity incident occurs, the ECA supplier shall follow the incident response process.N-CYBER-016REQ_SEC_0045
SSR-CYBER-0068CYBERDesign constraintQMLowReviewThe ECA supplier shall maintain the incident response process for the entire product lifetime.N-CYBER-016REQ_SEC_0046
SSR-CYBER-0069CYBERDesign constraintQMLowReviewThe ECA supplier shall manage the cybersecurity risk in coordination with the vehicle manufacturer using the incident response process.N-CYBER-016REQ_SEC_0032
SSR-CYBER-0070CYBERDesign constraintQMLowReviewThe ECA supplier shall consider each identified vulnerability in each current development project and in each project under field monitoring.N-CYBER-016REQ_SEC_0037
SSR-VAL-0005VALDesign constraintQMLowReviewThe ECA supplier shall include in the report the information needed to identify the affected vehicles or products.N-VAL-002CR-VAL-0003
SSR-VAL-0006VALDesign constraintQMLowReviewThe ECA shall report its unique individual identification number.N-VAL-0026.9
SSR-VAL-0007splitVALDesign constraintQMLowReviewThe ECA shall store its accumulated operational hours.N-VAL-0026.19.1
SSR-VAL-0007-2splitVALDesign constraintQMLowReviewThe ECA shall report its accumulated operational hours.N-VAL-0026.19.1
SSR-VAL-0008VALDesign constraintQMLowReviewThe ECA shall report its accumulated lifetime travel length.N-VAL-0026.19.2
SSR-VAL-0009splitVALDesign constraintQMLowReviewThe ECA shall support validation of the reported ESD.N-VAL-0026.23The acronym 'ESD' is not expanded in the source; its exact meaning is undefined in the provided text.
SSR-VAL-0009-2splitVALDesign constraintQMLowReviewThe ECA shall support invalidation of the reported ESD.N-VAL-0026.23
SSR-VAL-0010splitVALDesign constraintQMLowReviewThe ECA supplier shall support the PCB during the process.N-VAL-002CR-VAL-0013'The process' is not identified in the extracted text (conformal coating / PCB handling per doc 3299216_1, p.36).
SSR-VAL-0010-2splitVALDesign constraintQMLowReviewThe ECA supplier shall prevent the PCB from bending in any direction during the process.N-VAL-002CR-VAL-0013
SSR-VAL-0011needs clarificationVALDesign constraintQMLowReviewThe conformal coating process and materials shall comply with the latest version of IPC/EIA J-STD-001.N-VAL-003CR-VAL-0014CLARIFY: The source text is truncated after 'with applicable standards as e.g.' - which additional standards apply to the conformal coating process and materials, and to which specific revision of IPC/EIA J-STD-001 shall compliance be pinned?; Additional applicable standards are truncated in the source ('with applicable standards as e.g.' is cut off).; 'Latest version' is an open, time-varying reference; the specific IPC/EIA J-STD-001 revision is unspecified (R8).
SSR-VAL-0012VALDesign constraintQMLowReviewIf an error condition occurs during the programming process, the ECA shall remain re-programmable.N-VAL-003CR-VAL-0015
SSR-VAL-0013VALDesign constraintQMLowReviewThe ECA supplier shall obtain the vehicle manufacturer's review and acceptance of the proposal for each dataLocator.N-VAL-003CR-VAL-0016
SSR-VAL-0014splitVALDesign constraintQMLowReviewWhile a mechanic is working on the vehicle, the driveline shall report Not Ready.N-VAL-003CR-VAL-0017
SSR-VAL-0014-2splitVALDesign constraintQMLowReviewWhile a mechanic is working on the vehicle, the driveline shall place the vehicle in the PropulsionNotReady state.N-VAL-003CR-VAL-0017
SSR-VAL-0015VALDesign constraintQMMediumReviewThe ECA supplier shall obtain the vehicle manufacturer's approval of the reporting methods, including the stipulated reporting time.N-VAL-004CR-VAL-0004The reporting time value is unspecified ('reasonable'); it is to be stipulated and agreed with the vehicle manufacturer.
SSR-SYS-0242SYSDesign constraintQMLowInspectionThe ECA supplier shall maintain a method for monitoring the available vulnerability databases for vulnerabilities that can affect the delivered product.N-SYS-043REQ_SEC_0036
SSR-HW-0026HWDesign constraintQMLowTestThe ECA shall protect each secret specified by the vehicle manufacturer throughout the ECA lifecycle.N-HW-006REQ_SEC_0050
SSR-CYBER-0071splitCYBERDesign constraintQMLowReviewThe ECA shall identify security-related events.N-CYBER-017REQ_SEC_0051
SSR-CYBER-0071-2splitCYBERDesign constraintQMLowReviewThe ECA shall log the identified security-related events.N-CYBER-017REQ_SEC_0051
SSR-CYBER-0072CYBERDesign constraintQMHighReviewThe ECA supplier shall analyse the risks of each individual hardware component, software component, mechanical component, and other technology used in the product, independently of the scope of ISO 26262.N-CYBER-017CR-CYBER-0035
SSR-SYS-0243splitSYSDesign constraintQMHighTestThe ECA shall be a common unit across each drivetrain.N-SYS-044CR-SYS-0019
SSR-SYS-0243-2splitSYSDesign constraintQMHighTestThe ECA shall be compatible with each driveline setup.N-SYS-044CR-SYS-0019
SSR-SYS-0244SYSFunctionalQMLowTestThe ECA shall be electrically driven.N-SYS-0452.1
SSR-SYS-0245SYSFunctionalQMMediumTestThe ECA shall incorporate its own internal ECU for manoeuvring and error handling.N-SYS-0452.3
SSR-SYS-0246SYSFunctionalQMLowTestThe ECA shall reach the extreme pushrod positions A and B, measured at the center of the pushrod end.N-SYS-0454.3The dimensional values for positions A and B are defined in Figure 3 (Pushrod positions), which is not available in the provided text.
SSR-SYS-0247SYSFunctionalQMLowTestWhen the ECA is powered up with the PP in the utmost forward position, the ECA shall move the AP to its utmost reversed position.N-SYS-0454.21
SSR-SYS-0248splitSYSFunctionalQMLowTestThe ECA shall apply a preload force to the release bearing.N-SYS-0454.23
SSR-SYS-0248-2splitSYSFunctionalQMLowTestWhile the clutch is in any position, the ECA shall maintain the preload force measured at the push rod between 150 N and 250 N.N-SYS-0454.23
SSR-SYS-0249splitSYSFunctionalQMMediumTestWhen clutch disengagement is requested, the ECA shall disengage the clutch within 180 ms.N-SYS-045CR-SYS-0033Disengagement position accuracy is stated as 'according to' a requirement whose reference is blank in the source; accuracy target is TBD.
SSR-SYS-0249-2splitSYSFunctionalQMMediumTestDuring clutch disengagement, the ECA shall limit the push rod speed to a maximum of 125 mm/s.N-SYS-045CR-SYS-0033
SSR-SYS-0250splitSYSFunctionalQMLowTestWhen clutch engagement is requested, the ECA shall engage the clutch within 180 ms.N-SYS-046CR-SYS-0035
SSR-SYS-0250-2splitSYSFunctionalQMLowTestDuring clutch engagement, the ECA shall limit the push rod speed to a maximum of 125 mm/s.N-SYS-046CR-SYS-0035
SSR-SYS-0250-3splitSYSFunctionalQMLowTestThe ECA shall engage the clutch with the position accuracy specified in requirement 5.10.N-SYS-046CR-SYS-0035
SSR-SYS-0251SYSFunctionalQMLowTestThe ECA shall include a displacement sensor that measures the movement of the push rod.N-SYS-0465.5
SSR-SYS-0252splitSYSFunctionalQMLowTestThe ECA shall determine the push rod position with an accuracy of +/-1.6 mm.N-SYS-0465.6
SSR-SYS-0252-2splitSYSFunctionalQMLowTestThe ECA shall determine the push rod position with a resolution of 0.0125 mm.N-SYS-0465.6
SSR-SYS-0252-3splitSYSFunctionalQMLowTestThe ECA shall determine the push rod position with a repeatability of +/-0.1 mm.N-SYS-0465.6
SSR-SYS-0252-4splitSYSFunctionalQMLowTestThe ECA shall determine the push rod position over a range of 85 mm.N-SYS-0465.6
SSR-SYS-0253SYSFunctionalQMLowTestThe ECA shall achieve a maximum push-rod speed of at least 125 mm/s.N-SYS-046CR-SYS-0040
SSR-SYS-0254SYSFunctionalQMLowTestThe ECA shall move the push rod at the highest speed that exceeds neither its maximum achievable speed nor the maximum requested speed.N-SYS-046CR-SYS-0041quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0255SYSFunctionalQMLowTestThe ECA supplier shall perform the release frequency test at the highest operating temperature and at the maximum clutch force.N-SYS-046CR-SYS-0048Highest operating temperature value is a blank cross-reference in the source (see ...); value is TBD.
SSR-SYS-0256SYSFunctionalQMLowTestWhile the maximum allowed speed signal is received on CAN, the ECA shall limit the push rod speed to that maximum allowed speed.N-SYS-0476.4quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0257SYSFunctionalQMLowTestWhen Test Mode is requested, the ECA shall perform tests to detect latent faults.N-SYS-047CR-SYS-0059
SSR-SYS-0258SYSFunctionalQMLowTestWhile a maximum allowed speed limit is defined, the ECA shall limit the push rod speed to that limit.N-SYS-047CR-SYS-0061Source uses 'this value' and 'this limit' with no antecedent in this item; assumed to be the maximum allowed speed limit as in req 6.4; exact source and value are TBD.
SSR-SYS-0259SYSFunctionalQMLowTestWhile the ECA is in the debug or test control state, the ECA shall send the control-state value 0xC.N-SYS-0476.14.8
SSR-SYS-0260SYSFunctionalQMLowTestWhile the ECA is performing a motor brake simulation, the ECA shall send the control-state value 0xD.N-SYS-0476.14.9
SSR-SYS-0261splitSYSFunctionalQMLowReviewThe ECA shall report the current for each phase of the actuator.N-SYS-0476.17'The filter time shall equal the update frequency' mixes a time and a frequency; the intended relationship (filter window equal to the update period versus equal to the update rate) is unclear and needs confirmation (TBD).
SSR-SYS-0261-2splitSYSFunctionalQMLowReviewThe ECA shall calculate each reported phase current using a moving-mean filter.N-SYS-0476.17
SSR-SYS-0261-3splitSYSFunctionalQMLowReviewThe ECA shall set the moving-mean filter time equal to the update frequency.N-SYS-0476.17
SSR-SYS-0262needs clarificationSYSFunctionalQMLowTestWhere the CVS41 voltage limits apply, the ECA shall maintain the ECU and communication function while the supply voltage is below TBD.N-SYS-0487.18CLARIFY: For SSR-SYS-0262, what supply-voltage value may the CVS41 limits go below, and what exact behaviour is required of the ECU and communication function while the voltage is in that lower range? (Clutch actuation is covered by req 5.13.); The voltage value that CVS41 limits may go below is not given (TBD).; The required behaviour of the ECU and communication function in that voltage range is not stated (TBD).
SSR-SYS-0263splitSYSFunctionalQMLowTestWhen the wake-up line transitions to the high state during a normal start-up, the ECA shall communicate on the CAN line within 250 ms.N-SYS-048CR-SYS-0088The abnormal-start-up readiness limit is stated only as 'as soon as possible after necessary movements' with no quantified value (TBD).
SSR-SYS-0263-2splitSYSFunctionalQMLowTestWhen the wake-up line transitions to the high state during a normal start-up, the ECA shall be ready to open the clutch within 350 ms.N-SYS-048CR-SYS-0088
SSR-SYS-0263-3splitSYSFunctionalQMLowTestWhen the wake-up line transitions to the high state during an abnormal start-up, the ECA shall be ready to open the clutch within TBD ms after completing the necessary movements.N-SYS-048CR-SYS-0088
SSR-SYS-0264splitSYSFunctionalQMLowTestWhen the ECA has completed movement and reset, the ECA shall communicate on the CAN line within 250 ms.N-SYS-048CR-SYS-0089The third clause (ready to open clutch within 3 s when wake-up coincides with U30) uses 'should' in the source, so it may be a goal rather than a hard requirement; confirmation needed.
SSR-SYS-0264-2splitSYSFunctionalQMLowTestWhen the ECA has completed movement and reset, the ECA shall be ready to open the clutch within 400 ms.N-SYS-048CR-SYS-0089
SSR-SYS-0264-3splitSYSFunctionalQMLowTestWhen the wake-up line goes high simultaneously with the U30 signal, the ECA shall be ready to open the clutch within 3 s.N-SYS-048CR-SYS-0089
SSR-SYS-0265splitSYSFunctionalQMLowTestWhile in the ready-to-open-clutch state, the ECA shall keep the actuator position between FCCP and FCCP minus 3 mm.N-SYS-048CR-SYS-0090
SSR-SYS-0265-2splitSYSFunctionalQMLowTestWhile in the ready-to-open-clutch state, the ECA shall be able to move directly to the disengaged clutch position when disengagement is requested.N-SYS-048CR-SYS-0090
SSR-SYS-0266SYSFunctionalQMLowTestWhen a clutch-disengagement signal is received, the ECA shall actuate the disengagement request independently of the CAN request.N-SYS-048CR-SYS-0092
SSR-SYS-0267SYSFunctionalQMLowReviewThe ECA shall withstand 6 500 000 actuations when subjected to the test cycle described in Appendix B.N-SYS-0488.3
SSR-SYS-0268splitSYSFunctionalQMLowReviewWhile the ECA is jammed and holding the clutch open, the ECA shall allow the clutch force to be removed by following an instruction documented on the ECA drawing.N-SYS-0498.9
SSR-SYS-0268-2splitSYSFunctionalQMLowReviewThe ECA supplier shall document the clutch-force-removal instruction on the ECA drawing.N-SYS-0498.9
SSR-SYS-0269SYSFunctionalQMLowTestThe ECA supplier shall run six consecutive ECA units past 6 500 000 actuations and continue each unit to its end of life.N-SYS-049CR-SYS-0117
SSR-SYS-0270SYSFunctionalQMLowTestEach of three consecutive ECA units shall run past 6 500 000 actuations at Scania and continue to its end of life.N-SYS-049CR-SYS-0118
SSR-SYS-0271SYSFunctionalQMLowTestBetween the two movements, the ECA shall remain in the fully disengaged position.N-SYS-049CR-SYS-0152
SSR-SYS-0272SYSFunctionalQMLowTestAfter complete engagement, the ECA shall remain in the engaged position until the next disengagement is requested.N-SYS-049CR-SYS-0153
SSR-SYS-0273SYSFunctionalQMLowTestThe ECA shall check whether the software is compatible with the hardware version and with the other data structures.N-SYS-049CR-SYS-0211
SSR-SYS-0274SYSFunctionalQMLowTestThe ECA shall check whether the software is compatible with the hardware version and with the other data structures.N-SYS-050CR-SYS-0275
SSR-MECH-0002splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall mark each ECA unit in accordance with Scania STD19, using the wordmark and part-number variant defined for the involved Traton brand.N-MECH-0022.6
SSR-MECH-0002-2splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall select the marking variant based on the delivery agreement and the involved brand.N-MECH-0022.6
SSR-MECH-0002-3splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall apply marking method MA1 to each ECA unit.N-MECH-0022.6
SSR-MECH-0002-4splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall apply a marking height of 3 mm to each ECA unit.N-MECH-0022.6
SSR-MECH-0002-5splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall mark the manufacturing date on each ECA unit in the YYMMDD format.N-MECH-0022.6
SSR-MECH-0002-6splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall mark each ECA unit with a unique serial number.N-MECH-0022.6
SSR-MECH-0002-7splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall mark each ECA unit with a Data Matrix Code that contains the part number and the serial number in accordance with Scania STD4562.N-MECH-0022.6
SSR-MECH-0002-8splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall position the marking so that it is concealed when the ECA unit is mounted on a gearbox.N-MECH-0022.6
SSR-MECH-0002-9splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall deliver each ECA unit to the required Traton brand production in a pallet position where the marking is visible.N-MECH-0022.6
SSR-MECH-0003MECHDesign constraintQMLowInspectionWhile the ECA is mounted on a gearbox, the ECA shall keep the marking concealed.N-MECH-002CR-MECH-0004
SSR-MECH-0004splitMECHDesign constraintQMLowInspectionThe ECA supplier shall mark the rubber cover defined in requirement 4.16 in accordance with Scania STD19, using Tentik wordmark variant W and the 9-digit part number in the format 12 345 6789.N-MECH-0022.7
SSR-MECH-0004-2splitMECHDesign constraintQMLowInspectionThe ECA supplier shall apply marking method CAS to the rubber cover.N-MECH-0022.7
SSR-MECH-0004-3splitMECHDesign constraintQMLowInspectionThe ECA supplier shall apply a marking height of 2 mm to 6 mm to the rubber cover.N-MECH-0022.7
SSR-MECH-0004-4splitMECHDesign constraintQMLowInspectionThe ECA supplier shall apply date dial CVM to the rubber cover.N-MECH-0022.7
SSR-MECH-0004-5splitMECHDesign constraintQMLowInspectionAs an alternative design, the ECA supplier shall apply date dial CXM or an equivalent combination of a date dial and a date field to the rubber cover.N-MECH-0022.7
SSR-MECH-0004-6splitMECHDesign constraintQMLowInspectionThe ECA supplier shall position the rubber-cover marking so that it is concealed when the ECA is mounted on a gearbox.N-MECH-0022.7
SSR-MECH-0005MECHDesign constraintQMLowInspectionThe total stroke of the ECA shall be 85 mm.N-MECH-0024.2
SSR-MECH-0006splitMECHDesign constraintQMLowInspectionWhen the ECA is assembled, the ECA shall prevent an object larger than Ø0,2 mm from being inserted between the ECA and the gearbox flange into the space behind the ECA.N-MECH-0024.6
SSR-MECH-0006-2splitMECHDesign constraintQMLowInspectionThe rubber grommet at the lower part of the flange is permitted to have the same interface as the surrounding aluminium flange.N-MECH-0024.6
SSR-MECH-0007MECHDesign constraintQMLowInspectionThe ECA shall be adapted for two 10 mm guide pins.N-MECH-0024.9
SSR-MECH-0008splitMECHDesign constraintQMLowInspectionThe guide pin holes in the ECA shall have a diameter of 10.1 ±0.05 mm and a depth of at least 12 mm, with the depth measured from the centre of the oval hole in the Gearbox/ECA flange.N-MECH-0034.10
SSR-MECH-0008-2splitMECHDesign constraintQMLowInspectionThe guide pin holes shall limit the guide pin protrusion from the gearbox housing to a maximum of 14 mm, measured from the centre of the oval hole in the Gearbox/ECA flange.N-MECH-0034.10
SSR-MECH-0009splitMECHDesign constraintQMLowDTThe ECA shall be capable of being held by the guide pins alone while exposed to the maximum clutch load for up to 50 load occasions.N-MECH-0034.11Maximum clutch load value is referenced as req. 4.22 and is not restated here.
SSR-MECH-0009-2splitMECHDesign constraintQMLowDTSurface indents in the contacts are permitted where the structural integrity remains unaffected.N-MECH-0034.11
SSR-MECH-0010MECHDesign constraintQMLowInspectionThe push rod end that contacts the clutch lever shall be a Ø15,93±0,07 mm steel sphere.N-MECH-0034.12
SSR-MECH-0011splitMECHDesign constraintQMLowInspectionThe ECA shall provide support for a clutch snap-in tool on the surface marked in Figure 4, withstanding a maximum force of 1 kN.N-MECH-0034.16
SSR-MECH-0011-2splitMECHDesign constraintQMLowInspectionSurface indents are permitted where they do not affect other requirements or the structural integrity of the ECA.N-MECH-0034.16
SSR-MECH-0012MECHDesign constraintQMLowInspectionThe guide pin holes shall limit the guide pin protrusion to a maximum of 14 mm from the gearbox housing.N-MECH-003CR-MECH-0021
SSR-MECH-0013MECHDesign constraintQMLowInspectionWhen the cover is assembled, the ECA shall prevent an object larger than Ø0,2 mm from being inserted into the gearbox housing between the cover and the ECA.N-MECH-0034.18
SSR-MECH-0014splitMECHDesign constraintQMLowInspectionThe ECA shall provide a loop or similar feature where the cable can be fixated with a cable tie.N-MECH-0044.19
SSR-MECH-0014-2splitMECHDesign constraintQMLowInspectionThe loop or the Scania-assembled bracket shall be located within ±20 mm of the centre of the cable section between the connector and the last cable fixation point on the gearbox.N-MECH-0044.19
SSR-MECH-0014-3splitMECHDesign constraintQMLowInspectionThe ECA may provide an M8 screw thread and a rotation stop for a sheet metal bracket in accordance with Figure 4 - ISO view of 3D envelope.N-MECH-0044.19
SSR-MECH-0015MECHDesign constraintQMLowInspectionWhile no power is connected to the ECA, the ECA shall allow its push rod to be moved by hand with a force of at most 300 N, independent of the lever position.N-MECH-0044.25
SSR-MECH-0016splitMECHDesign constraintQMLowDTFor each stroke that the ECA performs, the ECA shall adjust to the current wear of the clutch.N-MECH-0045.7
SSR-MECH-0016-2splitMECHDesign constraintQMLowDTWhen a relative stroke is requested from the fully closed clutch position, the ECA shall achieve the step accuracy defined in requirement 5.10.N-MECH-0045.7
SSR-MECH-0017MECHDesign constraintQMMediumInspectionAfter a clutch engagement, the ECA shall update the FCCP to 90% of the step within 0,2 s per mm that the FCCP changed during the stroke.N-MECH-004CR-MECH-0031
SSR-MECH-0018splitMECHDesign constraintQMMediumInspectionFor each marking variant, the ECA marking shall use marking method MA1.N-MECH-005CR-MECH-0003
SSR-MECH-0018-2splitMECHDesign constraintQMMediumInspectionThe ECA marking shall have a marking height of 3 mm.N-MECH-005CR-MECH-0003
SSR-MECH-0018-3splitMECHDesign constraintQMMediumInspectionThe ECA marking shall use the date format YYMMDD.N-MECH-005CR-MECH-0003
SSR-MECH-0018-4splitMECHDesign constraintQMMediumInspectionThe ECA marking shall include a unique serial number.N-MECH-005CR-MECH-0003
SSR-MECH-0018-5splitMECHDesign constraintQMMediumInspectionThe ECA marking shall include a DMC according to Scania STD 4562 that contains the part number and serial number information.N-MECH-005CR-MECH-0003
SSR-MECH-0019MECHDesign constraintQMLowInspectionThe ECA supplier shall deliver each ECA unit to the required Traton brand's production positioned in the pallet so that the marking is visible.N-MECH-005CR-MECH-0005
SSR-MECH-0020MECHDesign constraintQMLowInspectionThe ECA shall be designed to support remanufacturing and refurbishment, allowing larger electronic assemblies and components to be replaced.N-MECH-0052.8Remanufacturing and refurbishment details are to be agreed with Traton (TBD).
SSR-MECH-0021MECHDesign constraintQMLowInspectionThe ECA supplier shall mark the ECA rubber cover in accordance with Scania STD19, reference 14.17, using the Tentik wordmark variant W, a 9-digit part number in the format 12 345 6789, the CAS marking method, and a marking height between 2 mm and 6 mm.N-MECH-005CR-MECH-0008
SSR-MECH-0022splitMECHDesign constraintQMLowInspectionWhen the ECA is assembled, the ECA shall provide a gap of 3.5 mm towards surface B, with a profile tolerance of ±1 mm to the nominal dimensions.N-MECH-0054.7
SSR-MECH-0022-2splitMECHDesign constraintQMLowInspectionThe surface roughness of the ECA surface opposite to surface B shall be equal to or finer than Ra 3.2 µm.N-MECH-0054.7
SSR-MECH-0023MECHDesign constraintQMLowInspectionThe ECA shall be adapted for 6 M8 flange screws described by Scania STD4435.N-MECH-0054.8
SSR-MECH-0024MECHDesign constraintQMLowInspectionThe ECA shall maintain clearance from the geometry defined in the 3D envelope 11_RFQ2030.stp, except at locations where interference fits or functional contacts are required.N-MECH-006CR-MECH-0013
SSR-MECH-0025MECHDesign constraintQMLowInspectionThe ECA shall provide space for external tools according to the cylinders defined in the attached 3D envelope.N-MECH-0064.14
SSR-MECH-0026MECHDesign constraintQMLowInspectionThe ECA shall have a window through which the snap-in tool space volume shown in Figure 6 can pass.N-MECH-0064.15
SSR-MECH-0027splitMECHDesign constraintQMLowInspectionWhen connected, the ECA shall position the connector for communication and power as indicated in Figure 4 - ISO view of 3D envelope.N-MECH-0064.20Actual length and positioning tolerances of the communication and power connector are TBD, to be agreed with Traton during the design phase.
SSR-MECH-0027-2splitMECHDesign constraintQMLowInspectionThe ECA supplier shall agree the actual length and positioning tolerances of the communication and power connector with Traton during the design phase.N-MECH-0064.20
SSR-MECH-0028splitMECHDesign constraintQMLowInspectionWhen a new position is requested and the stroke is too short to reach the requested speed, the ECA shall complete the stroke in minimum time with dynamics compliant with requirement 5.2 and this section.N-MECH-006CR-MECH-0032A dynamics reference preceding '5.2' is blank in the source; only requirement 5.2 and 'this section' are named.
SSR-MECH-0028-2splitMECHDesign constraintQMLowInspectionThe ECA shall limit the position overshoot to a maximum of 0,2 mm.N-MECH-006CR-MECH-0032
SSR-MECH-0029MECHDesign constraintQMLowInspectionThe ECA housing shall be DC-isolated from the ground.N-MECH-006CR-MECH-0034
SSR-MECH-0030splitMECHDesign constraintQMLowInspectionThe ECA shall fulfil the requirements stated in Scania STD3868.N-MECH-0079.1
SSR-MECH-0030-2splitMECHDesign constraintQMLowInspectionThe ECA shall comply with CVS55 reference 14.32, the Scania STD4158 Black list of prohibited chemical substances, and the Scania STD4159 Grey list of chemical substances with limited use.N-MECH-0079.1
SSR-MECH-0030-3splitMECHDesign constraintQMLowInspectionThe ECA supplier shall provide a material declaration in accordance with CVS 83 using the Scania IMDS reporting standard.N-MECH-0079.1
SSR-MECH-0030-4splitMECHDesign constraintQMLowInspectionThe ECA shall mark each part of the housing according to its material content.N-MECH-0079.1
SSR-MECH-0030-5splitMECHDesign constraintQMLowInspectionThe ECA shall be lead free.N-MECH-0079.1
SSR-MECH-0031MECHDesign constraintQMLowInspectionEach part of the housing shall be marked according to its material content.N-MECH-007CR-MECH-0036
SSR-MECH-0032splitMECHDesign constraintQMLowInspectionThe ECA supplier shall verify the ECA using test procedure I and test procedure II.N-MECH-00710.4quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-MECH-0032-2splitMECHDesign constraintQMLowInspectionTest procedure I shall be a comprehensive test that verifies each functional requirement and that is performed before and after exposure.N-MECH-00710.4
SSR-MECH-0032-3splitMECHDesign constraintQMLowInspectionTest procedure I shall contain at least a full stroke to evaluate speed, a staircase to evaluate accuracy, and a power loss to evaluate safety, in accordance with Figure 17 - Test procedure I.N-MECH-00710.4
SSR-MECH-0032-4splitMECHDesign constraintQMLowInspectionTest procedure II shall be a reduced function test that verifies the fundamental requirements and that can be performed during exposure.N-MECH-00710.4
SSR-MECH-0032-5splitMECHDesign constraintQMLowInspectionTest procedure II shall be performed either as a test cycle according to Appendix B at a frequency of 10 strokes per minute to 30 strokes per minute, or as a release frequency test according to requirement 5.12.N-MECH-00710.4
SSR-MECH-0033splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall include a full-stroke test to evaluate speed in Test procedure I.N-MECH-007CR-MECH-0038quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-MECH-0033-2splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall include a staircase test to evaluate accuracy in Test procedure I.N-MECH-007CR-MECH-0038
SSR-MECH-0033-3splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall include a power-loss test to evaluate safety in Test procedure I.N-MECH-007CR-MECH-0038
SSR-MECH-0033-4splitMECHDesign constraintQMMediumInspectionThe ECA supplier shall define Test procedure II as a reduced function test that verifies the fundamental requirements.N-MECH-007CR-MECH-0038
SSR-MECH-0034splitMECHDesign constraintQMLowInspectionThe ECA shall fulfil IP54 without mounted connectors.N-MECH-00710.5.16
SSR-MECH-0034-2splitMECHDesign constraintQMLowInspectionThe ECA shall fulfil ingress protection classes IP6K6K, IP6K7, and IP6K9K.N-MECH-00710.5.16
SSR-MECH-0035MECHDesign constraintQMLowInspectionWhere the RoutineIdentifier is invoked, the ECA shall verify the authenticity of the received file package.N-MECH-007REQ_UDS_0169Cross-reference is truncated ('See CVS123 and ...'); the second reference is missing.
SSR-SYS-0275SYSDesign constraintQMLowTestThe ECA supplier shall invite Traton to participate in the electrical and mechanical design reviews.N-SYS-051CR-SYS-0024
SSR-SYS-0276SYSDesign constraintQMLowTestThe ECA shall prevent a shoot-through internal short circuit in each H-bridge.N-SYS-0517.1
SSR-HW-0027HWDesign constraintQMLowTestWhere the PP is fully calculated from the AP-sensor, the ECA shall apply no offset to the PP.N-HW-007CR-HW-0007'This offset' refers to a PP-to-AP offset defined earlier in the source and is not restated here.
SSR-CYBER-0073splitCYBERDesign constraintQMLowTestWhen the push rod is pulled 50 times with a force of 300 N, the ECA shall retain the push rod.N-CYBER-0184.13
SSR-CYBER-0073-2splitCYBERDesign constraintQMLowTestWhere the push rod has a loose fit in the ECA, the ECA shall allow the push rod to be reconnected by pushing it back by hand.N-CYBER-0184.13
SSR-CYBER-0074CYBERDesign constraintQMMediumTestThe ECA supplier shall hash each software version released for integration test, production, or service market.N-CYBER-018CR-CYBER-0036
SSR-CYBER-0075splitCYBERDesign constraintQMLowTestWhere a message-definition table marks a field as included in proofOfOwnershipServer, the ECA shall cover the field with the proofOfOwnershipServer signature.N-CYBER-018CR-CYBER-0098
SSR-CYBER-0075-2splitCYBERDesign constraintQMLowTestThe ECA shall include the proofOfOwnershipServer signature in the ECA response.N-CYBER-018CR-CYBER-0098
SSR-CYBER-0076needs clarificationCYBERDesign constraintQMLowReviewWhen the ECA receives an SDT request while the security sub-layer is busy, the ECA shall respond with TBD.N-CYBER-018CR-CYBER-0148CLARIFY: The source sentence is truncated at 'shall respond with'. What exact response (for example a negative response code such as busyRepeatRequest 0x21, or a specific message) must the ECA return when an SDT request arrives while the security sub-layer is busy?; Response code or message the ECA must return when the security sub-layer is busy
SSR-SYS-0277needs clarificationSYSDesign constraintQMLowReviewWhere the mating component has a loose fit in the ECA, the ECA shall allow the mating component to be reconnected by pushing it back into position by hand.N-SYS-052CR-SYS-0028CLARIFY: The customer statement uses 'it' with no antecedent. Which component has the loose fit and must be manually reconnectable (for example the pushrod, a pin, or an electrical connector)?
SSR-SYS-0278splitSYSDesign constraintQMLowTestThe ECA shall comply with the CAN communication messages specified in PD2497100 to the full extent.N-SYS-0526.2Criteria for when additional checksums and message counters are required ('if needed' is unspecified in the source)
SSR-SYS-0278-2splitSYSDesign constraintQMLowTestThe ECA shall be controlled by messages on the CAN bus and by the PWM signal specified in requirements 7.24 to 7.33.N-SYS-0526.2
SSR-SYS-0278-3splitSYSDesign constraintQMLowTestWhere messages require additional integrity protection, the ECA shall complement the messages with checksums and message counters.N-SYS-0526.2
SSR-SYS-0279SYSDesign constraintQMLowTestThe ECA shall keep CAN communication active.N-SYS-052CR-SYS-0060Operating condition or state during which CAN communication must remain active ('still' implies a context not included in the extracted sentence)
SSR-SYS-0280SYSDesign constraintQMLowTestThe ECA shall identify the FCCP according to the restrictions defined by the self-adjustment signal.N-SYS-052CR-SYS-0062
SSR-SYS-0281SYSDesign constraintQMLowTestThe ECA shall connect the wake-up signal to a digital input on the microprocessor.N-SYS-052CR-SYS-0086
SSR-SYS-0282splitSYSDesign constraintQMLowTestThe ECA CAN front end shall be designed to comply with TB1905 reference 14.3.N-SYS-0527.34
SSR-SYS-0282-2splitSYSDesign constraintQMLowTestEach watchdog circuit in the ECA shall operate independently of the CAN bus.N-SYS-0527.34
SSR-SYS-0283SYSDesign constraintQMLowTestThe ECA shall provide a CAN controller and a CAN transceiver that are CAN FD ready.N-SYS-0537.35
SSR-SYS-0284SYSDesign constraintQMLowTestEach ECA watchdog circuit shall leave the CAN bus unaffected.N-SYS-053CR-SYS-0095
SSR-SYS-0285SYSDesign constraintQMLowTestThe ECA CAN front end shall comply with TB1905.N-SYS-053CR-SYS-0096
SSR-SYS-0286splitSYSDesign constraintQMLowTestThe ECA PCB layout shall always include the CAN circuit section.N-SYS-0537.39
SSR-SYS-0286-2splitSYSDesign constraintQMLowTestThe ECA supplier shall allow the CAN-related components in the CAN circuit section to be changed or removed.N-SYS-0537.39
SSR-SYS-0287splitSYSDesign constraintQMLowTestThe ECA shall provide a footprint for connecting the CAN shield to system ground 31_ECA through a resistor and a capacitor in series.N-SYS-0537.40
SSR-SYS-0287-2splitSYSDesign constraintQMLowTestBy default, the ECA shall leave the resistor and the capacitor unpopulated.N-SYS-0537.40
SSR-SYS-0287-3splitSYSDesign constraintQMLowTestThe ECA CAN front end shall be designed to comply with TB1905 reference 14.3.N-SYS-0537.40
SSR-SYS-0288SYSDesign constraintQMLowTestThe ECA CAN front end shall comply with TB1905.N-SYS-053CR-SYS-0100
SSR-SYS-0289SYSDesign constraintQMLowTestThe ECA PCB layout and component placement shall accommodate the application of conformal coating.N-SYS-054CR-SYS-0105
SSR-SYS-0290SYSDesign constraintQMLowTestThe ECA shall maintain CAN communication.N-SYS-054CR-SYS-0126Event or condition during which CAN communication must be unaffected (not included in the extracted sentence)
SSR-SYS-0291SYSDesign constraintQMLowReviewThe ECA supplier shall perform life-time testing of the ECA consisting of 6,500,000 repetitions of the test cycle described in 'I - Test cycle'.N-SYS-054CR-SYS-0151
SSR-SYS-0292SYSDesign constraintQMLowReviewWhere the ECA is programmed stand-alone at the vehicle manufacturer over DoCAN, the ECA shall support a 1 Mbit/s transfer speed.N-SYS-054CR-SYS-0184
SSR-SYS-0293SYSDesign constraintQMLowTestThe ECA shall support the parameter EMP message according to CVS33.N-SYS-054CR-SYS-0217
SSR-SYS-0294splitSYSDesign constraintQMLowTestThe ECA shall use the start address as an offset in the software module.N-SYS-054CR-SYS-0221
SSR-SYS-0294-2splitSYSDesign constraintQMLowTestThe ECA shall use the length to determine which areas of the software module are verified, decrypted, or both.N-SYS-054CR-SYS-0221
SSR-SYS-0295SYSDesign constraintQMLowTestIf the parameter suppressPosRespMsgIndicationBit is true in a functionally addressed request message, the ECA shall preserve each ongoing physically addressed service.N-SYS-055REQ_UDS_0081
SSR-SYS-0296needs clarificationSYSDesign constraintQMLowReviewThe ECA shall allow access rights to be added to or removed from a client or tester independently of the roles assigned to the client or tester.N-SYS-055CR-SYS-0300CLARIFY: The source is an explanatory benefit statement ('It can also be useful if you want to...'), not a requirement. Should the ECA support adding or removing individual access rights for a client or tester independently of assigned roles, and if so, what is the exact required behavior?
SSR-SYS-0297SYSDesign constraintQMLowTestWhen evaluating each DID, the ECA shall parse both the pattern-rules and the DID-rules.N-SYS-055CR-SYS-0303
SSR-SYS-0298SYSDesign constraintQMLowTestThe ECA shall format the response as a valid SDT positive response according to ISO 14299-1:2020.N-SYS-055CR-SYS-0365Triggering condition for the positive response (for example upon successful SDT request verification) is not included in the extracted sentence
SSR-SYS-0299splitSYSDesign constraintQMLowTestWhen the ECA receives an SDT request, the ECA shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PREQARC.N-SYS-055CR-SYS-0368quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0299-2splitSYSDesign constraintQMLowTestWhen the SDT request is otherwise verified, the ECA shall update PREQARC to the value of the ANTIREPLAYCNT protocol element.N-SYS-055CR-SYS-0368
SSR-SYS-0300splitSYSDesign constraintQMLowTestWhen the client receives an SDT response, the client shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PRESARC.N-SYS-055CR-SYS-0370quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0300-2splitSYSDesign constraintQMLowTestWhen the SDT response is otherwise verified, the client shall update PRESARC to the value of the ANTIREPLAYCNT protocol element.N-SYS-055CR-SYS-0370
SSR-SYS-0301splitSYSDesign constraintQMLowTestWhen the ECA injects C into or extracts C from an SDT message, the ECA shall map the first octet of C to INTMSGREQID.N-SYS-056CR-SYS-0376
SSR-SYS-0301-2splitSYSDesign constraintQMLowTestWhen the ECA injects C into or extracts C from an SDT message, the ECA shall map the remaining octets of C to SRVSPECPARAM.N-SYS-056CR-SYS-0376
SSR-MECH-0036splitMECHDesign constraintQMLowDTThe ECA shall equip the hole with a cover that can be assembled and disassembled at least 50 times without tools.N-MECH-0084.17
SSR-MECH-0036-2splitMECHDesign constraintQMLowDTWhere an interference fit is chosen for the cover, the maximum force to assemble or disassemble the cover shall be 50 N at room temperature.N-MECH-0084.17
SSR-MECH-0036-3splitMECHDesign constraintQMLowDTThe cover shall remain intact and maintain its tightness after the vibration testing defined in requirement 10.5.N-MECH-0084.17
SSR-MECH-0037MECHDesign constraintQMLowDTWhere an interference fit is chosen, the force to assemble or disassemble the ECA at room temperature shall be at most 50 N.N-MECH-008CR-MECH-0026
SSR-SYS-0302SYSFunctionalQMLowTestThe ECA supplier shall agree the actual length and positioning tolerances with the vehicle manufacturer during the design phase.N-SYS-057CR-SYS-0030
SSR-SYS-0303SYSFunctionalQMLowTestThe ECA shall achieve the maximum disengage time defined in Figure 7 when measured against the maximum disengage force defined in Appendix A.N-SYS-057CR-SYS-0034Maximum disengage time value (Figure 7) not provided in the source; Maximum disengage force value (Appendix A) not provided in the source
SSR-SYS-0304SYSFunctionalQMLowTestThe ECA shall achieve the maximum engage time defined in Figure 8 when measured against the minimum engage force defined in Appendix A.N-SYS-057CR-SYS-0036Maximum engage time value (Figure 8) not provided in the source; Minimum engage force value (Appendix A) not provided in the source
SSR-SYS-0305SYSFunctionalQMLowTestThe ECA shall keep the stationary position error relative to the real FCCP, defined as the sum of the self-adjustment error and the step response error, within +/-0.15 mm.N-SYS-0575.9
SSR-SYS-0306SYSFunctionalQMLowTestWhen a new requested position value is sent, the ECA shall achieve the requested speed, limited to 125 mm/s, within 50 ms.N-SYS-057CR-SYS-0042
SSR-SYS-0307SYSFunctionalQMLowTestThe ECA shall maintain the requested speed until 2 mm from the target position.N-SYS-057CR-SYS-0043
SSR-SYS-0308SYSFunctionalQMLowTestWhen 100 ms have elapsed after reaching 2 mm from the target position, the ECA shall keep the position error within +/-0.1 mm.N-SYS-058CR-SYS-0044
SSR-SYS-0309SYSFunctionalQMLowTestThe ECA supplier shall verify the step accuracy defined in requirement 5.10 using the step response test cycle in accordance with Figure 10 - Step response test cycle.N-SYS-0585.11
SSR-SYS-0310SYSFunctionalQMLowTestWhile the supply voltage is between 16 V and loss of power, the ECA shall either hold the current position or move toward the requested position, with no timing constraint.N-SYS-058CR-SYS-0049
SSR-SYS-0311SYSFunctionalQMLowTestWhile self-adjustment is disabled, indicated by signal value 0x3, the ECA shall freeze the fully closed clutch position value at the last identified position and use it for Relative Position Control.N-SYS-0586.5.2
SSR-SYS-0312SYSFunctionalQMLowTestWhile self-adjustment is disabled, the ECA shall freeze the fully closed clutch position value at the last identified position and use it for Relative Position Control.N-SYS-058CR-SYS-0064The triggering condition (self-adjustment disabled) is inferred from the section 6.5 self-adjustment context and consistency with SSR-SYS-0311; to be confirmed with Traton.
SSR-SYS-0313SYSFunctionalQMLowTestThe ECA supplier shall analyze the quality and position of the wire bonding.N-SYS-058CR-SYS-0102
SSR-SYS-0314SYSFunctionalQMLowTestThe ECA supplier shall declare the melting point and the composition of the soldering material.N-SYS-059CR-SYS-0103
SSR-SYS-0315SYSFunctionalQMMediumTestWhile the clutch is fully engaged, the active control mode is position control or torque control, and there is no active request to extract the pushrod, the ECA shall keep the applied force within the preload force limits.N-SYS-060CR-SYS-0032Preload force limit values and the requirement reference are cut off in the source ('defined in req.')
SSR-SYS-0316SYSFunctionalQMHighestTestWhen the ECA is actuating Torque Control, the ECA shall report 0x4 as its active state via CAN.N-SYS-0606.14.4
SSR-SYS-0317splitSYSFunctionalQMMediumReviewThe ECA shall calculate the actuator motor torque.N-SYS-0606.16
SSR-SYS-0317-2splitSYSFunctionalQMMediumReviewThe ECA shall report the actuator motor torque.N-SYS-0606.16
SSR-MECH-0038MECHDesign constraintQMLowInspectionThe ECA shall report the absolute position of the current actuator stroke.N-MECH-0095.3
SSR-MECH-0039MECHDesign constraintQMLowInspectionThe ECA shall report the fully closed clutch position as an absolute position of the actuator stroke relative to the absolute zero position.N-MECH-0095.4
SSR-CYBER-0077CYBERDesign constraintQMLowTestWhile subjected to the maximum disengage force defined in Appendix A and the highest operating temperature defined in requirement 8.1, the ECA shall keep the clutch disengaged continuously for at least 120 minutes while retaining its function.N-CYBER-0195.14
SSR-SYS-0318SYSFunctionalQMLowTestThe ECA shall achieve the maximum disengage time when measured against the maximum disengage force defined in Appendix A at the highest operating temperature.N-SYS-061CR-SYS-0051Maximum disengage time limit value not provided; Highest operating temperature value and its requirement reference are cut off ('see req.'); Maximum disengage force value (Appendix A) not provided
SSR-SW-0001splitSWFunctionalQMLowTestWhen Absolute Position Control is requested using control mode value 0x01, the ECA shall move to the actuator position defined by the requested position.N-SW-0016.3.1The scope of the 'specific cases' requiring Traton approval is interpreted as cases where the ECA controls movement to protect against hardware damage; to be confirmed.
SSR-SW-0001-2splitSWFunctionalQMLowTestThe ECA may control its movement to protect the ECA and the clutch from hardware damage.N-SW-0016.3.1
SSR-SW-0001-3splitSWFunctionalQMLowTestThe ECA supplier shall agree with Traton each specific case in which the ECA controls its movement to protect the ECA or the clutch from hardware damage.N-SW-0016.3.1
SSR-SW-0002splitSWFunctionalQMLowReviewWhen Relative Position Control is requested, the ECA shall move to an offset from the FCCP that corresponds to the Requested Position.N-SW-0016.3.2
SSR-SW-0002-2splitSWFunctionalQMLowReviewWhile in Relative Position Control, the ECA shall accept a Requested Position up to the full release travel of 22.4 mm.N-SW-0016.3.2
SSR-SW-0002-3splitSWFunctionalQMLowReviewWhen the Requested Position is 0 in Relative Position Control, the ECA shall keep the actuator position at or below the FCCP.N-SW-0016.3.2
SSR-SYS-0319SYSFunctionalQMLowTestWhen Absolute Position Control is requested, the ECA shall move to the actuator position defined by the Requested Position.N-SYS-062CR-SYS-0055
SSR-SYS-0320SYSFunctionalQMLowTestWhen the ECA is actuating Absolute Position Control, the ECA shall report 0x1 as its active state via CAN.N-SYS-0626.14.2
SSR-SYS-0321SYSFunctionalQMLowTestWhen the ECA is actuating Relative Position Control, the ECA shall report 0x2 as its active state via CAN.N-SYS-0626.14.3
SSR-SW-0003SWFunctionalQMHighTestWhen Torque Control is requested, the ECA shall actuate the requested motor torque.N-SW-002CR-SW-0003
SSR-SW-0004SWFunctionalQMLowTestWhen Test Mode is sent, the ECA shall behave, with respect to actuator control, as if the power supply were cut.N-SW-003CR-SW-0004
SSR-SW-0005SWFunctionalQMLowReviewWhile the ECA is in boot mode, the ECA shall report 0x00 as the active state.N-SW-003CR-SW-0007
SSR-VAL-0016VALDesign constraintQMLowReviewThe ECA shall report a complete software version number in the range 0 to 64255.N-VAL-0056.11
SSR-VAL-0017VALDesign constraintQMLowReviewThe ECA shall report a complete hardware version number in the range 0 to 64255.N-VAL-0056.12
SSR-SYS-0322splitSYSFunctionalQMLowTestWhen low accuracy mode is requested using accuracy mode value 0x0, the ECA shall limit the push rod position error to a maximum of ±0.5 mm.N-SYS-063CR-SYS-0066
SSR-SYS-0322-2splitSYSFunctionalQMLowTestThe ECA shall fulfil the accuracy defined in requirement 5.10.N-SYS-063CR-SYS-0066
SSR-SW-0006SWFunctionalQMMediumTestThe ECA shall send, via CAN, a bit field containing the errors that are present.N-SW-004CR-SW-0005The CAN bit-field layout (bit-to-error mapping) and the content referenced by the truncated 'Additionally, see,' cross-reference are not provided in the source.
SSR-SW-0007SWFunctionalQMLowTestThe ECA shall execute the new software only after the new software has been verified using routine 0xFF01.N-SW-004CR-SW-0039
SSR-SW-0008SWFunctionalQMMediumTestIf executing an ECUReset would compromise vehicle safety, the ECA shall reject the ECUReset request.N-SW-004REQ_UDS_0062The criteria that define when an ECUReset 'would compromise vehicle safety' are not specified in the source.
SSR-SW-0009SWFunctionalQMLowTestAfter sending a positive response message to an ECUReset request, the ECA shall be available for ECU identification within 1 second.N-SW-004REQ_UDS_0065quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SW-0010SWFunctionalQMLowTestThe ECA shall send the ECUReset positive response message after completing the preceding reset tasks and before performing the actual resetType.N-SW-004CR-SW-0090'The preceding reset tasks' references tasks listed earlier in the source ('the server tasks above') that are not included in this item.
SSR-SW-0011SWFunctionalQMLowTestWhen an application-layer service 0x29 request is received inside a service 0x84 SDT-protected message, the ECA shall reject the service 0x29 request.N-SW-004CR-SW-0203
SSR-SW-0012SWFunctionalQMLowTestThe ECA shall reject an SDT message that uses service 0x84 as its application-layer service encapsulated inside another service 0x84.N-SW-005CR-SW-0233
SSR-SW-0013SWFunctionalQMLowTestWhile the ECA is performing its initiation routine and is unavailable for control, the ECA shall report 0xA as its active state via CAN.N-SW-0066.14.6
SSR-SW-0014SWFunctionalQMLowTestWhen pre-programming the application module, the ECA supplier shall set ECU and software identifiers 0xF187 and 0xF188 to the product-specific values defined by the vehicle manufacturer.N-SW-006CR-SW-0021The specific product-specific values for 0xF187 and 0xF188 are defined by the vehicle manufacturer and are not provided in this item.
SSR-SW-0015SWFunctionalQMLowTestWhere the application module is delivered without supplier pre-programming, the ECA shall set the ECU and software identifiers 0xF187 and 0xF188 to the default values defined in CVS124.N-SW-006CR-SW-0022
SSR-SW-0016splitSWFunctionalQMLowTestIf the ECA hardware or software is inconsistent at startup, the ECA shall start and execute the boot loader.N-SW-006CR-SW-0030
SSR-SW-0016-2splitSWFunctionalQMLowTestIf the ECA hardware or software is inconsistent at startup, the ECA shall reset the data identifiers 0xF181, 0xF187, 0xF188, and 0xF1A1 to their default values.N-SW-006CR-SW-0030
SSR-SW-0017SWFunctionalQMLowTestIf an error occurs during decryption of data, the ECA shall return NRC 0x10.N-SW-006CR-SW-0043
SSR-SW-0018SWFunctionalQMLowTestThe ECA shall support service 0x84 in accordance with CVS32.N-SW-006CR-SW-0046
SSR-SW-0019SWFunctionalQMLowTestThe ECA shall execute the specified RoutineIdentifier independently of the programming sequence.N-SW-007CR-SW-0054The specific RoutineIdentifier value ('This RoutineIdentifier') is defined in preceding source context not included in this item.
SSR-SW-0020SWFunctionalQMLowTestWhere the client requests execution of the routineIdentifier as a standalone procedure, the ECA shall perform a software consistency check.N-SW-007CR-SW-0055
SSR-SW-0021SWFunctionalQMLowTestThe client shall send the ECA routineStatus and routineResult response to the backend.N-SW-007CR-SW-0059
SSR-SW-0022SWFunctionalQMLowTestThe ECA shall support the routine negative response in accordance with CVS33.N-SW-007CR-SW-0061
SSR-SW-0023needs clarificationSWFunctionalQMLowTestThe ECA implementation shall comply with ISO 14229-1.N-SW-007REQ_UDS_0001CLARIFY: The source ends mid-sentence: '...shall be compliant with ISO 14229-1 with the'. What follows 'with the' (for example specific exceptions, additional constraints, or a referenced release/deviation list)?; Source sentence is truncated after 'with the', so any qualification to the ISO 14229-1 compliance is unknown.
SSR-SW-0024SWFunctionalQMLowTestThe ECA shall implement each project-specific DID within the system-supplier-specific data identifier range defined in ISO 14229-1.N-SW-007REQ_UDS_0052
SSR-SW-0025SWFunctionalQMLowTestThe ECA shall support the SPRMIB for the services specified in ISO 14229-1.N-SW-008REQ_UDS_0055
SSR-SW-0026SWFunctionalQMLowTestThe ECA shall limit the supported negative response codes from ISO 14229-1 Annex A.1 to those explicitly specified by this specification or its normative references.N-SW-008REQ_UDS_0056
SSR-SW-0027SWFunctionalQMLowTestIf communication is still switched on, the ECA shall respond with NRC 0x22.N-SW-008CR-SW-0080
SSR-SW-0028SWFunctionalQMLowTestWhere the ECA is involved in engine start, the ECA shall postpone processing of CommunicationControl service requests until 2 seconds after terminal 15 becomes active.N-SW-008REQ_UDS_0075
SSR-SW-0029splitSWFunctionalQMLowTestIf a request is received before the 2-second period has elapsed, the ECA shall respond with either NRC 0x78 or NRC 0x22.N-SW-008CR-SW-0093'This time' is interpreted as the 2-second period referenced in the source (REQ_UDS_0075 / preceding context).
SSR-SW-0029-2splitSWFunctionalQMLowTestWhere the ECA responds with NRC 0x78, the ECA shall process the request and send a final response after the 2-second period has elapsed.N-SW-008CR-SW-0093
SSR-SW-0030SWFunctionalQMLowTestThe ECA shall support writing data records with service 0x2E WriteDataByIdentifier in any order.N-SW-008REQ_UDS_0089
SSR-SW-0031needs clarificationSWFunctionalQMLowTestIf the specified action is necessary, the ECA shall integrate the action implicitly into the ECU Reset service 0x11 subfunction 0x02.N-SW-009CR-SW-0103CLARIFY: What is 'this action' that must be integrated implicitly into ECU Reset (0x11) subfunction 0x02, and under what condition is it 'necessary'? The referent is defined in preceding source context not included here.; 'This action' references content in the preceding source context not included in this item.
SSR-SW-0032needs clarificationSWFunctionalQMLowTestWhere the ECA is one of the specified ECUs, the ECA shall set each of the specified bytes to the default value 0xFF.N-SW-009CR-SW-0119CLARIFY: Which ECUs ('these ECUs') and which bytes ('these bytes') does this apply to? Both reference preceding source context not included in this item.; The set of applicable ECUs and the specific bytes reference preceding source context not included in this item.
SSR-SW-0033SWFunctionalQMLowTestThe ECA shall provide negative response codes in accordance with ISO 14229-1.N-SW-009REQ_UDS_0282
SSR-SW-0034SWFunctionalQMLowTestThe ECA shall conform to the data identifier ranges specified in ISO 14229-1.N-SW-009REQ_UDS_0102
SSR-SW-0035SWFunctionalQMLowTestThe ECA shall provide the negative response format and codes in accordance with ISO 14229-1.N-SW-009REQ_UDS_0294
SSR-SW-0036SWFunctionalQMLowTestThe ECA shall support negative response codes in accordance with ISO 14229-1.N-SW-009REQ_UDS_0146
SSR-SW-0037SWFunctionalQMLowReviewIf each precondition is satisfied, the ECA shall omit the routineStatus byte from the response.N-SW-010REQ_UDS_0156
SSR-SW-0038SWFunctionalQMLowTestThe ECA shall send a response to RoutineIdentifier 0x2401 Software Installation without requiring further input from the client.N-SW-010REQ_UDS_0171
SSR-SW-0039SWFunctionalQMLowTestIf authenticity verification fails, the ECA shall send the positive response with AuthenticityVerificationStatus bits 7-6 set to 0x02 and SoftwareInstallationStatus bits 7-6 set to 0x02.N-SW-010REQ_UDS_0172
SSR-SW-0040SWFunctionalQMLowTestIf no authenticity verification takes place as part of the RoutineIdentifier, the ECA shall set AuthenticityVerificationStatus bits 7-6 to 0x01.N-SW-010REQ_UDS_0178
SSR-SW-0041splitSWFunctionalQMLowTestThe ECA shall allow the client to start a consistency check of the ECA using the RoutineIdentifier.N-SW-010CR-SW-0166The specific RoutineIdentifier value is defined in preceding source context not included here.
SSR-SW-0041-2splitSWFunctionalQMLowTestThe ECA should execute the RoutineIdentifier independently of the programming sequence.N-SW-010CR-SW-0166
SSR-SW-0042SWFunctionalQMLowTestThe ECA shall set the default timestamp value to 0xFF in each byte.N-SW-010REQ_UDS_0207Source phrase 'in each data' is ambiguous; interpreted as each byte of the timestamp field.
SSR-SW-0043SWFunctionalQMLowTestIf the occurrence counter is set to 1, the ECA shall set the timestamp of the latest occurrence to 0xFF.N-SW-011REQ_UDS_0211
SSR-SW-0044SWFunctionalQMLowTestIf no source of vehicle distance information provides current data, the ECA shall set the distance information to 0xFF in each byte.N-SW-011REQ_UDS_0214
SSR-SW-0045SWFunctionalQMLowTestIf no source of operational hours information provides current data, the ECA shall set the operational hours information to 0xFF in each byte.N-SW-011REQ_UDS_0219
SSR-SW-0046SWFunctionalQMLowTestWhere the ECA is a Linux-based system still running in boot, the ECA should indicate via DID 0xF1AD that it is running in boot.N-SW-011CR-SW-0182
SSR-SW-0047SWFunctionalQMLowTestThe client shall use the value estimation for P2*Client given in ISO 14229-2.N-SW-011REQ_UDS_0228
SSR-SW-0048SWFunctionalQMLowTestIf an encapsulated service 0x29 request is detected, the ECA shall return the application-layer NRC 0x39 as a correctly formatted SDT positive response.N-SW-011CR-SW-0204
SSR-SW-0049needs clarificationSWFunctionalQMLowTestThe ECA shall respond with the application-layer NRC 0x39.N-SW-012CR-SW-0234CLARIFY: The source is truncated after 'i.e.'. Under what condition shall the ECA respond with application-layer NRC 0x39, and what does the 'i.e.' clause specify (for example delivery as a correctly formatted SDT positive response for a service 0x84 message encapsulated inside another service 0x84, per CVS32/CR-SW-0233)?; Triggering condition for NRC 0x39 and the truncated 'i.e.' clarification are not provided in the source.
SSR-SW-0050SWFunctionalQMLowTestThe client shall populate the SIGLEN protocol element in the request with the value 0x0010.N-SW-012CR-SW-0238
SSR-SW-0051SWFunctionalQMLowTestThe ECA shall populate the SIGLEN protocol element with the value 0x0010.N-SW-012CR-SW-0239Source states 'in the request' for the ECA (server); populating SIGLEN in the request rather than the response is atypical, so the message context (request vs response) needs confirmation.
SSR-SW-0052SWFunctionalQMLowTestThe client shall populate the SIGLEN protocol element in the SDT request with the value 16.N-SW-012CR-SW-0240
SSR-SW-0053SWFunctionalQMLowTestThe ECA shall populate the SIGLEN protocol element in the SDT response with the value 16.N-SW-012CR-SW-0241
SSR-SW-0054SWFunctionalQMLowTestWhen the ECA receives an SDT request that has an incorrect length or an invalid format, the ECA shall respond with an SDT negative response using NRC 0x13.N-SW-012CR-SW-0245
SSR-SW-0055SWFunctionalQMLowTestWhen the ECA receives an SDT request, if ANTIREPLAYCNT is less than or equal to PREQARC, the ECA shall respond with an SDT negative response using NRC 0x3A.N-SW-013CR-SW-0246
SSR-SW-0056SWFunctionalQMLowTestWhen the ECA receives an SDT request, if PRESARC is exhausted, the ECA shall respond with an SDT negative response using NRC 0x3A.N-SW-013CR-SW-0247
SSR-SW-0057SWFunctionalQMLowTestWhen the ECA receives an SDT request, if verification or decryption of the request is unsuccessful, the ECA shall respond with an SDT negative response using NRC 0x3A.N-SW-013CR-SW-0251
SSR-SW-0058splitSWFunctionalQMLowTestIf the client determines that an SDT request has been lost in transit, or if the client receives an SDT negative response with NRC 0x21, the client shall repeat the request byte for byte.N-SW-013CR-SW-0252
SSR-SW-0058-2splitSWFunctionalQMLowTestWhile repeating the request, the client shall preserve its state variables.N-SW-013CR-SW-0252
SSR-HW-0028HWDesign constraintQMLowDTThe ECA shall report the current system temperature.N-HW-0086.15Reporting interface, resolution and accuracy for the temperature value are not specified in the source.
SSR-HW-0029splitHWDesign constraintQMLowInspectionThe ECA solder material shall be lead-free.N-HW-008CR-HW-0021'High-temperature solder type' is not quantified (no temperature class or standard cited).
SSR-HW-0029-2splitHWDesign constraintQMLowInspectionThe ECA solder material shall be of a high-temperature solder type.N-HW-008CR-HW-0021
SSR-HW-0030HWDesign constraintQMLowTestThe ECA shall report the current input voltage.N-HW-0096.18Reporting interface, resolution and accuracy for the voltage value are not specified in the source.
SSR-HW-0031splitHWDesign constraintQMLowInspectionThe ECA shall provide geometric coding for each external electrical connector.N-HW-0097.5
SSR-HW-0031-2splitHWDesign constraintQMLowInspectionWhere internal components are included in repair kits, the ECA shall provide geometric coding for each internal electrical connector.N-HW-0097.5
SSR-HW-0032HWDesign constraintQMLowInspectionWhere internal components are included in a repair kit, the internal electrical connectors of the ECA shall also be geometrically coded.N-HW-009CR-HW-0015
SSR-HW-0033splitHWDesign constraintQMLowInspectionThe ECA shall be free of tantalum capacitors.N-HW-009CR-HW-0022
SSR-HW-0033-2splitHWDesign constraintQMLowInspectionThe power supply circuits of the ECA shall be free of serial resistors.N-HW-009CR-HW-0022
SSR-HW-0034HWDesign constraintQMLowTestThe ECA shall remain re-programmable within the normal operating voltage range specified by [11] for 24V systems or by [12] for 12V systems.N-HW-009CR-HW-0034Actual voltage-range limits are defined in referenced documents [11] (24V systems) and [12] (12V systems) and are not restated here.
SSR-SW-0059splitSWFunctionalQMMediumReviewThe ECA supplier shall address cybersecurity through a dedicated process that conforms to the applicable Traton cybersecurity workflow.N-SW-0146.21The customer states that additional standards or documents will be made available if applicable; these are not yet identified.
SSR-SW-0059-2splitSWFunctionalQMMediumReviewThe ECA supplier shall comply with the mandatory Traton secure update specifications CVS31, CVS32, CVS123-2 and CVS154.N-SW-0146.21
SSR-SW-0059-3splitSWFunctionalQMMediumReviewThe ECA supplier shall comply with the mandatory Traton secure diagnostics specifications CVS31, CVS32 and CVS151.N-SW-0146.21
SSR-SW-0059-4splitSWFunctionalQMMediumReviewThe ECA supplier shall comply with the mandatory Traton Unified Diagnostic Services specification CVS124.N-SW-0146.21
SSR-SW-0059-5splitSWFunctionalQMMediumReviewWhere applicable, the ECA supplier shall apply the supporting specifications CVS30, CVS33, CVS34, CVS121, CVS122, SecureBoot, Vehicle Baseline Requirements and ECU Baseline Requirements.N-SW-0146.21
SSR-SYS-0323SYSDesign constraintQMLowTestThe ECA shall set the filter time equal to the update frequency.N-SYS-064CR-SYS-0078The numeric value of the update frequency (and hence the filter time) is defined elsewhere and not stated here.
SSR-SYS-0324SYSDesign constraintQMLowReviewThe ECA supplier shall document the normal and worst-case performance values for the total time of the programming sequence comprising the programming steps prefixed P1Pro.N-SYS-064CR-SYS-0170
SSR-SYS-0325SYSDesign constraintQMLowInspectionThe ECA supplier shall deliver flash files that the vehicle manufacturer can use as delivered.N-SYS-064CR-SYS-0175
SSR-SYS-0326SYSDesign constraintQMLowInspectionThe ECA supplier shall provide the flash files corresponding to each delivered ECU when the vehicle manufacturer requests them, whether or not the ECU is delivered with a pre-programmed application and application data.N-SYS-064CR-SYS-0177
SSR-SYS-0327SYSDesign constraintQMLowTestBefore executing the TransferData service, the ECA shall determine whether the data received during the RequestDownload request must be decrypted before being written to non-volatile memory.N-SYS-064CR-SYS-0182
SSR-SYS-0328SYSDesign constraintQMLowReviewThe ECA shall update an individual module independently of the other modules.N-SYS-064CR-SYS-0186
SSR-SYS-0329SYSDesign constraintQMLowReviewWhen programmed in the vehicle manufacturer's production facility, the ECA shall complete programming of the complete set of its modules within 90 seconds using the programming sequence covering phase #1 and phase #2.N-SYS-065CR-SYS-0197quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0330SYSDesign constraintQMLowReviewWhen programmed in the workshop, the ECA shall complete programming of the complete set of its modules within 10 minutes using the programming sequence covering phase #1 and phase #2.N-SYS-065CR-SYS-0198quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SYS-0331SYSDesign constraintQMLowReviewFor each received RequestDownload request, the ECA shall determine whether a VerificationEntry match exists in the SDSC.N-SYS-065CR-SYS-0200
SSR-SYS-0332SYSDesign constraintQMLowTestThe client shall provide the pre-calculated checksum as part of the data submitted with the TransferData service request.N-SYS-065CR-SYS-0208
SSR-SYS-0333SYSDesign constraintQMLowReviewThe ECA shall set PREQARC to the value received in the ANTIREPLAYCNT protocol element of the SDT request if and only if the ECA successfully verifies or decrypts that SDT request.N-SYS-065CR-SYS-0393
SSR-SYS-0334SYSDesign constraintQMLowReviewThe client shall set PRESARC to the value received in the ANTIREPLAYCNT protocol element of the SDT response if and only if the client successfully verifies or decrypts that SDT response.N-SYS-065CR-SYS-0398
SSR-SW-0060needs clarificationSWFunctionalQMLowTestWhere higher resolution is required to troubleshoot an individual fault occurrence, the ECA shall store the corresponding diagnostic parameters internally.N-SW-0156.24CLARIFY: Which specific diagnostic parameters (for example time-stamps and occurrence counters) must the ECA store internally, and is the ECA required to include these in the ESD fault notifications to the gearbox control unit, or are they generated solely by the TCU when setting DTCs?; The set of 'higher resolution' parameters the ECA must store is not enumerated (source uses 'etc.').; The criterion for when 'higher resolution is required' is not defined.
SSR-SW-0060-2splitSWFunctionalQMLowTestThe ECA shall restrict access to the internally stored diagnostic parameters to supplier-defined tools.N-SW-0156.24
SSR-SW-0061SWFunctionalQMLowTestThe ECA shall be programmable in accordance with this specification using tools other than supplier-specific tools, even when one or more DTCs are active or one or more functions are degraded.N-SW-015CR-SW-0016
SSR-SW-0062SWFunctionalQMLowTestIf the programming preconditions are unmet, the ECA shall reject a ControlDTCSetting service request that requests DTC setting type off by responding with NRC 0x22.N-SW-015REQ_UDS_0343
SSR-SW-0063splitSWFunctionalQMHighTestWhen the ControlDTCSetting service is executed, the ECA shall limit the effect of the service to the DTC setting.N-SW-015REQ_UDS_0344
SSR-SW-0063-2splitSWFunctionalQMHighTestWhen the ControlDTCSetting service is executed, the ECA shall continue to run the diagnostic tests for safety and degradations as in normal operation.N-SW-015REQ_UDS_0344
SSR-SW-0064SWFunctionalQMLowTestThe ECA shall define the groupOfDTC parameter in accordance with ISO 14229-1.N-SW-015REQ_UDS_0262
SSR-SW-0065SWFunctionalQMLowReviewThe ECA shall format the ReportNumberOfDTCByStatusMask parameter in accordance with ISO 14229-1.N-SW-015REQ_UDS_0266
SSR-SW-0066SWFunctionalQMLowTestThe ECA shall format the DTCStatusMask parameter in accordance with ISO 14229-1.N-SW-016REQ_UDS_0267
SSR-SW-0067SWFunctionalQMLowTestThe ECA shall format the DTCSnapshotRecordNumber parameter in accordance with ISO 14229-1.N-SW-016REQ_UDS_0268
SSR-SW-0068SWFunctionalQMLowTestThe ECA shall format the DTCSeverityMaskRecord parameter in accordance with ISO 14229-1.N-SW-016REQ_UDS_0270
SSR-SW-0069SWFunctionalQMLowTestThe ECA shall format the DTCSeverityMask parameter in accordance with ISO 14229-1.N-SW-016REQ_UDS_0271
SSR-SW-0070SWFunctionalQMLowTestThe ECA shall format the DTCStatusAvailabilityMask response parameter in accordance with ISO 14229-1.N-SW-016REQ_UDS_0273
SSR-SW-0071SWFunctionalQMLowTestThe ECA shall format the DTCFormatIdentifier response parameter in accordance with ISO 14229-1.N-SW-016REQ_UDS_0274
SSR-SW-0072SWFunctionalQMLowTestThe ECA shall format the DTCCount response parameter in accordance with ISO 14229-1.N-SW-017REQ_UDS_0275
SSR-SW-0073SWFunctionalQMLowTestThe ECA shall format the DTCAndStatusRecord response parameter in accordance with ISO 14229-1.N-SW-017REQ_UDS_0276
SSR-SW-0074SWFunctionalQMLowTestThe ECA shall format the DTCRecord response parameter in accordance with ISO 14229-1.N-SW-017REQ_UDS_0277
SSR-SW-0075SWFunctionalQMLowTestThe ECA shall populate the latest captured DTC snapshot record, DTCSnapshotRecordNumber#2, with the same data type and format as DTCSnapshotRecord[]#1.N-SW-017CR-SW-0117The source is a garbled table extract; the other field definitions (dataIdentifier range, DTCSnapshotRecordNumberOfIdentifiers#2 and the #65..#70 byte layout) are not reconstructable and may carry separate field-level requirements.
SSR-SW-0076SWFunctionalQMLowTestThe ECA shall associate DTCSnapshotRecordNumber#1 with the first occurrence of the DTC and DTCSnapshotRecordNumber#2 with the latest occurrence of the DTC.N-SW-017REQ_UDS_0304
SSR-SW-0077needs clarificationSWFunctionalQMLowTestThe ECA shall report the total vehicle distance at the latest DTC activation in bytes #35..#38 as a 4-byte big-endian integer with a resolution of 5 m per bit.N-SW-017CR-SW-0120CLARIFY: The source for CR-SW-0120 is a garbled table extract. Please confirm the byte #35..#38 field definition for total vehicle distance at the latest DTC activation (4-byte big-endian, 5 m/bit resolution, range 0 to 21 307 064 315 m) and confirm whether the 0xFFFFFFFF 'not used' default applies to the ECA or only to TRATON external engine and marine ECUs.; Source table is garbled; the exact range/resolution encoding needs confirmation.; Applicability of the 0xFFFFFFFF 'not used' default value to the ECA (versus TRATON external engine and marine ECUs) is unclear.
SSR-SW-0078SWFunctionalQMLowTestThe ECA shall set the DTCExtDataRecordNumber#4 byte to the value 0x14.N-SW-018CR-SW-0121The garbled distance-encoding portion of the source (total vehicle distance, 5 m/bit) may contain a separate field requirement that is not reconstructable here.
SSR-SW-0079SWFunctionalQMLowTestThe ECA shall format the DTCSeverityAvailabilityMask response parameter in accordance with ISO 14229-1.N-SW-018REQ_UDS_0279
SSR-SW-0080SWFunctionalQMLowTestThe ECA shall format the DTCAndSeverityRecord response parameter in accordance with ISO 14229-1.N-SW-018REQ_UDS_0280
SSR-SW-0081SWFunctionalQMLowTestThe ECA shall reset each DTC status bit using only standardized reset conditions.N-SW-018REQ_UDS_0197
SSR-SW-0082SWFunctionalQMLowTestWhen DTC status bit 0 testFailed and bit 3 confirmedDTC both change from 0 to 1, the ECA shall increment the occurrence counter.N-SW-018REQ_UDS_0203
SSR-SW-0083needs clarificationSWFunctionalQMLowTestWhen DTC status bit 0 testFailed changes from 0 to 1, the ECA shall increment the occurrence counter.N-SW-018REQ_UDS_0204CLARIFY: The customer statement is truncated at a trailing comma. Which condition qualifies this increment (for example, must bit 3 confirmedDTC already be 1, mirroring REQ_UDS_0205)?; Trailing qualifying condition for the occurrence-counter increment on bit 0 testFailed is truncated in the source (REQ_UDS_0204).
SSR-SW-0084SWFunctionalQMLowTestWhen DTC status bit 3 confirmedDTC changes from 0 to 1 while bit 0 testFailed is already 1, the ECA shall increment the occurrence counter.N-SW-019REQ_UDS_0205
SSR-SW-0085SWFunctionalQMLowTestWhen DTC status bit 0 testFailed and bit 3 confirmedDTC both change from 0 to 1, the ECA shall update the latest occurrence.N-SW-019REQ_UDS_0210
SSR-SW-0086SWFunctionalQMLowTestWhen DTC status bit 0 testFailed changes from 0 to 1 while bit 3 confirmedDTC is already 1, the ECA shall update the latest occurrence.N-SW-019REQ_UDS_0210
SSR-SW-0087SWFunctionalQMLowTestWhen DTC status bit 0 testFailed and bit 3 confirmedDTC change from 0 to 1 for the first time, the ECA shall update the first occurrence.N-SW-019REQ_UDS_0212
SSR-SYS-0335SYSDesign constraintQMLowReviewThe ECA supplier shall agree each logged or stored data item with Traton.N-SYS-0666.25
SSR-SYS-0336splitSYSDesign constraintQMLowReviewThe ECA shall ventilate the air inside the electronics enclosure by means of a membrane.N-SYS-0667.45
SSR-SYS-0336-2splitSYSDesign constraintQMLowReviewThe ECA shall withstand the salt-spray environment in accordance with CVS40 §6.1.6 without clogging of the membrane.N-SYS-0667.45
SSR-SYS-0336-3splitSYSDesign constraintQMLowReviewThe ECA shall position the membrane so that it is protected against blunt force, falling dust, and dripping salt-water.N-SYS-0667.45
SSR-SYS-0336-4splitSYSDesign constraintQMLowReviewThe ECA shall prevent accumulation of water on top of the membrane and in the cavity of the membrane.N-SYS-0667.45
SSR-SYS-0337SYSDesign constraintQMLowTestThe ECA shall withstand the salt-spray environment in accordance with CVS40 §6.1.6 without clogging of the membrane.N-SYS-066CR-SYS-0109
SSR-SYS-0338SYSDesign constraintQMLowTestThe ECA shall verify the version against the Major and Minor version of the DSC logic supported by the ECA for compliance.N-SYS-066CR-SYS-0321Identity of 'the version' being verified is not specified in the source.; 'DSC logic' is a customer term whose definition is not provided.
SSR-HW-0035splitHWDesign constraintQMLowTestWhen storing data, the ECA shall prevent corruption of the stored data.N-HW-0106.26
SSR-HW-0035-2splitHWDesign constraintQMLowTestWhen data corruption occurs, the ECA shall handle the corruption while preserving the stored data and the ECA function, except for purely statistical data from the active operation cycle following an abnormal shutdown.N-HW-0106.26
SSR-HW-0036HWDesign constraintQMLowTestThe ECA shall draw its power solely from the battery positive terminal 30 connection.N-HW-0107.12
SSR-HW-0037HWDesign constraintQMLowTestWhere gaps between memory areas must be excluded from the hash calculation, the ECA shall support the definition of the hash calculation as one or several address ranges.N-HW-010CR-HW-0038
SSR-SYS-0339splitSYSDesign constraintQMLowInspectionThe ECA supplier shall deliver exactly one calibration set of the ECA to Traton.N-SYS-0676.27
SSR-SYS-0339-2splitSYSDesign constraintQMLowInspectionThe ECA shall use a calibration that is independent of the ECA installation variants.N-SYS-0676.27
SSR-SYS-0340SYSDesign constraintQMLowTestIf higher resolution is required for the supplier to troubleshoot an individual occurrence, the ECA shall store the parameters internally.N-SYS-067CR-SYS-0081The specific parameters ('these parameters') and the resolution threshold implied by 'higher resolution' are not defined in the source.
SSR-SYS-0341SYSDesign constraintQMLowTestThe ECA shall permit access to internally stored parameters only through supplier-defined tools.N-SYS-067CR-SYS-0082
SSR-SYS-0342needs clarificationSYSDesign constraintQMLowTestWhere a client implements programming support using alternative service parameter values or an alternative set of programming steps, the ECA shall support that programming sequence.N-SYS-067CR-SYS-0157CLARIFY: The source is truncated at 'than' and describes client behaviour rather than an ECA obligation. What must the ECA support with respect to alternative client programming parameter values or steps, and against which baseline sequence is the alternative compared?; Source truncated at 'than'; baseline programming sequence and the required ECA behaviour are unknown.
SSR-SYS-0343SYSDesign constraintQMLowReviewThe ECA boot loader shall comply with each requirement in CVS124 that is not explicitly stated to apply to the application only.N-SYS-067CR-SYS-0162
SSR-SYS-0344SYSDesign constraintQMLowTestWhen the module is programmed, the ECA shall override the default parameter values persisted in the boot loader software module with the parameter values in the module.N-SYS-067CR-SYS-0172Identity of 'this module' is taken from prior CVS123-2 context and is likely the boot parameter module; not explicitly stated in the source.
SSR-SYS-0345SYSDesign constraintQMLowInspectionThe ECA shall implement the default values for the EOL parameters in a dedicated application data module named the EOL parameters module.N-SYS-068CR-SYS-0173
SSR-SYS-0346SYSDesign constraintQMLowTestThe ECA shall support the addressing modes, SPRMIB values, and other parameter values specified for each service in CVS124.N-SYS-068CR-SYS-0181
SSR-SYS-0347SYSDesign constraintQMLowTestWhen the boot manager starts and executes the application at startup, the ECA shall apply the parameter values persisted in the boot parameter module.N-SYS-068CR-SYS-0191
SSR-SYS-0348SYSDesign constraintQMLowTestWhen at startup the ECA executes the boot loader and a valid boot parameter module has been successfully programmed, the ECA shall read and apply the parameter values from the boot parameter module.N-SYS-068CR-SYS-0192
SSR-SYS-0349SYSDesign constraintQMLowTestWhen at startup the ECA executes the boot loader and no boot parameter module has been successfully programmed, the ECA shall apply the parameter values persisted in the boot loader module.N-SYS-068CR-SYS-0193
SSR-SYS-0350SYSDesign constraintQMLowReviewThe ECA shall reject the transferRequestParameterRecord parameter.N-SYS-068CR-SYS-0203
SSR-SYS-0351SYSDesign constraintQMLowReviewThe ECA shall reject the transferResponseParameterRecord parameter.N-SYS-069CR-SYS-0204
SSR-SYS-0352SYSDesign constraintQMLowReviewThe ECA shall support the Anti-replay Counter (ANTIREPLAYCNT) parameter in accordance with CVS32.N-SYS-069CR-SYS-0206
SSR-SYS-0353SYSDesign constraintQMLowTestThe ECA shall reject the transferRequestParameterRecord parameter.N-SYS-069REQ_UDS_0122
SSR-SYS-0354SYSDesign constraintQMLowTestThe ECA shall reject the transferRequestParameterRecord parameter.N-SYS-069REQ_UDS_0124
SSR-FUSA-0001splitFUSAFunctionalQMHighTestWhen a power off-on cycle occurs after a functional safety event, the ECA shall reset the ECA application.N-FUSA-0016.28Detailed handling of the reset after functional safety events is TBD pending agreement with Traton.
SSR-FUSA-0001-2splitFUSAFunctionalQMHighTestThe ECA supplier shall agree the handling of functional safety events with Traton.N-FUSA-0016.28
SSR-FUSA-0002FUSAFunctionalQMHighReviewThe ECA supplier shall handle the ECA as part of a safety-critical system.N-FUSA-001CR-FUSA-0003
SSR-FUSA-0003FUSAFunctionalQMHighReviewThe ECA supplier shall develop and implement the ECA in accordance with the objectives and requirements of ISO 26262, Road vehicles - Functional Safety.N-FUSA-001CR-FUSA-0004
SSR-FUSA-0004FUSAFunctionalQMHighReviewThe ECA supplier shall apply the methods of ISO 26262 as a minimum for the safety analyses.N-FUSA-001CR-FUSA-0005'these analyses' is not explicitly scoped in the source; assumed to mean the ECA safety analyses.
SSR-FUSA-0005FUSAFunctionalQMMediumTestWhile the actuator is moving, the ECA shall execute a safe memory read and write sequence.N-FUSA-0027.4Acceptance criteria for a 'safe' memory read/write sequence are defined by the safety goals in PD3339794 (Ref 14.16) and are not restated here.
SSR-MECH-0040MECHDesign constraintQMLowTestThe ECA shall provide DC isolation between the system ground and the ECA housing.N-MECH-0107.13
SSR-SW-0088splitSWDesign constraintQMLowTestThe ECA shall implement the termination resistance using two 60 Ω resistors with 1% tolerance.N-SW-020CR-SW-0010
SSR-SW-0088-2splitSWDesign constraintQMLowTestThe ECA shall support the baud rates 250 kbit/s, 500 kbit/s, and 1000 kbit/s.N-SW-020CR-SW-0010
SSR-SW-0088-3splitSWDesign constraintQMLowTestThe ECA shall support flashing in production at 1000 kbit/s.N-SW-020CR-SW-0010
SSR-SW-0089needs clarificationSWDesign constraintQMLowTestThe ECA shall implement the TRATON Software Update Variant 2 (SUV2) sequence in accordance with CVS123-2.N-SW-020CR-SW-0011CLARIFY: The source is the CVS123-2 foreword/boilerplate and contains no specific obligation. Which requirement of the SUV2 sequence in CVS123-2 should this SSR capture?; Source is document foreword/scope text; no specific ECA obligation is stated.
SSR-SW-0090SWDesign constraintQMLowTestWhere the ECA does not support boot loader reprogramming, the ECA shall store the boot loader software in a protected area of the memory.N-SW-020CR-SW-0014
SSR-SW-0091SWDesign constraintQMLowTestWhen programming of a subset of modules causes the consistency check at the end of the programming sequence to fail, the ECA shall preserve the already-programmed modules.N-SW-020CR-SW-0015
SSR-SW-0092SWDesign constraintQMMediumReviewThe ECA supplier shall agree the solution for maintaining and reorganizing data before and after reprogramming of software modules with the vehicle manufacturer.N-SW-020CR-SW-0018
SSR-SW-0093needs clarificationSWDesign constraintQMLowTestWhere the client strategy updates specified entities before a software update, the ECA shall support that update sequence.N-SW-020CR-SW-0025CLARIFY: The source describes an optional client strategy, not a firm ECA obligation, and does not identify the 'certain entities'. Which entities must the ECA support updating prior to a software update, and is this behaviour mandatory?; 'certain entities' not specified; obligation stated as an optional client strategy ('may be a client strategy').
SSR-SW-0094SWDesign constraintQMLowTestThe ECA shall check the reprogrammed flag C3 to determine whether application initialization is required.N-SW-021CR-SW-0028
SSR-SW-0095SWDesign constraintQMLowTestAfter reprogramming, the ECA shall store the DIDs F1AB, F1AA, and F1A9.N-SW-021CR-SW-0031
SSR-SW-0096needs clarificationSWDesign constraintQMLowReviewWhere each ECA software module is pre-programmed at the supplier premises, the in-vehicle software reprogramming requirement does not apply.N-SW-021CR-SW-0034CLARIFY: This is a scope-exclusion note referring to 'This'. Which requirement does 'This' exclude, and should the exclusion be captured as an attribute of that requirement rather than as a standalone SSR?; Referent of 'This' (the excluded requirement) is not identified in the source.
SSR-SW-0097SWDesign constraintQMLowTestWhile a bootloader update procedure is ongoing and the non-volatile memory area is hosting a bootloader copy, the ECA shall preserve that memory area until a valid bootloader has been flashed in the bootloader memory area.N-SW-021CR-SW-0050
SSR-SW-0098SWDesign constraintQMLowReviewThe ECA supplier shall specify the byte value of an erased data byte as an input to the hashing process.N-SW-021CR-SW-0062
SSR-SW-0099SWDesign constraintQMLowTestThe ECA shall store the DID under the flash memory module in flash memory.N-SW-021REQ_UDS_0005The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source.
SSR-SW-0100SWDesign constraintQMLowTestThe ECA shall store the DID under the dataset module in flash memory.N-SW-022REQ_UDS_0232The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source.
SSR-SW-0101SWDesign constraintQMLowTestThe ECA shall store the DID under the dataset module in flash memory.N-SW-022REQ_UDS_0233The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source.
SSR-SW-0102SWDesign constraintQMLowTestThe ECA shall store the DID under the flash memory module in flash memory.N-SW-022REQ_UDS_0236The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source.
SSR-SW-0103SWDesign constraintQMLowTestThe ECA shall store the DID under the flash memory module in flash memory.N-SW-022REQ_UDS_0238The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source.
SSR-SW-0104SWDesign constraintQMLowTestWhile performing flashing or parametrisation, the ECA should use the communication control service to inhibit in-vehicle systems.N-SW-022CR-SW-0095The in-vehicle systems to be inhibited are not enumerated in the source (example given: engine start).
SSR-SW-0105SWDesign constraintQMLowTestWhile a bootloader update procedure is ongoing and the non-volatile memory area is hosting a bootloader copy, the ECA shall preserve that memory area until a valid bootloader has been flashed in the bootloader memory area.N-SW-022REQ_UDS_0159
SSR-HW-0038HWDesign constraintQMLowReviewThe ECA shall maintain the memory functions at Class A.N-HW-011CR-HW-0025The classification scheme defining 'Class A' is not identified in the source.
SSR-HW-0039HWDesign constraintQMLowTestWhere the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another memory area before erasing the boot loader memory.N-HW-011CR-HW-0035
SSR-HW-0040HWDesign constraintQMLowTestWhere the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another non-volatile memory area before erasing the boot loader memory.N-HW-011CR-HW-0036
SSR-HW-0041HWDesign constraintQMLowTestThe ECA shall interpret the range start field as the memory address offset from the dataLocator field.N-HW-011CR-HW-0037
SSR-HW-0042HWDesign constraintQMLowTestThe ECA shall verify that the erased-only blocks covered by the memory range are erased.N-HW-011CR-HW-0039
SSR-HW-0043HWDesign constraintQMLowTestWhere the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another memory area before erasing the boot loader memory.N-HW-011CR-HW-0044
SSR-HW-0044HWDesign constraintQMLowTestWhere the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another non-volatile memory area before erasing the boot loader memory.N-HW-012CR-HW-0047
SSR-HW-0045HWDesign constraintQMLowTestWhere the ECA implements Automatic erase, the ECA shall perform memory erasing in parallel with the data transfer.N-HW-012CR-HW-0048
SSR-SYS-0355needs clarificationSYSDesign constraintQMLowDemonstrationWhere Traton requests support for the CVS46 section 5.4 vehicle radiated-immunity test, the ECA supplier shall provide the requested support.N-SYS-07010.7.34CLARIFY: What specific support (samples, test setup, on-site attendance, analysis, etc.) must the supplier provide for the CVS46 section 5.4 vehicle radiated-immunity test, and does the 'Y' in the source confirm supplier support is mandatory?; Scope and deliverables of the required supplier support are not defined in the source.; The trailing 'Y' token is assumed to indicate that supplier support is required.
SSR-SYS-0356splitSYSDesign constraintQMLowTestThe ECA supplier shall use a function test rig to perform the function tests between the durability intervals.N-SYS-070CR-SYS-0154The cycling-frequency unit for '15 per minute' and '30 per minute' is assumed to be cycles per minute; the customer text uses the notation '15/min' and '30/min' without stating the unit.; The 'intermediate load' value for run-to-failure mode is not quantified by the customer.
SSR-SYS-0356-2splitSYSDesign constraintQMLowTestAt 6.25 million cycles, the ECA supplier shall perform a function test at -40°C and the release frequency test before placing the rigs into run-to-failure mode.N-SYS-070CR-SYS-0154
SSR-SYS-0356-3splitSYSDesign constraintQMLowTestDuring run-to-failure mode, the ECA supplier shall cycle the ECA at intermediate load and at room temperature or 80°C until failure.N-SYS-070CR-SYS-0154
SSR-SYS-0356-4splitSYSDesign constraintQMLowTestThe ECA supplier shall start the temperature durability test at a cycling frequency of 15 per minute in order to assess whether 30 per minute is feasible.N-SYS-070CR-SYS-0154
SSR-SYS-0356-5splitSYSDesign constraintQMLowTestThe ECA supplier shall run one rig at room temperature at a cycling frequency of 15 per minute as a reference unit for cycle acceleration.N-SYS-070CR-SYS-0154
SSR-SYS-0357SYSDesign constraintQMLowTestThe ECA shall support programming of each application software module, each application data module, and any subset of those modules within a single, uninterrupted programming sequence.N-SYS-070CR-SYS-0167
SSR-SYS-0358SYSDesign constraintQMLowTestThe ECA shall format the software identification string according to the pattern 'Appl: <Diag.family> <Diag.generation> Boot: <Diag.family> <Diag.generation>_BOOT'.N-SYS-070CR-SYS-0244The specific field or DID that carries this identification string is not named in the source.
SSR-SYS-0359SYSDesign constraintQMLowReviewThe ECA shall comply with the diagnostic state diagram and state definitions specified in the referenced UDS specification.N-SYS-070REQ_UDS_0051The state diagram and state list are referenced but not included in the source (the statement is truncated at 'the following state'); obtain the exact diagram and states from REQ_UDS_0051.
SSR-SYS-0360SYSDesign constraintQMLowTestThe ECA shall represent the vehicle distance as a four-byte big-endian integer with a resolution of 5 metres per bit.N-SYS-070REQ_UDS_0213
SSR-SYS-0361SYSDesign constraintQMLowTestThe ECA shall use big-endian byte order for the DID.N-SYS-071CR-SYS-0298
SSR-SW-0106SWFunctionalQMHighTestThe ECA shall implement two or more diagnostic servers.N-SW-023CR-SW-0012
SSR-SW-0107SWFunctionalQMMediumTestThe ECA shall be programmable both while integrated in the vehicle network and as a standalone unit, using only the conditions and diagnostic tester interventions defined in this specification.N-SW-023CR-SW-0017
SSR-SW-0108SWFunctionalQMMediumTestThe ECA shall persist the system name identified by DID 0xF197, the diagnostic address, and the bitrate in the application data module dedicated to boot parameters, named the boot parameter module.N-SW-023CR-SW-0019
SSR-SW-0109SWFunctionalQMMediumTestUntil a boot parameter module has been programmed, the ECA shall apply the project-specific default diagnostic address, baud rate, and DID.N-SW-023CR-SW-0020The customer labelled the values as 'typical' and 'project-specific'; confirm the exact default diagnostic address, baud rate, and DID for project P112478.
SSR-SW-0109-2splitSWFunctionalQMMediumTestThe default diagnostic address shall be 0xA7.N-SW-023CR-SW-0020
SSR-SW-0109-3splitSWFunctionalQMMediumTestThe default baud rate shall be 500 kb/s.N-SW-023CR-SW-0020
SSR-SW-0109-4splitSWFunctionalQMMediumTestThe default DID shall be 0xF197.N-SW-023CR-SW-0020
SSR-SW-0110SWFunctionalQMMediumTestWhen the ECA switches from the application to the boot loader, the ECA shall respond with the same diagnostic address that it used while running the application.N-SW-023CR-SW-0029
SSR-SW-0111SWFunctionalQMMediumTestWhen power is applied, the ECA shall be available for complete diagnostic communication within 2 seconds.N-SW-023REQ_UDS_0223quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SW-0112SWFunctionalQMMediumTestIf the diagnostic data is unavailable within the required time, the ECA shall respond with NRC 0x78 requestCorrectlyReceived-ResponsePending for up to the maximum allowed time.N-SW-024REQ_UDS_0224The 'maximum allowed time' is not quantified; confirm the applicable ISO 14229-1 timing bound (e.g., P2*server_max) for this project.
SSR-SW-0113SWFunctionalQMMediumTestThe ECA shall support, for each entry in the pattern rules, one octet for the pattern rule settings followed by the diagnostic pattern of variable length.N-SW-024CR-SW-0190
SSR-SW-0114SWFunctionalQMHighTestThe ECA shall support SDT in each execution state through both the boot loader diagnostic server and the application diagnostic server.N-SW-024CR-SW-0231
SSR-SYS-0362splitSYSDesign constraintQMLowTestThe ECA shall locate the boot loader in a memory area that is separate from the application software.N-SYS-072CR-SYS-0160
SSR-SYS-0362-2splitSYSDesign constraintQMLowTestThe ECA shall make the boot loader erasable and programmable independently of the application software.N-SYS-072CR-SYS-0160
SSR-SYS-0363SYSDesign constraintQMLowTestThe ECA shall verify each programmed software module by calculating a checksum over the programmed data and matching it against the pre-calculated checksum.N-SYS-072CR-SYS-0207
SSR-SYS-0364SYSDesign constraintQMLowTestIf the specified memory area is already completely erased or is writable when the erase service is requested, the ECA shall respond with a positive response code and leave the memory contents unchanged.N-SYS-072CR-SYS-0209
SSR-SYS-0365SYSDesign constraintQMLowReviewWhen the ECA has accepted a SDSC, the ECA shall store the receipt number provided in the EMP request in NVM.N-SYS-072CR-SYS-0216
SSR-SYS-0366SYSDesign constraintQMLowReviewThe ECA shall read from NVM, for hashing, the data range whose start and end addresses are specified by the Ranges parameter.N-SYS-072CR-SYS-0226
SSR-SYS-0367SYSDesign constraintQMLowTestWhen hashing software, the ECA shall support inclusion of the whole memory range of a memory module, including its erased-only bytes, in the hash calculation.N-SYS-072CR-SYS-0227
SSR-SYS-0368SYSDesign constraintQMLowTestThe ECA shall decrypt received data before storing it to NVM.N-SYS-073CR-SYS-0231
SSR-SYS-0369SYSDesign constraintQMLowTestIf the specified memory area is already completely erased or is writable when the erase service is requested, the ECA shall respond with a positive response code and leave the memory contents unchanged.N-SYS-073REQ_UDS_0158
SSR-SYS-0370SYSDesign constraintQMLowReviewWhen the ECA receives a DSC, the ECA shall semantically verify the DSC by parsing its entire content before storing the DSC in NVM.N-SYS-073CR-SYS-0319
SSR-SW-0115SWFunctionalQMHighTestThe ECA shall comply with ISO 14229-1:2020 and the Traton UDS specification CVS124, including the clarifications, extensions, and exceptions stated in this specification.N-SW-025CR-SW-0013
SSR-SW-0116SWFunctionalQMLowReviewThe ECA supplier shall treat the causes specified in ISO 14229-1:2020 as non-exhaustive examples.N-SW-025CR-SW-0032
SSR-SW-0117SWFunctionalQMMediumTestThe ECA shall support the diagnostic services as specified in CVS124.N-SW-025CR-SW-0033
SSR-SW-0118SWFunctionalQMLowTestThe ECA shall support the service negative response as specified in ISO 14229-1:2020.N-SW-025CR-SW-0040
SSR-SW-0119SWFunctionalQMLowTestThe ECA shall support the request message format defined in ISO 14229-1:2020.N-SW-025CR-SW-0041The specific diagnostic service that this request refers to is not identified in the source.
SSR-SW-0120SWFunctionalQMLowTestThe ECA shall support the positive response format defined in ISO 14229-1:2020.N-SW-025CR-SW-0042The specific diagnostic service that this positive response refers to is not identified in the source.
SSR-SW-0121SWFunctionalQMLowTestThe ECA shall support the blockSequenceCounter parameter formatted according to ISO 14229-1:2020.N-SW-026CR-SW-0044
SSR-SW-0122SWFunctionalQMLowTestThe ECA shall support the transferRequestParameterRecord parameter formatted according to ISO 14229-1:2020.N-SW-026CR-SW-0045
SSR-SW-0123SWFunctionalQMLowTestThe ECA shall support the request message format defined in ISO 14229-1:2020.N-SW-026CR-SW-0047The specific diagnostic service that this request refers to is not identified in the source.
SSR-SW-0124SWFunctionalQMLowTestThe ECA shall support the positive response format defined in ISO 14229-1:2020.N-SW-026CR-SW-0048The specific diagnostic service that this positive response refers to is not identified in the source.
SSR-SW-0125SWFunctionalQMLowTestThe ECA shall support the Administrative Parameter formatted according to ISO 14229-1:2020.N-SW-026CR-SW-0049
SSR-SW-0126SWFunctionalQMMediumTestIf the ECA sets routineResult to 0x00 CorrectResult, the ECA shall reject the specified diagnostic services and routines with NRC 0x24 until a new SDSC is provided.N-SW-026CR-SW-0056The set of diagnostic services and routines to be rejected ('the following ...') is referenced but not enumerated in the source.
SSR-SW-0127SWFunctionalQMMediumTestWhen the ECA has accepted a SDSC, the ECA shall accept the diagnostic routine 0xFF00 Erase Memory.N-SW-027CR-SW-0060The source lists 'the following diagnostic services and routines' but shows only routine 0xFF00 Erase Memory; confirm whether additional entries apply.
SSR-SW-0128SWFunctionalQMLowTestThe ECA shall support the routineControlOptionRecord request parameter as specified in ISO 14229-1.N-SW-027REQ_UDS_0288
SSR-SW-0129SWFunctionalQMLowTestThe ECA shall exclude the RoutineControlOptionRecord request parameter from the supported request parameters.N-SW-027REQ_UDS_0151
SSR-SW-0130SWFunctionalQMLowTestThe ECA shall exclude the routineControlType request parameter value 0x03 requestRoutineResults from the supported values.N-SW-027REQ_UDS_0152
SSR-SW-0131SWFunctionalQMLowTestThe ECA shall support the RoutineControl service without the requestRoutineResults routineControlType value 0x03.N-SW-027REQ_UDS_0164
SSR-SW-0132SWFunctionalQMLowTestThe ECA shall support the RoutineControl service without the routineControlOptionRecord parameter.N-SW-027REQ_UDS_0174
SSR-SW-0133needs clarificationSWFunctionalQMLowTestThe ECA shall format each positive response to a RoutineControl service request for Software Installation according to TBD.N-SW-028REQ_UDS_0175CLARIFY: What is the required format and content of the positive response to a RoutineControl (Software Installation) service request? The source statement ends at 'shall be formatted'.; The required format and content of the positive RoutineControl (Software Installation) response is not stated; the customer statement is truncated after 'shall be formatted'.
SSR-SW-0134SWFunctionalQMLowReviewWhere a requirement in the customer specification deviates from ISO 14229-1, the ECA supplier shall apply the requirement of the customer specification.N-SW-028CR-SW-0230
SSR-SW-0135SWFunctionalQMMediumTestWhere the encapsulated UDS response is negative, the ECA shall return it within a positive SDT response.N-SW-028CR-SW-0242
SSR-HW-0046HWDesign constraintQMLowTestThe ECA shall allow the generic bootloader to be reused for future purposes or applications while retaining the existing platform part number.N-HW-013CR-HW-0029
SSR-CYBER-0078CYBERDesign constraintQMLowReviewWhere the ECA supplier delivers encrypted flash files to the vehicle manufacturer, the ECA supplier shall provide the information required to verify the flash files during the flash file update procedure.N-CYBER-020CR-CYBER-0038
SSR-CYBER-0079CYBERDesign constraintQMLowTestIf the software to be updated is encrypted, the ECA shall have the decryption keys available before step P1Pro9.N-CYBER-020CR-CYBER-0041
SSR-CYBER-0080CYBERDesign constraintQMLowTestThe ECA shall determine whether any part of the received data is encrypted by checking the address ranges for a match in an EncryptionEntry defined in the SDSC.N-CYBER-020CR-CYBER-0045
SSR-CYBER-0081CYBERDesign constraintQMLowTestIf the software is encrypted, the ECA shall decrypt the software before decompression and software hash comparison verification are performed.N-CYBER-020CR-CYBER-0046
SSR-CYBER-0082CYBERDesign constraintQMLowTestThe ECA shall support the Signature and Encryption Calculation parameter SIGENCRYPT according to CVS32.N-CYBER-020CR-CYBER-0047
SSR-CYBER-0083CYBERDesign constraintQMLowTestWhere a match for the received data is found in an EncryptionEntry of the DSC and a cipher is not yet initialized, the ECA shall initialize a cipher.N-CYBER-020CR-CYBER-0054
SSR-CYBER-0084CYBERDesign constraintQMLowTestWhile received data continues to match the current EncryptionEntry, the ECA shall keep the initialized cipher scheme active.N-CYBER-021CR-CYBER-0055
SSR-CYBER-0085CYBERDesign constraintQMLowTestThe ECA shall reinitialize the cipher for each new EncryptionEntry.N-CYBER-021CR-CYBER-0056
SSR-CYBER-0086CYBERDesign constraintQMLowTestWhen the ECA receives data that matches an address range in an EncryptionEntry, the ECA shall decrypt the data received in the TransferData request.N-CYBER-021CR-CYBER-0057
SSR-CYBER-0087CYBERDesign constraintQMLowTestWhen the ECA receives data within a range given as address and size in the RequestDownload request, the ECA shall decrypt the data before storing it.N-CYBER-021CR-CYBER-0058quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-CYBER-0088CYBERDesign constraintQMLowTestThe ECA shall allow the requests contained in the role 0 rule regardless of the value of the Confidentiality field setting.N-CYBER-021CR-CYBER-0082
SSR-CYBER-0089CYBERDesign constraintQMLowTestThe ECA shall support a DSC containing encryptionEntries.N-CYBER-021CR-CYBER-0085
SSR-CYBER-0090CYBERDesign constraintQMLowTestThe ECA shall accept a zero-length ASN.1 SEQUENCE tag for an empty encryptionEntries element in a DSC transmitted by the client.N-CYBER-022CR-CYBER-0086
SSR-CYBER-0091CYBERDesign constraintQMLowTestThe ECA shall support an empty DSC that contains only the version and id Metadata and the empty sequences for verificationEntries, encryptionEntries and itemEntries.N-CYBER-022CR-CYBER-0087
SSR-CYBER-0092splitCYBERDesign constraintQMLowTestThe ECA shall provide support for verification and encryption.N-CYBER-022CR-CYBER-0088
SSR-CYBER-0092-2splitCYBERDesign constraintQMLowTestWhere a DSC contains only the version and id, the ECA shall skip verification and encryption for that DSC.N-CYBER-022CR-CYBER-0088
SSR-CYBER-0093CYBERDesign constraintQMLowTestThe ECA shall support the ASN.1 content defined as: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }.N-CYBER-022CR-CYBER-0090
SSR-CYBER-0094CYBERDesign constraintQMLowTestThe ECA shall support the EncryptionEntry algorithm.N-CYBER-022CR-CYBER-0092
SSR-CYBER-0095CYBERDesign constraintQMHighTestThe ECA shall verify the length of the key and the iv according to the algorithm stipulated in the EncryptionEntry.N-CYBER-022CR-CYBER-0093
SSR-CYBER-0096CYBERDesign constraintQMLowTestThe ECA shall support a DSC in which the verificationEntries, encryptionEntries and itemEntries sequence tags are present with zero length.N-CYBER-023CR-CYBER-0095
SSR-CYBER-0097CYBERDesign constraintQMLowTestThe ECA shall support the CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305.N-CYBER-023CR-CYBER-0127
SSR-CYBER-0098CYBERDesign constraintQMLowTestWhen the ECA receives an SDT message, the ECA shall verify or decrypt the message using the CipherScheme indicated by the SIGENCRYPT protocol element.N-CYBER-023CR-CYBER-0128
SSR-CYBER-0099CYBERDesign constraintQMLowTestWhere the SDT response is positive, the ECA shall respond to the client request using the same CipherScheme that was used in the request.N-CYBER-023CR-CYBER-0129
SSR-CYBER-0100CYBERDesign constraintQMLowTestWhere the client alters the CipherScheme between SDT requests within the same SDT sequence, the ECA shall accept the altered CipherScheme.N-CYBER-023CR-CYBER-0130quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-CYBER-0101CYBERDesign constraintQMHighTestThe ECA shall maintain state variables that indicate which CipherScheme and which resulting key were used in the previous SDT transaction.N-CYBER-023CR-CYBER-0131
SSR-CYBER-0102splitCYBERDesign constraintQMLowTestWhere an SDT request is being constructed and SIGENCRYPT differs from PSIGENCRYPT, the client shall re-run the KDF.N-CYBER-024CR-CYBER-0132
SSR-CYBER-0102-2splitCYBERDesign constraintQMLowTestWhere the authentication or encryption succeeds, the client shall update the state variables PSIGENCRYPT and PKEY with the new values.N-CYBER-024CR-CYBER-0132
SSR-CYBER-0103splitCYBERDesign constraintQMLowTestWhen the ECA receives an SDT request whose SIGENCRYPT differs from PSIGENCRYPT, the ECA shall re-run the KDF.N-CYBER-024CR-CYBER-0133
SSR-CYBER-0103-2splitCYBERDesign constraintQMLowTestWhere the verification or decryption succeeds, the ECA shall update the state variables PSIGENCRYPT and PKEY with the new values.N-CYBER-024CR-CYBER-0133
SSR-CYBER-0104needs clarificationCYBERDesign constraintQMMediumTestThe client shall encrypt and authenticate the SDT request with the A argument set to TBD.N-CYBER-024CR-CYBER-0140CLARIFY: What value must the A (associated data) argument be set to when the client encrypts and authenticates the SDT request? The source statement is truncated after 'with the A argument set to the'.; The value to which the A argument must be set is missing; the customer statement is truncated after 'set to the'.
SSR-CYBER-0105CYBERDesign constraintQMLowTestThe client shall decrypt and verify the SDT response with the A argument set to the concatenated octet string comprising the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the value stored in the state variable PREQTAG.N-CYBER-024CR-CYBER-0141
SSR-CYBER-0106CYBERDesign constraintQMLowTestThe ECA shall decrypt and verify the SDT request with the A argument set to the concatenated octet string comprising the SDT, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements.N-CYBER-024CR-CYBER-0142
SSR-CYBER-0107CYBERDesign constraintQMMediumTestThe ECA shall encrypt and authenticate the SDT response with the A argument set to the concatenated octet string comprising the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the octet string carried by the SIGMACBYTE protocol element of the corresponding request.N-CYBER-024CR-CYBER-0143
SSR-CYBER-0108CYBERDesign constraintQMMediumTestWhere the ECA successfully authenticates or encrypts the SDT response, the ECA shall update its state by incrementing PRESARC by one.N-CYBER-025CR-CYBER-0149
SSR-CYBER-0109CYBERDesign constraintQMMediumTestWhere the client successfully authenticates or encrypts the SDT request, the client shall update its state by incrementing PREQARC by one.N-CYBER-025CR-CYBER-0150
SSR-CYBER-0110CYBERDesign constraintQMLowTestWhen the client receives an SDT response with an unsupported SIGENCRYPT value, the client shall discard the response.N-CYBER-025CR-CYBER-0151
SSR-CYBER-0111CYBERDesign constraintQMLowTestWhen the client receives an SDT response in which APAR conflicts with SIGENCRYPT, the client shall discard the response.N-CYBER-025CR-CYBER-0152
SSR-CYBER-0112CYBERDesign constraintQMLowTestWhen the client receives an SDT response in which SIGLEN conflicts with SIGENCRYPT, the client shall discard the response.N-CYBER-025CR-CYBER-0153
SSR-SW-0136SWFunctionalQMLowTestThe ECA shall perform an authentication sequence with the client by means of the Authentication service 0x29.N-SW-029CR-SW-0023
SSR-SW-0137SWFunctionalQMLowTestWhen the ECA receives an Authentication service 0x29 request with the deAuthenticate sub-function 0x00 from the client, the ECA shall disable authorized access to the diagnostic programming services.N-SW-029CR-SW-0024
SSR-SW-0138SWFunctionalQMLowTestThe ECA shall format the negative response to the Authentication service 0x29 as specified in ISO 14229-1 section 5.5.18.N-SW-029REQ_UDS_0129
SSR-SW-0139SWFunctionalQMLowTestThe ECA shall use the Authentication service 0x29 for mutual authentication of the client and the ECA.N-SW-029REQ_UDS_0130
SSR-SW-0140SWFunctionalQMLowTestThe ECA shall implement the Authentication service 0x29 according to CVS31.N-SW-029REQ_UDS_0133
SSR-SW-0141SWFunctionalQMLowTestIf a normal condition defined in ISO 14229-1 for performing the service fails, the ECA shall return a negative response code.N-SW-029CR-SW-0165
SSR-SW-0142SWFunctionalQMLowTestThe ECA shall require that requests matching allow rules are authenticated using SecuredDataTransmission service 0x84.N-SW-030CR-SW-0187
SSR-SW-0143needs clarificationSWFunctionalQMLowTestThe ECA shall make each service, DID and RID assigned to role 0 available to each client regardless of the client diagnostic role, authorization status and authentication status.N-SW-030CR-SW-0193CLARIFY: CR-SW-0193 is phrased as an explanatory note ('role 0 is particularly useful for defining ...'), not a normative shall. Please confirm the intended ECA obligation: shall every service, DID and RID configured under role 0 be available to every client irrespective of the client's diagnostic role, authorization status and authentication status?
SSR-SW-0144SWFunctionalQMLowTestThe ECA shall allow each request contained in the role 0 rule irrespective of whether the request is data-authenticated using SecuredDataTransmission service 0x84.N-SW-030CR-SW-0194
SSR-SW-0145SWFunctionalQMLowTestThe ECA shall generate the challengeClient using a CRNG.N-SW-030CR-SW-0205
SSR-SW-0146SWFunctionalQMLowTestIf the ECA determines that the client lacks an existing authentication pending state, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x24, indicating requestSequenceError.N-SW-030CR-SW-0211
SSR-SW-0147SWFunctionalQMLowTestIf the ECA determines that the client has an existing authentication pending state and the Authentication completion timer has expired, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x24, indicating requestSequenceError.N-SW-030CR-SW-0212
SSR-SW-0148SWFunctionalQMLowTestIf the ECA is unable to determine whether the client has an existing authentication pending state, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable.N-SW-031CR-SW-0213
SSR-SW-0149SWFunctionalQMLowTestIf the ECA is deleting the authentication pending state as a consequence of a client proofOfOwnership signature verification failure and the ECA determines that the authentication pending state was deleted, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x10, indicating generalReject.N-SW-031CR-SW-0214
SSR-SW-0150SWFunctionalQMLowTestIf the ECA is deleting the authentication pending state as a consequence of a client proofOfOwnership signature verification failure and the ECA is unable to determine that the authentication pending state was deleted, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable.N-SW-031CR-SW-0215
SSR-SW-0151SWFunctionalQMLowTestIf the ECA is deleting the authentication pending state as a consequence of a failure to store the authentication state, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable.N-SW-031CR-SW-0216
SSR-SW-0152SWFunctionalQMLowTestIf the ECA determines that the client is currently unauthenticated, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x24, indicating requestSequenceError.N-SW-031CR-SW-0217
SSR-SW-0153SWFunctionalQMLowTestIf the ECA is unable to determine that the client is currently authenticated, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable.N-SW-031CR-SW-0218
SSR-SW-0154SWFunctionalQMLowTestIf the ECA is unable to delete the client's authentication state or is unable to verify its presence, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x94.N-SW-032CR-SW-0219
SSR-SW-0155SWFunctionalQMLowTestIf the ECA is unable to delete the client's authentication state or is unable to retrieve it because of internal errors, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x94.N-SW-032CR-SW-0220
SSR-SW-0156SWFunctionalQMMediumTestWhen a client request triggers an ECA reset, the ECA shall send the corresponding response before invalidating the authentication pending state.N-SW-032CR-SW-0226
SSR-SW-0157SWFunctionalQMMediumTestWhen a client request triggers an ECA reset, the ECA shall send the corresponding response before invalidating the authentication state.N-SW-032CR-SW-0227
SSR-SW-0158needs clarificationSWFunctionalQMLowTestThe ECA shall always allow the Authentication service 0x29.N-SW-032CR-SW-0228CLARIFY: CR-SW-0228 is truncated at 'regardless of'. Please complete the clause: under exactly which conditions must the ECA always allow the Authentication service 0x29 (e.g. regardless of the active diagnostic session, security level, or RBACC access-control state)?; Truncated qualifier: what condition(s) the 'regardless of ...' clause was intended to cover (e.g. active diagnostic session, security level, RBACC rules).
SSR-SW-0159SWFunctionalQMLowTestThe ECA shall use the diagnostic tester address of the SDT client to identify the authentication state and the associated SecuredDataTransmissionKey.N-SW-032CR-SW-0232
SSR-SW-0160SWFunctionalQMLowTestWhen either PREQARC or PRESARC reaches the maximum value 65535, the ECA shall require the client to re-authenticate before the ECA processes further Secured Data Transmission messages.N-SW-033CR-SW-0235quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SW-0161SWFunctionalQMLowTestIn addition to the Negative Response Codes 0x3A, 0x13 and 0x21 specified by ISO 14229-1:2020, the ECA shall support Negative Response Code 0x34, indicating authenticationRequired.N-SW-033CR-SW-0243
SSR-SW-0162SWFunctionalQMLowTestWhen the ECA receives an SDT request from an unauthenticated client, the ECA shall respond with an SDT negative response using Negative Response Code 0x34.N-SW-033CR-SW-0244
SSR-CYBER-0113needs clarificationCYBERDesign constraintQMHighTestWhere a client reads stored entities to verify their presence, the ECA shall provide read access to the certificate validity time and the RBAC configuration file.N-CYBER-026CR-CYBER-0039CLARIFY: CR-CYBER-0039 is written as an illustrative example ('As example, the client may read ...'). Please confirm the normative ECA obligation: shall the ECA provide read access to the certificate validity time and the RBAC configuration file so a client can verify the stored entities, and via which service/DIDs?
SSR-CYBER-0114CYBERDesign constraintQMHighestTestIf a conflicting or overlapping rule is found between the client certificate D-RBACC extension and a rule in the RBAC configuration in the RBACC, the ECA shall enforce the rule in the client certificate D-RBACC extension.N-CYBER-026CR-CYBER-0075
SSR-CYBER-0115CYBERDesign constraintQMMediumTestWhile the DynamicallyDefineDataIdentifier service is being used, the ECA shall evaluate each DID included in the request against the rules applicable to the client in the client certificate and in the RBACC.N-CYBER-026CR-CYBER-0083
SSR-CYBER-0116needs clarificationCYBERDesign constraintQMLowTestThe ECA shall accept a verifyCertificateBidirectional subfunction request formatted according to TBD.N-CYBER-026CR-CYBER-0096CLARIFY: CR-CYBER-0096 is truncated at 'shall be formatted according to'. Which specification, table or clause defines the required format of the verifyCertificateBidirectional subfunction request?; TBD: specification/table that defines the required format of the verifyCertificateBidirectional subfunction request (source truncated after 'according to').
SSR-CYBER-0117CYBERDesign constraintQMLowTestIf, upon reception of a verifyCertificateBidirectional request, the Authentication delay timer has expired, the ECA shall continue to process the verifyCertificateBidirectional request.N-CYBER-026CR-CYBER-0097
SSR-CYBER-0118CYBERDesign constraintQMMediumTestIf the ECA verifies the client certificate as valid, the ECA shall create the requested client authentication pending state.N-CYBER-026CR-CYBER-0099
SSR-CYBER-0119CYBERDesign constraintQMLowTestWhen the ECA receives a verifyCertificateBidirectional request, the ECA shall verify the value of lengthOfCertificateClient.N-CYBER-027CR-CYBER-0100
SSR-CYBER-0120CYBERDesign constraintQMLowTestThe ECA shall use certificates whose format and structure conform to CVS30.N-CYBER-027CR-CYBER-0109
SSR-CYBER-0121CYBERDesign constraintQMHighestTestIf a client certificate received through the verifyCertificateBidirectional subfunction matches the ECA's own certificate, the ECA shall reject that client certificate.N-CYBER-027CR-CYBER-0110
SSR-CYBER-0122CYBERDesign constraintQMHighestTestThe ECA shall reject each authentication attempt that uses the ECA's own key or certificate.N-CYBER-027CR-CYBER-0111
SSR-CYBER-0123CYBERDesign constraintQMHighTestThe ECA shall verify the client certificate sent using the verifyCertificateBidirectional subfunction in accordance with Figure 3 of the referenced specification.N-CYBER-027CR-CYBER-0112The specification document containing Figure 3 is not identified in the item; the exact reference is TBD.
SSR-CYBER-0124CYBERDesign constraintQMHighTestThe ECA shall verify the signature of the client certificate using the AUTH-CA EMP entity public key.N-CYBER-027CR-CYBER-0113
SSR-CYBER-0125CYBERDesign constraintQMLowTestIf the D-RBACC extension is detected, the ECA shall override the RBACC permissions with the D-RBACC permissions.N-CYBER-028CR-CYBER-0115
SSR-CYBER-0126needs clarificationCYBERDesign constraintQMLowTestThe ECA shall validate the D-RBACC by parsing its entire content.N-CYBER-028CR-CYBER-0116CLARIFY: CR-CYBER-0116 is truncated at 'If content is invalid,'. What action shall the ECA take when the D-RBACC content is found to be invalid (e.g. reject the D-RBACC, fall back to the RBACC, respond with which NRC)?; TBD: action the ECA shall take when the D-RBACC content is invalid (source truncated after 'If content is invalid,').
SSR-CYBER-0127CYBERDesign constraintQMLowTestThe ECA shall verify that the D-RBACC version provided by the client is compatible with the ECA's supported D-RBACC version.N-CYBER-028CR-CYBER-0117
SSR-CYBER-0128CYBERDesign constraintQMHighTestThe ECA shall validate the certificate so that notBefore ≤ Certificate-time ≤ notAfter.N-CYBER-028CR-CYBER-0122
SSR-CYBER-0129needs clarificationCYBERDesign constraintQMLowTestThe ECA shall enforce a minimum time of TBD between consecutive verifyCertificateBidirectional requests, defined by the delay timer.N-CYBER-028CR-CYBER-0124CLARIFY: CR-CYBER-0124 is a truncated definition ('The delay timer represents the required minimum time between verifyCertificateBidirectional'). Please confirm the obligation and provide the value: what is the minimum time the ECA shall enforce between consecutive verifyCertificateBidirectional requests?; TBD: minimum time value the delay timer enforces between consecutive verifyCertificateBidirectional requests (source truncated after 'between verifyCertificateBidirectional').
SSR-CYBER-0130CYBERDesign constraintQMLowTestWhile the delay timer is inactive, the ECA shall start the delay timer as part of processing a verifyCertificateBidirectional request.N-CYBER-028CR-CYBER-0125
SSR-CYBER-0131needs clarificationCYBERDesign constraintQMMediumTestWhere a client updates the RBAC configuration file, the ECA shall update the stored entities according to the client's set request.N-CYBER-029CR-CYBER-0040CLARIFY: CR-CYBER-0040 is written as an illustrative example ('As example, the client may ...'). Please confirm the normative ECA obligation: shall the ECA accept a client set request that updates the RBAC configuration file entities, and through which service/mechanism?
SSR-CYBER-0132needs clarificationCYBERDesign constraintQMMediumTestWhere a client sets an updated RBAC configuration file entity via EMP, the ECA shall store the updated entity.N-CYBER-029CR-CYBER-0043CLARIFY: CR-CYBER-0043 is written as an illustrative example ('As example, the client may ...'). Please confirm the normative ECA obligation: shall the ECA accept and store an updated RBAC configuration file entity that a client sets via EMP?
SSR-CYBER-0133CYBERDesign constraintQMMediumTestThe ECA shall implement Role-Based Access Control in accordance with CVS151.N-CYBER-029REQ_UDS_0047
SSR-CYBER-0134CYBERDesign constraintQMMediumTestThe ECA shall define the CVS31 and CVS32 requirement preconditions for each service within the RBAC configuration file.N-CYBER-029REQ_UDS_0048
SSR-CYBER-0135CYBERDesign constraintQMLowTestEach RBACC shall contain exactly one role configuration for each supported role.N-CYBER-029CR-CYBER-0066
SSR-CYBER-0136CYBERDesign constraintQMLowTestIf no rule in the RBACC matches the request, the ECA shall deny the request.N-CYBER-029CR-CYBER-0068
SSR-CYBER-0137needs clarificationCYBERDesign constraintQMLowTestEach RBACC ALLOW rule shall include a setting that dictates whether a request matching the rule must be authenticated.N-CYBER-030CR-CYBER-0069CLARIFY: CR-CYBER-0069 is garbled/truncated ('...must be 14229-1:2020)'). Please confirm: does each RBACC ALLOW rule carry a setting that dictates whether a request matching the rule must be data-authenticated (e.g. via SecuredDataTransmission per ISO 14229-1:2020)?; TBD: exact meaning of the truncated setting; source reads '...must be 14229-1:2020)' and appears to reference data authentication per ISO 14229-1:2020.
SSR-CYBER-0138CYBERDesign constraintQMLowTestThe ECA shall define the RBACC in accordance with the following ASN.1 definition: RBACC ::= SEQUENCE { version OCTET STRING (SIZE(2)), rbacc-id OCTET STRING (SIZE(16)), role-configurations SEQUENCE (SIZE(0..MAX)) OF Role-configuration } Role-configuration ::= SEQUENCE { role INTEGER(0..MAX), pattern-rules-deny SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(2..MAX)), pattern-rules-allow SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(2..MAX)), did-rules-deny SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)), did-rules-allow SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)), rid-rules-deny SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)), rid-rules-allow SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)) }.N-CYBER-030CR-CYBER-0071
SSR-CYBER-0139CYBERDesign constraintQMLowTestBefore the RBACC is stored, the ECA shall verify that the ECA supports the structure indicated by the version number.N-CYBER-030CR-CYBER-0072
SSR-CYBER-0140CYBERDesign constraintQMLowTestThe ECA shall support 16 octets in the rbacc-id field.N-CYBER-030CR-CYBER-0073
SSR-CYBER-0141CYBERDesign constraintQMLowTestThe ECA shall interpret the extnValue as one instance of a RBACC.N-CYBER-030CR-CYBER-0076
SSR-CYBER-0142CYBERDesign constraintQMMediumTestThe ECA shall implement the RBAC internal logic as specified in Figure 4.N-CYBER-030CR-CYBER-0077
SSR-CYBER-0143CYBERDesign constraintQMMediumTestThe ECA shall implement the RBAC pattern rule evaluation logic as specified in Figure 5.N-CYBER-031CR-CYBER-0078
SSR-CYBER-0144CYBERDesign constraintQMMediumTestThe ECA shall implement the RBAC DID rule evaluation as specified in Figure 6.N-CYBER-031CR-CYBER-0079
SSR-CYBER-0145CYBERDesign constraintQMMediumTestThe ECA shall implement the RBAC RID rule evaluation as specified in Figure 7.N-CYBER-031CR-CYBER-0080
SSR-SW-0163SWFunctionalQMLowTestWhere a LinkControl service request is received while an application programmed by the supplier is active, the ECA may respond with negative response code 0x7F, serviceNotSupportedInActiveSession.N-SW-034CR-SW-0026
SSR-SW-0164SWFunctionalQMLowTestIf the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall start erasing the memory area specified by the RequestDownload request.N-SW-034CR-SW-0035
SSR-SW-0165splitSWFunctionalQMLowTestIf the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall reset the identification DIDs to their default values.N-SW-034CR-SW-0036The source enumerates identification DIDs only for the boot software download case (0xF180, 0xF191, 0xF187); the complete set of identification DIDs reset for other download cases is not provided in the source.
SSR-SW-0165-2splitSWFunctionalQMLowTestWhere boot software download is requested, the ECA shall reset the identification DIDs 0xF180, 0xF191 and 0xF187 to their default values.N-SW-034CR-SW-0036
SSR-SW-0166SWFunctionalQMLowTestWhen the RequestDownload service has started, the ECA shall permit only the TesterPresent, ECUReset, TransferData and DiagnosticSessionControl services until the RequestTransferExit service has been called or any of these services returns an error.N-SW-034CR-SW-0037
SSR-SW-0167SWFunctionalQMMediumTestThe ECA shall support the default diagnostic session.N-SW-034REQ_UDS_0040
SSR-SW-0168SWFunctionalQMMediumTestThe ECA shall support the non-default diagnostic session named extendedDiagnosticSession.N-SW-034REQ_UDS_0042
SSR-SW-0169SWFunctionalQMHighReviewThe ECA supplier shall agree each diagnostic session that is not defined in this document with the vehicle manufacturer.N-SW-035REQ_UDS_0043
SSR-SW-0170SWFunctionalQMLowReviewThe ECA supplier shall agree the mapping of RoutineControl service routines to sessions with the vehicle manufacturer.N-SW-035REQ_UDS_0046
SSR-SW-0171SWFunctionalQMLowTestThe ECA shall process a DiagnosticSessionControl service request with the diagnosticSessionType parameter set to ProgrammingSession only when normal communication has been switched off by a previous CommunicationControl service call.N-SW-035REQ_UDS_0057
SSR-SW-0172SWFunctionalQMLowTestThe ECA shall set the response parameter diagnosticSessionType in accordance with ISO 14229-1.N-SW-035REQ_UDS_0241
SSR-SW-0173SWFunctionalQMLowTestThe ECA shall set the response parameter sessionParameterRecord in accordance with ISO 14229-1.N-SW-035REQ_UDS_0242
SSR-SW-0174SWFunctionalQMLowTestIf the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall start erasing the memory area specified by the RequestDownload request.N-SW-035REQ_UDS_0108
SSR-SW-0175splitSWFunctionalQMLowTestIf the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall reset the identification DIDs to their default values.N-SW-036REQ_UDS_0109The source enumerates identification DIDs only for the boot software download case (0xF180, 0xF191, 0xF187); the complete set of identification DIDs reset for other download cases is not provided in the source.
SSR-SW-0175-2splitSWFunctionalQMLowTestWhere boot software download is requested, the ECA shall reset the identification DIDs 0xF180, 0xF191 and 0xF187 to their default values.N-SW-036REQ_UDS_0109
SSR-SW-0176SWFunctionalQMLowTestWhen the RequestDownload service has started, the ECA shall permit only the TesterPresent, ECUReset, TransferData and DiagnosticSessionControl services until the RequestTransferExit service has been called or any of these services returns an error.N-SW-036REQ_UDS_0110
SSR-SW-0177SWFunctionalQMLowTestThe ECA shall support the routine in the Extended session of both the Application and the Boot software.N-SW-036REQ_UDS_0150
SSR-SW-0178SWFunctionalQMLowTestThe ECA shall support the routine in the Programming session.N-SW-036REQ_UDS_0162
SSR-SW-0179SWFunctionalQMLowTestThe ECA shall support the routine in the Programming session.N-SW-036REQ_UDS_0173
SSR-SW-0180SWFunctionalQMLowTestThe ECA shall support the routine in the Programming session.N-SW-036REQ_UDS_0189
SSR-SW-0181SWFunctionalQMLowTestThe ECA shall support the routine in each session of both the Application and the Boot software.N-SW-037REQ_UDS_0195
SSR-SW-0182needs clarificationSWFunctionalQMMediumReviewThe ECA supplier shall interpret the keywords 'shall', 'should' and 'must' used in this document in accordance with RFC 2119.N-SW-0371.3CLARIFY: This source is a document-conventions paragraph (mnemonics, pseudo-code notation, requirement tagging, and keyword interpretation). Does it yield any verifiable ECA or supplier requirement, or should it be retained as informational only? If a requirement is intended, which specific obligation applies?
SSR-SW-0183SWFunctionalQMMediumTestThe ECA shall have the information required to verify the software integrity available before the RoutineControl eraseMemory step P1Pro6.N-SW-038CR-SW-0027
SSR-SW-0184needs clarificationSWFunctionalQMLowTestThe ECA shall support physical memory range erase in accordance with ISO 14229-1 Table H1.N-SW-038CR-SW-0053CLARIFY: The source is a fragment of a table (module/index and memory-erase mapping with a legend 'M = Mandatory', 'C = Mandatory if required to meet the performance requirements') and cannot be parsed into a single requirement. Please provide the intended obligation and the complete table.; The module-to-index / memory-erase mapping is provided only as a table fragment (e.g. Module 2 Application SW, range 0x02-0xFF) and is not fully specified in the source.
SSR-SW-0185splitSWFunctionalQMHighTestWhen the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall simulate turning the ignition key off and back on.N-SW-038REQ_UDS_0070
SSR-SW-0185-2splitSWFunctionalQMHighTestWhen the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall preserve the values of the non-volatile memory locations.N-SW-038REQ_UDS_0070
SSR-SW-0185-3splitSWFunctionalQMHighTestWhen the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall initialize the volatile memory.N-SW-038REQ_UDS_0070
SSR-SW-0186SWFunctionalQMLowTestWhen the ECA processes an ECUReset service request with the requestParameter set to the keyOffOnReset value 0x02, the ECA shall store the buffered volatile-memory data into non-volatile memory before sending a positive response.N-SW-038REQ_UDS_0072
SSR-SW-0187SWFunctionalQMLowTestThe ECA shall store each changed data value into non-volatile memory in a valid state no later than the completion of an ECUReset service 0x11 subFunction 0x02 requested by the client.N-SW-038REQ_UDS_0091
SSR-SW-0188SWFunctionalQMHighTestThe ECA shall support the forced transfer of buffered data into non-volatile memory both by an ECUReset service with subFunction 0x02 and by an ignition-key power cycle.N-SW-038REQ_UDS_0092
SSR-SW-0189SWFunctionalQMLowTestThe ECA shall define the MemoryAddress parameter in accordance with ISO 14229-1.N-SW-039REQ_UDS_0291
SSR-SW-0190SWFunctionalQMLowTestThe ECA shall define the MemorySize parameter in accordance with ISO 14229-1.N-SW-039REQ_UDS_0292
SSR-SW-0191SWFunctionalQMLowTestThe ECA shall define the MemoryAddress parameter in accordance with ISO 14229-1.N-SW-039REQ_UDS_0296
SSR-SW-0192SWFunctionalQMLowTestThe ECA shall define the MemorySize parameter in accordance with ISO 14229-1.N-SW-039REQ_UDS_0297
SSR-SW-0193needs clarificationSWFunctionalQMLowTestThe ECA shall support physical memory range erase in accordance with ISO 14229-1 Table H1.N-SW-039CR-SW-0157CLARIFY: The source is a fragment of a table (module/index and memory-erase mapping with a legend 'M = Mandatory', 'C = Mandatory if required to meet the performance requirements') and cannot be parsed into a single requirement. Please provide the intended obligation and the complete table.; The module-to-index / memory-erase mapping is provided only as a table fragment (e.g. Module 2 Application SW, range 0x02-0xFF) and is not fully specified in the source.
SSR-SW-0194splitSWFunctionalQMLowTestWhen the addressAndLengthFormatIdentifier is set to 0x01, the ECA shall apply the defined module-to-index mapping for the memoryStartAddress.N-SW-039REQ_UDS_0166The module-to-index mapping is truncated in the source at index 4 ('4 ...'); index values from 4 onward are not provided.
SSR-SW-0194-2splitSWFunctionalQMLowTestThe ECA shall map memoryStartAddress index 1 to the Boot loader, index 2 to the Application and index 3 to the Application Data.N-SW-039REQ_UDS_0166
SSR-HW-0047splitHWDesign constraintQMLowTestWhen the triggering condition (TBD) is met, the ECA shall perform the required checks or reorganization measures for the data structures.N-HW-014CR-HW-0030The triggering condition is referenced only as 'If so' and its antecedent is not provided in the source.; The data structures were given as an open-ended example list (EEPROM data, operational data, adaptive data, ...) and are not exhaustively defined.; The stored DIDs were followed by 'etc.'; the complete set beyond F1AB, F1AA, F1A9 is not provided.
SSR-HW-0047-2splitHWDesign constraintQMLowTestWhen the triggering condition (TBD) is met, the ECA shall execute the self-test.N-HW-014CR-HW-0030
SSR-HW-0047-3splitHWDesign constraintQMLowTestWhen the triggering condition (TBD) is met, the ECA shall store the event memory entries, the default values and the DIDs F1AB, F1AA and F1A9.N-HW-014CR-HW-0030
SSR-HW-0048HWDesign constraintQMLowTestThe ECA shall support downgrading of the software modules while the programmed modules are compatible with each other and with the hardware configuration.N-HW-015CR-HW-0032
SSR-SYS-0371splitSYSDesign constraintQMLowReviewWhen the ECA is restarted for any reason, or is returned to the DefaultSession due to a lack of TesterPresent or unfulfilled preconditions, the ECA shall support programming from the start of the programming sequence at programming step P1Pre.N-SYS-074CR-SYS-0195
SSR-SYS-0371-2splitSYSDesign constraintQMLowReviewWhen the ECA is restarted for any reason, or is returned to the DefaultSession due to a lack of TesterPresent or unfulfilled preconditions, the ECA shall remain independent of any state from an interrupted programming sequence.N-SYS-074CR-SYS-0195
SSR-SYS-0372SYSDesign constraintQMLowTestThe ECA shall support the specified session transitions when requested by either physical or functional addressing.N-SYS-074REQ_UDS_0338The set of session transitions ('stated below') is referenced but not included in the source.
SSR-SYS-0373SYSDesign constraintQMLowTestWhen a request to switch to the ProgrammingSession has been accepted, the ECA shall complete the preparations required to perform the programming operation.N-SYS-074REQ_UDS_0059The specific preparations required for reliable programming operation are not enumerated in the source ('all preparations to guarantee trouble-free programming operation').
SSR-SYS-0374SYSDesign constraintQMLowTestWhen switching to the Programming session, the ECA shall send the positive response before performing the actual session switch.N-SYS-074REQ_UDS_0061
SSR-SYS-0375SYSDesign constraintQMLowTestThe ECA shall generate the sessionKey in accordance with the specified pseudo code.N-SYS-074CR-SYS-0347The pseudo code defining sessionKey generation is referenced ('pseudo code below') but not included in the source.
SSR-SYS-0376SYSDesign constraintQMLowTestThe ECA shall use the sessionKey exclusively for the application responsible for communication over securedDataTransmission.N-SYS-074CR-SYS-0348
SSR-SW-0195SWFunctionalQMLowTestIf a non-permitted service is requested after the RequestDownload service has started and before the RequestTransferExit service has been called, then the ECA shall respond with negative response code 0x24.N-SW-040CR-SW-0038
SSR-SW-0196splitSWFunctionalQMLowTestWhile erasing memory, the ECA shall allow the client to start a data transfer using the TransferData service (0x36).N-SW-040CR-SW-0052
SSR-SW-0196-2splitSWFunctionalQMLowTestWhere the ECA implements automatic erase, the ECA shall perform the memory erasing in parallel with the data transfer.N-SW-040CR-SW-0052
SSR-SW-0197SWFunctionalQMLowTestIf a non-permitted service is requested after the RequestDownload service has started and before the RequestTransferExit service has been called, then the ECA shall respond with negative response code 0x12.N-SW-040REQ_UDS_0111The NRC name is truncated in the source as '(sub'; 0x12 corresponds to subFunctionNotSupported in ISO 14229-1, to be confirmed.
SSR-SW-0198SWFunctionalQMLowTestWhen a RequestFileTransfer request specifies modeOfOperation 0x06 (ResumeFile), the ECA shall resume downloading the file defined in the filePathAndName parameter at the returned filePosition indicator.N-SW-040CR-SW-0145The 'U' support-classification marker in the CVS124 table is not defined in the source; if it denotes an unsupported mode, applicability of this requirement to the ECA is to be confirmed.
SSR-SW-0199SWFunctionalQMLowTestAfter erasing memory, the ECA shall allow the client to start a data transfer using the TransferData (0x36) service.N-SW-040REQ_UDS_0161
SSR-SW-0200splitSWFunctionalQMLowTestWhen the addressAndLengthFormatIdentifier parameter is set to a value greater than 0x00, the ECA shall reset the software and data identification DIDs to their default values.N-SW-041CR-SW-0051
SSR-SW-0200-2splitSWFunctionalQMLowTestWhen any part of the boot software is erased, the ECA shall reset DIDs 0xF180, 0xF191 and 0xF187 to their default values.N-SW-041CR-SW-0051
SSR-SW-0201SWFunctionalQMLowTestThe ECA shall hash the receipt number together with the routineStatus routineResult parameter, in this respective order.N-SW-041CR-SW-0057
SSR-SW-0202SWFunctionalQMLowTestThe ECA shall return the signed hash in the routineResultProof parameter.N-SW-041CR-SW-0058
SSR-SW-0203SWFunctionalQMLowTestWhen the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall finish each server task before sending a positive response.N-SW-041REQ_UDS_0071
SSR-SW-0204SWFunctionalQMLowTestThe ECA shall format the resetType response parameter in accordance with ISO 14229-1.N-SW-041REQ_UDS_0245
SSR-SW-0205SWFunctionalQMLowTestThe ECA shall format the request message and its parameters in accordance with ISO 14229-1.N-SW-041REQ_UDS_0249The specific diagnostic service to which this request format applies is not identified in the source line.
SSR-SW-0206SWFunctionalQMLowTestThe ECA shall define the DataIdentifier parameter in accordance with ISO 14229-1.N-SW-042REQ_UDS_0255
SSR-SW-0207SWFunctionalQMLowTestThe ECA shall format the request message and its parameters in accordance with ISO 14229-1.N-SW-042REQ_UDS_0258The specific diagnostic service to which this request format applies is not identified in the source line (distinct from REQ_UDS_0249).
SSR-SW-0208SWFunctionalQMLowTestThe ECA shall format the FunctionalGroupIdentifier response parameter in accordance with ISO 14229-1.N-SW-042REQ_UDS_0269
SSR-SW-0209SWFunctionalQMLowTestThe ECA shall format the FunctionalGroupIdentifier response parameter in accordance with ISO 14229-1.N-SW-042REQ_UDS_0278Applies to a different service context than REQ_UDS_0269; the specific service is not identified in the source line.
SSR-SW-0210SWFunctionalQMLowTestThe ECA shall format the ControlEnableMaskRecord parameter in accordance with ISO 14229-1.N-SW-042REQ_UDS_0284
SSR-SW-0211SWFunctionalQMLowTestThe ECA shall format the routineIdentifier request parameter in accordance with ISO 14229-1.N-SW-042REQ_UDS_0106
SSR-SW-0212SWFunctionalQMLowTestThe ECA shall define the data parameter in accordance with ISO 14229-1.N-SW-043REQ_UDS_0126The specific service and 'data' parameter to which this definition applies are not identified in the source line.
SSR-SW-0213SWFunctionalQMLowTestWhen a RequestFileTransfer request specifies modeOfOperation 0x04 (ReadFile), the ECA shall read the file at the location defined by the filePathAndName parameter.N-SW-043CR-SW-0143
SSR-SW-0214SWFunctionalQMLowTestWhen a RequestFileTransfer request specifies modeOfOperation 0x05 (ReadDir), the ECA shall read the directory defined in the filePathAndName parameter.N-SW-043CR-SW-0144The 'U' support-classification marker in the CVS124 table is not defined in the source; if it denotes an unsupported mode, applicability of this requirement to the ECA is to be confirmed.
SSR-SW-0215SWFunctionalQMLowTestThe ECA shall format the sub-function parameter in accordance with ISO 14229-1.N-SW-043REQ_UDS_0142
SSR-SW-0216SWFunctionalQMLowTestWhen the addressAndLengthFormatIdentifier parameter is set to a value greater than 0x00, the ECA shall reset the software and data identification DIDs to their default values.N-SW-043REQ_UDS_0160The specific list of software and data identification DIDs to reset was truncated in the source ('...(see'); the enumerated DID set is to be confirmed (see also CR-SW-0051).
SSR-SW-0217SWDesign constraintQMLowReviewWhen the vehicle mileage signal is first received with a good signal status after a software update, the ECA shall report through the DID a snapshot of the vehicle mileage as received on CAN or another ECU-external source.N-SW-044REQ_UDS_0029The specific DID identifier referred to by 'This DID' is not given in the source line.
SSR-SW-0218splitSWFunctionalQMLowTestBefore executing a diagnostics service, the ECA shall verify that the vehicle speed is approximately 0, the gear box is in neutral, and the parking brake is engaged.N-SW-045CR-SW-0074The tolerance for 'approximately 0' (vehicle speed and engine speed) is not quantified in the source (TBD).
SSR-SW-0218-2splitSWFunctionalQMLowTestWhere the vehicle has an internal-combustion engine, the ECA shall additionally verify that the engine speed is approximately 0 before executing a diagnostics service.N-SW-045CR-SW-0074
SSR-SW-0218-3splitSWFunctionalQMLowTestWhere the vehicle has a high-voltage battery system, the ECA shall additionally verify that the high-voltage system is disengaged before executing a diagnostics service.N-SW-045CR-SW-0074
SSR-SW-0219SWFunctionalQMLowTestWhen the ECUReset service is requested with requestParameter value 0x01 (hardReset), the ECA shall simulate the power-on or start-up sequence performed after the ECA has been disconnected from its power supply.N-SW-045REQ_UDS_0069
SSR-SW-0220SWFunctionalQMLowTestIf a service request is denied due to insufficient rights according to the RBACC check, the ECA shall respond with negative response code 0x22 (conditionsNotCorrect).N-SW-046REQ_UDS_0342
SSR-SW-0221needs clarificationSWFunctionalQMMediumTestThe ECA shall implement Role-Based Access Control (RBAC) for diagnostics in accordance with CVS151.N-SW-046CR-SW-0184CLARIFY: This source line is CVS151 foreword/document-scope boilerplate ('This Commercial Vehicle Standard contains requirement specifications for TRATON Group...') and contains no ECA obligation. Is a requirement intended here, and if so, is it that the ECA shall implement diagnostics RBAC in accordance with CVS151?
SSR-SW-0222SWFunctionalQMHighestTestThe ECA shall provide Role-Based Access Control (RBAC) for diagnostics accessed over UDS.N-SW-046CR-SW-0185
SSR-SW-0223SWFunctionalQMMediumReviewBefore executing a diagnostics service that is under RBAC, the ECA shall require the requesting client to have completed an authorization procedure.N-SW-046CR-SW-0186
SSR-SW-0224SWFunctionalQMLowReviewThe ECA shall report the version of the currently stored RBACC via diagnostics.N-SW-046CR-SW-0188
SSR-SW-0225SWFunctionalQMLowReviewThe ECA shall report the rbacc-id of the currently stored RBACC via diagnostics.N-SW-046CR-SW-0189
SSR-SW-0226SWFunctionalQMMediumTestThe ECA shall allow reception of UDS Authentication (0x29) requests regardless of the RBACC settings.N-SW-047CR-SW-0195
SSR-SW-0227SWFunctionalQMLowTestThe ECA shall accept a UDS Authentication (0x29) request regardless of whether the RBACC contains a corresponding matching rule.N-SW-047CR-SW-0196
SSR-SW-0228SWFunctionalQMMediumReviewWhen the ECA receives a UDS SecuredDataTransmission (0x84) request, the ECA shall evaluate the reported internal service against the RBACC rules.N-SW-047CR-SW-0197
SSR-SW-0229SWFunctionalQMMediumTestThe ECA shall allow reception of UDS SecuredDataTransmission (0x84) requests regardless of the RBACC settings.N-SW-047CR-SW-0198
SSR-SW-0230splitSWFunctionalQMLowTestThe ECA shall accept a UDS SecuredDataTransmission (0x84) request regardless of whether the RBACC contains a corresponding matching rule.N-SW-047CR-SW-0199
SSR-SW-0230-2splitSWFunctionalQMLowTestBefore executing the internal request contained in a UDS SecuredDataTransmission (0x84) request, the ECA shall find a corresponding matching rule for that internal request in the RBACC.N-SW-047CR-SW-0199
SSR-SW-0231SWFunctionalQMMediumTestThe ECA shall allow reception of UDS TesterPresent (0x3E) requests regardless of the RBACC settings.N-SW-047CR-SW-0200
SSR-SW-0232SWFunctionalQMLowTestThe ECA shall accept a UDS TesterPresent (0x3E) request regardless of whether the RBACC contains a corresponding matching rule.N-SW-048CR-SW-0201
SSR-SW-0233splitSWFunctionalQMLowTestWhen entering the programming session, the ECA shall end each routine and function that influences programming.N-SW-049CR-SW-0081The precise trigger 'this process' is inferred to be entry into the programming session (DiagnosticSessionControl to ProgrammingSession) from context; the customer text does not state it explicitly.
SSR-SW-0233-2splitSWFunctionalQMLowTestWhen entering the programming session, the ECA shall check the safe-state conditions as a minimum.N-SW-049CR-SW-0081
SSR-SW-0234SWFunctionalQMHighTestWhere the ECA provides gateway server functionality, when the ECA receives a CommunicationControl service request, the ECA shall quiet down the network towards ECUs that have no diagnostic server and are present in its sub-buses.N-SW-050REQ_UDS_0076Whether the ECA provides gateway server functionality with sub-buses is to be confirmed for project P112478.
SSR-FUSA-0006FUSAFunctionalQMMediumTestBefore accepting a request to disable communication, the ECA shall verify that the applicable safety conditions are met.N-FUSA-003REQ_UDS_0077The applicable safety conditions are project-specific and are not enumerated in the source (TBD for project P112478).
SSR-SYS-0377SYSDesign constraintQMLowTestThe ECA shall map authentication error cases to the corresponding negative response codes (NRCs) in accordance with the Authentication service implementation specification CVS31.N-SYS-075REQ_UDS_0139
SSR-SYS-0378SYSDesign constraintQMLowReviewIf an authentication pending state already exists, the ECA shall replace the existing authentication pending state with the newly established one.N-SYS-075CR-SYS-0331Source sentence was truncated ('...replace the existing'); the object was completed by analogy to CR-SYS-0336 (active authentication state).
SSR-SYS-0379SYSDesign constraintQMLowReviewWhen the ECA sends a positive response, the ECA shall start the Authentication completion timer.N-SYS-075CR-SYS-0333
SSR-SYS-0380SYSDesign constraintQMLowTestThe ECA shall generate the challengeServer field as 32 octets using a cryptographic random number generator (CRNG).N-SYS-075CR-SYS-0334
SSR-SYS-0381SYSDesign constraintQMLowReviewIf the ECA fails to store the authentication state or cannot determine that it was stored, the ECA shall delete the authentication pending state connected to the client that submitted the proofOfOwnership request.N-SYS-075CR-SYS-0335
SSR-SYS-0382SYSDesign constraintQMLowReviewIf an active authentication state already exists, the ECA shall replace the existing state with the newly established one.N-SYS-075CR-SYS-0336
SSR-SYS-0383SYSDesign constraintQMLowReviewBefore sending a positive response to the deAuthenticate request, the ECA shall delete or invalidate the client's authentication.N-SYS-076CR-SYS-0338
SSR-SYS-0384SYSDesign constraintQMLowReviewThe ECA shall include in its authentication pending state at least the address of the client that issued the authentication request.N-SYS-076CR-SYS-0343The source list of pending-state contents is explicitly non-exhaustive; the full set of required fields is not enumerated.
SSR-SYS-0385SYSDesign constraintQMLowReviewThe ECA shall include in its authentication state at least the SessionKey.N-SYS-076CR-SYS-0344The source list of authentication-state contents is explicitly non-exhaustive; the full set of required fields is not enumerated.
SSR-SYS-0386SYSDesign constraintQMLowReviewThe ECA shall support only one authentication state.N-SYS-076CR-SYS-0345
SSR-SYS-0387SYSDesign constraintQMLowReviewThe ECA shall support only one authentication pending state.N-SYS-076CR-SYS-0346
SSR-SYS-0388SYSDesign constraintQMLowTestThe ECA shall support only passive time-based de-authentication.N-SYS-076CR-SYS-0350
SSR-SYS-0389SYSDesign constraintQMLowReviewIf the A3 timer times out before a new request from the same client is received, the ECA shall invalidate the authentication state.N-SYS-077CR-SYS-0353
SSR-SYS-0390SYSDesign constraintQMLowReviewThe ECA supplier shall define the passive timeout-based de-authentication parameter within the project.N-SYS-077CR-SYS-0354Value of the passive timeout-based de-authentication parameter is TBD, to be decided within the project.
SSR-SYS-0391SYSDesign constraintQMLowReviewIf the ECA can determine that a delay is not running after reset, the ECA shall accept a subsequent authentication request without delay.N-SYS-077CR-SYS-0357
SSR-SYS-0392SYSDesign constraintQMLowReviewIf the ECA cannot determine that a delay is not running after reset, the ECA shall accept a subsequent authentication request only after the delay has elapsed.N-SYS-077CR-SYS-0358
SSR-SYS-0393SYSDesign constraintQMLowTestThe ECA shall set the Authentication completion timer to 1 minute.N-SYS-077CR-SYS-0359
SSR-SYS-0394needs clarificationSYSDesign constraintQMLowTestThe ECA shall support more than one authentication state.N-SYS-077CR-SYS-0364CLARIFY: The source text '(There may be more than one authentication state)' is an informational note, not an obligation. What is the intended requirement on the ECA - must it maintain multiple concurrent authentication states, how many, and under what conditions?; The number of authentication states to support and the conditions under which multiple states apply are not specified.
SSR-SYS-0395needs clarificationSYSDesign constraintQMLowTestThe client shall authenticate the SDT request with the A argument set to the specified octet string.N-SYS-078CR-SYS-0384CLARIFY: The customer statement is truncated after 'set to the octet string'. Which octet string shall the A argument be set to for the SDT request (for example, the concatenation of the SDT request protocol elements excluding SIGMACBYTE)?; Definition of the octet string to which the A argument is set for the SDT request is missing (customer statement ends at 'set to the octet string').
SSR-SYS-0396SYSDesign constraintQMLowReviewThe ECA shall authenticate the SDT response with the A argument set to the octet string that comprises the protocol elements of the SDT response other than the SIGMACBYTE protocol element, concatenated with the octet string carried by the SIGMACBYTE protocol element of the corresponding request.N-SYS-078CR-SYS-0390
SSR-SYS-0397needs clarificationSYSDesign constraintQMLowTestWhen an SDT response is received and the client is unauthenticated, the client shall discard the SDT response.N-SYS-078CR-SYS-0394CLARIFY: The customer statement is truncated after 'the client shall discard the'. What exactly shall the unauthenticated client discard upon reception of an SDT response (for example, the SDT response itself)?; The object the client shall discard is not stated (customer statement ends at 'discard the').
SSR-FUSA-0007FUSAFunctionalQMLowReviewThe ECA supplier shall include the Diag safe state conditions in the preconditions agreed with the vehicle manufacturer.N-FUSA-004CR-FUSA-0007The complete set of preconditions is TBD, pending discussion with the vehicle manufacturer; only the Diag safe state conditions are confirmed.
SSR-CYBER-0146CYBERDesign constraintQMLowTestIf conflicting or overlapping rules are found within a role-configuration, the ECA shall enforce that the deny rule takes precedence over the allow rule.N-CYBER-032CR-CYBER-0067quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-CYBER-0147CYBERDesign constraintQMLowTestThe ECA shall evaluate each role-configuration independently.N-CYBER-032CR-CYBER-0070
SSR-CYBER-0148CYBERDesign constraintQMLowTestThe ECA shall support role-configurations using a 32-bit unsigned integer.N-CYBER-032CR-CYBER-0074
SSR-SW-0235SWFunctionalQMHighTestThe ECA shall exert the RBACC roles based on the ECU-diagnostics-Role extension in the client's certificate.N-SW-051CR-SW-0191
SSR-SW-0236SWFunctionalQMLowTestThe ECA shall accept lengthOfCertificateClient values within the range from 0x00C8 to 0x0800.N-SW-051CR-SW-0206
SSR-SW-0237SWFunctionalQMLowTestIf the lengthOfCertificateClient value is outside the expected range, the ECA shall send negative response code 0x13 indicating incorrectMessageLengthOrInvalidFormat.N-SW-051CR-SW-0207quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD)
SSR-SW-0238SWFunctionalQMLowTestWhen a verifyCertificateBidirectional request is received while the Authentication delay timer is running, the ECA shall respond with negative response code 0x37 indicating requiredTimeDelayNotExpired.N-SW-051CR-SW-0208
SSR-SW-0239SWFunctionalQMHighTestIf the ECA verifies the client certificate as invalid, the ECA shall respond to the verifyCertificateBidirectional request with negative response code 0x10 indicating generalReject.N-SW-051CR-SW-0209
SSR-SW-0240SWFunctionalQMLowTestIf the ECA fails to store the authentication pending state or cannot determine whether the authentication pending state was stored, the ECA shall respond to the verifyCertificateBidirectional request with negative response code 0x94 indicating ResourceTemporarilyNotAvailable.N-SW-051CR-SW-0210
SSR-SW-0241splitSWFunctionalQMHighTestIf the ECA NodeUID is absent from the NodeUID extension, the ECA shall reject the certificate.N-SW-052CR-SW-0221
SSR-SW-0241-2splitSWFunctionalQMHighTestIf the ECA NodeUID is absent from the NodeUID extension, the ECA shall generate negative response code 0x10 indicating generalReject.N-SW-052CR-SW-0221
SSR-SW-0242SWFunctionalQMHighTestThe client certificate shall include the ECU-Diagnostic role extension.N-SW-052CR-SW-0222
SSR-SW-0243SWFunctionalQMLowTestWhere a D-RBACC extension is present in the client certificate, the ECA shall apply the additional permissions and the restrictions specified by the D-RBACC extension in addition to the permissions derived from the client's roles.N-SW-052CR-SW-0223
SSR-SW-0244SWFunctionalQMHighTestIf the certificate content is invalid, the ECA shall return negative response code 0x10 indicating generalReject.N-SW-052CR-SW-0224
SSR-SW-0245SWFunctionalQMHighTestIf the certificate is non-compliant, the ECA shall return negative response code 0x10 indicating generalReject.N-SW-052CR-SW-0225
SSR-SW-0246needs clarificationSWFunctionalQMLowTestWhere the evaluate pattern applies, the ECA shall set the Confidentiality rule setting to 0x01, requiring confidentiality.N-SW-053CR-SW-0192CLARIFY: The source is introduced with 'E.g:', indicating an illustrative example. Is it a normative requirement that, for the evaluate pattern, the Confidentiality rule setting must be 0x01 (confidentiality required), or is it only an example of a possible rule setting?
SSR-SW-0247SWFunctionalQMLowTestWhen an SDT request is received and the ECA does not support SIGENCRYPT, the ECA shall respond with an SDT negative response using negative response code 0x3A.N-SW-053CR-SW-0248
SSR-SW-0248SWFunctionalQMLowTestWhen an SDT request is received and APAR is in conflict with SIGENCRYPT, the ECA shall respond with an SDT negative response using negative response code 0x3A.N-SW-053CR-SW-0249
SSR-SW-0249SWFunctionalQMLowTestWhen an SDT request is received and SIGLEN is in conflict with SIGENCRYPT, the ECA shall respond with an SDT negative response using negative response code 0x3A.N-SW-053CR-SW-0250
SSR-CYBER-0149CYBERDesign constraintQMLowTestThe ECA shall allow each request contained in the role 0 rules regardless of the client authentication state.N-CYBER-033CR-CYBER-0081
SSR-CYBER-0150CYBERDesign constraintQMLowTestIf the client's proofOfOwnership signature is successfully verified, the ECA shall establish a new authentication state for the client.N-CYBER-033CR-CYBER-0102
SSR-CYBER-0151CYBERDesign constraintQMLowTestIf verification of the client proofOfOwnership signature fails, the ECA shall delete the authentication pending state connected to the client that submitted the proofOfOwnership request.N-CYBER-033CR-CYBER-0103
SSR-CYBER-0152CYBERDesign constraintQMLowTestIf the client's proofOfOwnership signature is successfully verified, the ECA shall establish a new authentication state for the client.N-CYBER-033CR-CYBER-0104
SSR-CYBER-0153CYBERDesign constraintQMLowTestThe ECA shall use the ED25519 signature algorithm throughout the authentication process.N-CYBER-033CR-CYBER-0106
SSR-SYS-0398SYSDesign constraintQMLowTestWhile the client performs the ReadDataByIdentifier read operation, if the conditions and rules for each DID aliased by the dynamically defined identifier are not met, the ECA shall reject the request with the applicable negative response code.N-SYS-079CR-SYS-0302The specific negative response code for rejection is not defined (source says 'an appropriate NRC').
SSR-SW-0250splitSWFunctionalQMLowReviewThe ECA supplier shall document each deviation from this specification.N-SW-0541.1
SSR-SW-0250-2splitSWFunctionalQMLowReviewThe ECA supplier shall submit each documented deviation from this specification to the vehicle manufacturer for review.N-SW-0541.1
SSR-SW-0250-3splitSWFunctionalQMLowReviewThe ECA shall support only the APCE security concept of the Authentication (0x29) service specified in ISO 14229-1:2020.N-SW-0541.1
SSR-SW-0250-4splitSWFunctionalQMLowReviewWhere a requirement in this specification or in the Traton UDS specification CVS124 conflicts with ISO 14229-1:2020, the ECA supplier shall implement the requirement in this specification or CVS124.N-SW-0541.1
SSR-HW-0049HWDesign constraintQMLowTestIf an existing authentication pending state is found, the ECA shall verify whether the Authentication completion timer is currently running.N-HW-016CR-HW-0049
SSR-HW-0050HWDesign constraintQMLowTestWhile the Authentication completion timer is running, the ECA shall continue processing the client's proofOfOwnership request.N-HW-016CR-HW-0050
SSR-HW-0051HWDesign constraintQMLowTestIf a client and the ECA have completed the authentication process successfully, the ECA shall invalidate the authentication state when the ECA is reset by a power cycle.N-HW-016CR-HW-0051Source lists invalidation events under 'in the event of:' but presents only the power-cycle reset event; any further invalidation events are not captured in the source.
SSR-SW-0251SWFunctionalQMLowTestThe ECA shall set the ikm argument of the HKDF function to the octet string containing the SecuredDataTransmissionKey from the service 0x29 authentication state.N-SW-055CR-SW-0236
SSR-SW-0252SWFunctionalQMLowTestThe ECA shall set the info argument of the HKDF function to the concatenation of the "SDT_0x84_KEY" octet string and the CipherScheme identifier.N-SW-055CR-SW-0237

Jira import (ready)

Field mapping matches the P112478 requirement template (custom-field IDs). Reporter/Quality Reviewer carry the ${JIRA_DEFAULT_REPORTER} token; Due Date = 2026-07-31. The customer file keeps the verbatim statement in Description plus reference columns (GtWR verdict, violated rules, GtWR-compliant rewrite). The SSR file uses Requirements/Test Level = System (SYS.2,5), complete Summary, Status, clarification and traceability columns.

FileRowsPurposeDownload
Customer requirements — Jira import918Verbatim + GtWR rewritecustomer_requirements_jira_import.csv
System requirements (SSR) — Jira import1077Authored + verified, traceablesystem_requirements_jira_import.csv
Customer GtWR compliance matrix918Per-item verdictscompliance_customer.csv
SSR GtWR compliance matrix1077Per-item verdictscompliance_ssr.csv
Validation checklistINCOSE gate recordvalidation_checklist.md