INCOSE Requirements Analysis
GtWR v4 analysis of the customer requirements and freshly authored, traceable system requirements — ready for Jira import.
INCOSE Requirements Analysis
System of Interest: ECA (Electronic Clutch Actuator) · Project P112478. Customer requirements analysed against INCOSE GtWR v4; stakeholder needs and system requirements derived per the NRM transformation and Carson patterns, authored and independently verified by sub-agents.
918 customer requirements → 202 stakeholder needs → 1077 traceable system requirements
Every customer statement is checked verbatim against the 18 compulsory GtWR rules, abstracted into stakeholder needs, then refined into ECA-level system requirements that carry the specific obligation. Quantitative values come only from the customer sources — none are invented.
Method & standards
Analysis follows the INCOSE Guide to Writing Requirements v4 (rules R1–R42, characteristics C1–C15), the Needs & Requirements Manual v2 transformation flow, and the Carson requirement patterns (Functional/Performance, Suitability, Environment, Design). Customer statements are the RFQX extracted set from the customer RFQ (1001379436) and referenced specifications (3299216_1, CVS31/32/123-2/124/151/154). Each customer requirement is refined into one or more ECA-level system requirements that restate its specific obligation, authored and independently checked by writer and verifier sub-agents. Where the customer states no measurable target, the value is recorded as a managed unknown (TBD/TBC) rather than invented.
Customer set — GtWR rule compliance
| Rule | Name | Non-compliant | Compliant | Set verdict |
|---|---|---|---|---|
| R1 | Structured Statements | 117 | 801 | 117 flagged |
| R2 | Active Voice | 131 | 787 | 131 flagged |
| R5 | Definite Articles | 24 | 894 | 24 flagged |
| R7 | Vague Terms | 33 | 885 | 33 flagged |
| R8 | Escape Clauses | 4 | 914 | 4 flagged |
| R9 | Open-Ended Clauses | 10 | 908 | 10 flagged |
| R10 | Superfluous Infinitives | 18 | 900 | 18 flagged |
| R16 | Use of 'Not' | 121 | 797 | 121 flagged |
| R17 | Oblique Symbol | 72 | 846 | 72 flagged |
| R18 | Single-Thought Sentence | 48 | 870 | 48 flagged |
| R19 | Combinators | 256 | 662 | 256 flagged |
| R20 | Purpose Phrases | 17 | 901 | 17 flagged |
| R21 | Parentheses | 206 | 712 | 206 flagged |
| R24 | Pronouns | 50 | 868 | 50 flagged |
| R26 | Absolutes | 81 | 837 | 81 flagged |
| R32 | Universal Qualification | 106 | 812 | 106 flagged |
| R34 | Measurable Performance | 43 | 875 | 43 flagged |
| R35 | Temporal Dependencies | 1 | 917 | 1 flagged |
Customer requirements (918)
| ID | Customer ID | Area | Category | Prio | GtWR | Violated | Statement (verbatim) |
|---|---|---|---|---|---|---|---|
| CR-CYBER-0001 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R9 | The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybe rsecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc. |
| CR-CYBER-0002 | REQ_SEC_0001 | CYBER | Design constraint | Low | NON-COMPLIANT | R19 | The supplier shall provide documentation describing their strategies and methods for working with embedded systems cybersecurity. |
| CR-CYBER-0003 | REQ_SEC_0002 | CYBER | Design constraint | Medium | NON-COMPLIANT | R19 | The supplier shall perform risk assessment based on a threat and vulnerability analysis for each release, including any vehicle manufacturer-specific adaptations. |
| CR-SYS-0001 | — | SYS | Design constraint | Medium | NON-COMPLIANT | R19 | Method and scope shall be proposed to and approved by the vehicle manufacturer. |
| CR-VAL-0001 | — | VAL | Design constraint | Low | NON-COMPLIANT | R19 | Documentation on the method and results shall be provided to the vehicle manufacturer. |
| CR-CYBER-0004 | REQ_SEC_0003 | CYBER | Design constraint | Low | NON-COMPLIANT | R19 | The supplier shall describe the cybersecurity concept and how it is implemented in hardware and software respectively. |
| CR-CYBER-0005 | REQ_SEC_0022 | CYBER | Design constraint | Low | NON-COMPLIANT | R26R32 | All risks identified in cybersecurity risk analyses shall be evaluated. |
| CR-CYBER-0006 | — | CYBER | Design constraint | Low | COMPLIANT | — | For each risk identified in the cybersecurity risk analyses, a risk treatment decision shall be made to avoid, reduce, share, or retain the risk. |
| CR-CYBER-0007 | REQ_SEC_0023 | CYBER | Design constraint | Low | COMPLIANT | — | Cybersecurity controls shall sufficiently reduce the risk. |
| CR-CYBER-0008 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R24 | It shall be possible to verify which cybersecurity controls were derived from which requirements. |
| CR-CYBER-0009 | REQ_SEC_0024 | CYBER | Design constraint | High | NON-COMPLIANT | R19 | The cybersecurity concept of the supplier shall contain a documentation of the accepted residual risk and be agreed with the vehicle manufacturer. |
| CR-CYBER-0010 | REQ_SEC_0004 | CYBER | Design constraint | Low | NON-COMPLIANT | R19 | The supplier shall provide documentation of the verification and validation methods of cybersecurity features. |
| CR-CYBER-0011 | REQ_SEC_0005 | CYBER | Design constraint | Low | NON-COMPLIANT | R19 | The supplier shall provide test reports detailing the results from the verification and validation of cybersecurity features. |
| CR-CYBER-0012 | REQ_SEC_0040 | CYBER | Design constraint | High | NON-COMPLIANT | R1R2 | The vehicle manufacturer reserves the right to perform penetration testing on the ECU to identify potential vulnerabilities. |
| CR-SYS-0002 | REQ_SEC_0007 | SYS | Design constraint | Low | NON-COMPLIANT | R2R5R19 | An inventory of software and protocols, including their versions, shall be provided by the supplier. |
| CR-HW-0001 | REQ_SEC_0025 | HW | Design constraint | Low | NON-COMPLIANT | R2R5R19 | A BOM containing part numbers and versions of hardware components used in the product shall be provided by the supplier. |
| CR-VAL-0002 | REQ_SEC_0041 | VAL | Design constraint | Medium | NON-COMPLIANT | R1R2R19 | The vehicle manufacturer reserves the right to request documentation and evidence as well as to perform or order a compliance audit to determine whether the listed requirements are fulfilled. |
| CR-CYBER-0013 | REQ_SEC_0042 | CYBER | Design constraint | Medium | NON-COMPLIANT | R19 | The vehicle manufacturer and the supplier shall set up a cybersecurity DIA to agree on the responsibilities for the distributed cybersecurity activities. |
| CR-CYBER-0014 | REQ_SEC_0008 | CYBER | Design constraint | Medium | NON-COMPLIANT | R10R19R34 | The ECU shall be able to verify integrity and authenticity of a vehicle manufacturer-specified set of data stored within the ECU. |
| CR-SYS-0003 | — | SYS | Design constraint | Medium | NON-COMPLIANT | R19 | Methods shall be proposed to and approved by the vehicle manufacturer. |
| CR-CYBER-0015 | REQ_SEC_0009 | CYBER | Design constraint | Low | NON-COMPLIANT | R17R19 | The supplier shall apply methods for isolation of software/hardware components and data to reduce the effect in case of a cybersecurity breach. |
| CR-SYS-0004 | REQ_SEC_0020 | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Selection of cryptographic methods and their use shall be agreed upon between the vehicle manufacturer and the supplier. |
| CR-SYS-0005 | REQ_SEC_0010 | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | All network services implemented in the ECU shall undergo hardening. |
| CR-SYS-0006 | REQ_SEC_0011 | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The ECU shall only expose network and communication services that have been agreed upon with the vehicle manufacturer. |
| CR-MECH-0001 | REQ_SEC_0012 | MECH | Design constraint | Low | NON-COMPLIANT | R17 | Communication interfaces shall use boundary controls such as ingress/egress filtering. |
| CR-SYS-0007 | REQ_SEC_0013 | SYS | Design constraint | Low | COMPLIANT | — | Communication boundary controls shall be configurable by the vehicle manufacturer. |
| CR-SYS-0008 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Methods shall be proposed and approved by the vehicle manufacturer. |
| CR-SYS-0009 | REQ_SEC_0014 | SYS | Design constraint | Low | NON-COMPLIANT | R19R32 | Any interfaces used for development purposes shall be removed or disabled in series production. |
| CR-SYS-0010 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The details shall be agreed upon between the vehicle manufacturer and the supplier. |
| CR-HW-0002 | REQ_SEC_0026 | HW | Design constraint | Low | NON-COMPLIANT | R19 | Only hardware interfaces and protocols specified by the vehicle manufacturer shall be available in series production. |
| CR-CYBER-0016 | REQ_SEC_0027 | CYBER | Design constraint | Low | NON-COMPLIANT | R24 | It shall be possible for the vehicle manufacturer to securely inject data into the product in accordance with the specification provided by the vehicle manufacturer. |
| CR-SYS-0011 | REQ_SEC_0028 | SYS | Design constraint | Low | COMPLIANT | — | Data specified by the vehicle manufacturer shall be protected from manipulations. |
| CR-SYS-0012 | REQ_SEC_0029 | SYS | Design constraint | Low | COMPLIANT | — | Data specified by the vehicle manufacturer shall be protected from disclosure. |
| CR-SYS-0013 | REQ_SEC_0006 | SYS | Design constraint | Low | COMPLIANT | — | Intellectual property of the vehicle manufacturer shall be protected from disclosure. |
| CR-CYBER-0017 | REQ_SEC_0016 | CYBER | Design constraint | High | NON-COMPLIANT | R19R24 | It shall be possible for the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECU according to the specification of the vehicle manufacturer. |
| CR-CYBER-0018 | REQ_SEC_0019 | CYBER | Design constraint | Medium | COMPLIANT | — | Secrets, public keys and other data used for cybersecurity controls in production vehicle systems shall be different from those used in pre-production phases. |
| CR-SYS-0014 | REQ_SEC_0021 | SYS | Design constraint | Low | NON-COMPLIANT | R19 | ECUs shall only contain the secrets agreed between the vehicle manufacturer and the supplier. |
| CR-CYBER-0019 | REQ_SEC_0015 | CYBER | Design constraint | Low | COMPLIANT | — | ECUs shall conform to the harmonized Security Access specification [1] provided by the vehicle manufacturer. |
| CR-CYBER-0020 | REQ_SEC_0043 | CYBER | Design constraint | Low | NON-COMPLIANT | R24 | It shall be possible to update the software of the ECU. |
| CR-CYBER-0021 | REQ_SEC_0030 | CYBER | Design constraint | Low | NON-COMPLIANT | R32 | The supplier shall inform the vehicle manufacturer if any cybersecurity patches are available. |
| CR-CYBER-0022 | REQ_SEC_0044 | CYBER | Design constraint | Medium | NON-COMPLIANT | R5R19 | An incident response process shall be proposed to and approved by the vehicle manufacturer. |
| CR-CYBER-0023 | REQ_SEC_0045 | CYBER | Design constraint | Low | COMPLIANT | — | In case of cybersecurity incidents, the incident response process shall be used. |
| CR-CYBER-0024 | REQ_SEC_0046 | CYBER | Design constraint | Low | COMPLIANT | — | The incident response process shall be maintained for the entire product lifetime. |
| CR-CYBER-0025 | REQ_SEC_0032 | CYBER | Design constraint | Low | COMPLIANT | — | The incident response process shall ensure that risk is managed in coordination with the vehicle manufacturer. |
| CR-CYBER-0026 | REQ_SEC_0033 | CYBER | Design constraint | Low | NON-COMPLIANT | R32 | Any vulnerabilities that are identified during product lifecycle shall be promptly communicated to the vehicle manufacturer. |
| CR-VAL-0003 | — | VAL | Design constraint | Low | NON-COMPLIANT | R17 | The report shall include information needed to identify the affected vehicles/products. |
| CR-SYS-0015 | — | SYS | Design constraint | Medium | NON-COMPLIANT | R7R19 | Methods including the stipulation of a reasonable notification time shall be proposed to and approved by the vehicle manufacturer. |
| CR-CYBER-0027 | REQ_SEC_0034 | CYBER | Design constraint | Low | COMPLIANT | — | Following each identified and reported vulnerability, the supplier and vehicle manufacturer shall agree on an initial response to the vulnerability. |
| CR-CYBER-0028 | REQ_SEC_0035 | CYBER | Design constraint | Low | NON-COMPLIANT | R7R34 | Within adequate time after the initial vulnerability report, the supplier shall provide more information about the identified vulnerability. |
| CR-CYBER-0029 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R19 | The information shall contain • the version(s) of affected hardware or software components, • nature of the vulnerability, • description of the affected cybersecurity goal, • technical conditions to exploit the vulnerability, • impact of the exploitation and • possibilities to remove the vulnerability. |
| CR-VAL-0004 | — | VAL | Design constraint | Medium | NON-COMPLIANT | R7R19 | Methods including the stipulation of a reasonable reporting time shall be proposed to and approved by the vehicle manufacturer. |
| CR-SYS-0016 | REQ_SEC_0036 | SYS | Design constraint | Low | COMPLIANT | — | The supplier shall have a method for monitoring available vulnerability databases for vulnerabilities that can affect the delivered product. |
| CR-CYBER-0030 | REQ_SEC_0037 | CYBER | Design constraint | Low | NON-COMPLIANT | R19R26R32 | Identified vulnerabilities shall be considered in all current development projects or projects under field monitoring. |
| CR-HW-0003 | REQ_SEC_0047 | HW | Design constraint | Low | NON-COMPLIANT | R5 | An ECU returned from field shall allow for field-return analysis. |
| CR-SYS-0017 | REQ_SEC_0048 | SYS | Design constraint | Low | NON-COMPLIANT | R16 | Field-return analysis secrets shall not be operational in the field. |
| CR-HW-0004 | REQ_SEC_0049 | HW | Design constraint | Low | NON-COMPLIANT | R5R16 | An ECU enabled for field-return analysis shall not be possible to use as a spare part. |
| CR-HW-0005 | REQ_SEC_0050 | HW | Design constraint | Low | NON-COMPLIANT | R26R32 | All secrets specified by the vehicle manufacturer shall be protected throughout the lifecycle of the ECU. |
| CR-SYS-0018 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | End-of-life and decommissioning shall be specifically considered. |
| CR-HW-0006 | — | HW | Design constraint | Low | NON-COMPLIANT | R16 | Notes: a) It shall not be possible for a third party to reuse an ECU without system support from the vehicle manufacturer. |
| CR-CYBER-0031 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R16R19 | b) Decommissioning of an ECU shall not have the potential of causing unacceptable risk to the road user or the vehicle manufacturer. |
| CR-CYBER-0032 | REQ_SEC_0051 | CYBER | Design constraint | Low | NON-COMPLIANT | R19 | Security related events shall be identified and logged. |
| CR-SYS-0019 | — | SYS | Design constraint | High | NON-COMPLIANT | R18R19R26R32 | The gearbox itself shall be used in all drivetrains and the ECA shall be common and must be complaint to be put on any driveline setup. |
| CR-SYS-0020 | 2.1 | SYS | Functional | Low | COMPLIANT | — | The clutch actuator shall be electrically driven |
| CR-SYS-0021 | 2.3 | SYS | Functional | Medium | NON-COMPLIANT | R1R2R19R21 | The ECA (Electric Clutch Actuator) must have its own internal ECU for manoeuvring and error handling. |
| CR-MECH-0002 | 2.6 | MECH | Design constraint | Medium | NON-COMPLIANT | R16R18R21 | The ECA units shall be manufactured with marking variants according to the requirements in Scania STD19 (Ref 14.17). The variant type shall be based on delivery agreement and Brand involved. Variant 1: For Scania units, wordmark variant C1 Part number (7 digits). Variant 2: For MAN units, wordmark variant Z1. Part number (13 digits). Variant 3: For International units, wordmark variant X1. Part number (8 digits) Variant 4 Tentik wordmark variant W. Part number (9 digits, two spaces in format: 12 345 6789). Common marking requirements that must be fulfilled for each marking variant are: Marking method: MA1 Marking height: 3 mm Date format: YYMMDD A unique serial number A DMC according to Scania STD 4562 (Ref 14.18) that contains the part number and serial number information. The marking shall not be visible when the ECA is mounted on a gearbox. The ECA units shall be delivered to the required Traton brand’s production in a position in the pallet where the marking is visible. |
| CR-SYS-0022 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The variant type shall be based on delivery agreement and Brand involved. |
| CR-MECH-0003 | — | MECH | Design constraint | Medium | NON-COMPLIANT | R1R2R19R21 | Common marking requirements that must be fulfilled for each marking variant are: Marking method: MA1 Marking height: 3 mm Date format: YYMMDD A unique serial number A DMC according to Scania STD 4562 (Ref 14.18) that contains the part number and serial number information. |
| CR-MECH-0004 | — | MECH | Design constraint | Low | NON-COMPLIANT | R16 | The marking shall not be visible when the ECA is mounted on a gearbox. |
| CR-MECH-0005 | — | MECH | Design constraint | Low | COMPLIANT | — | The ECA units shall be delivered to the required Traton brand’s production in a position in the pallet where the marking is visible. |
| CR-MECH-0006 | 2.7 | MECH | Design constraint | Low | NON-COMPLIANT | R16R18R21 | The rubber cover (See req. 4.16) shall be marked according to the requirements in Scania STD19 (Ref 14.17) Tentik, wordmark variant W Part number (9 digits, two spaces in format 12 345 6789) Marking method: CAS Marking height: 2-6 mm. Date dial: CVM. Alternative design: CXM or equivalent combination of date dial and date field The rubber cover marking shall not be visible when the ECA is mounted on a gearbox |
| CR-MECH-0007 | 2.8 | MECH | Design constraint | Low | NON-COMPLIANT | R17R19 | The ECA shall be designed with Remanufacturing and/or Refurbishment in mind with possibility of swapping out larger electronic assemblies/components. Details to be agreed with Traton |
| CR-SYS-0023 | 2.11 | SYS | Design constraint | Low | NON-COMPLIANT | R9R19 | The mechanics shall also be tested and verified, in an overall durability test as stated in Appendix B etc. |
| CR-MECH-0008 | — | MECH | Design constraint | Low | NON-COMPLIANT | R21 | 4.16) shall be marked according to the requirements in Scania STD19 (Ref 14.17) Tentik, wordmark variant W Part number (9 digits, two spaces in format 12 345 6789) Marking method: CAS Marking height: 2-6 mm. |
| CR-SYS-0024 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Details to be agreed with Traton 2.9 Traton shall be invited to participate in electrical and mechanical design reviews. |
| CR-SYS-0025 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R26R32 | 2.10 Traton requires extensive testing to be performed by the supplier to verify all demands stated in the requirement specification. |
| CR-VAL-0005 | — | VAL | Design constraint | Low | NON-COMPLIANT | R1R2 | 2.12 Traton requires: - Documentation of the product, i.e. |
| CR-HW-0007 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R16R19R26 | Should the PP be fully calculated from the AP-sensor, then this offset should not exist. |
| CR-MECH-0009 | 4.2 | MECH | Design constraint | Low | COMPLIANT | — | The total stroke of the actuator shall be 85 mm |
| CR-SYS-0026 | 4.3 | SYS | Functional | Low | NON-COMPLIANT | R10R19 | The clutch actuator shall be able to reach the extreme positions A and B in with the center of the pushrod end. Dimensions measured on the ECA. See Figure 3 - Pushrod positions. Figure 3 - Pushrod positions |
| CR-MECH-0010 | 4.6 | MECH | Design constraint | Low | NON-COMPLIANT | R16R20R21 | When the ECA is assembled, it shall not be possible to insert an object larger than Ø0,2 mm (A wire could be used as test object) between the ECA and gearbox flange, so that the object enters the space behind the ECA. The rubber grommet at the lower part of the flange can have the same interface as the surrounding aluminum flange. |
| CR-MECH-0011 | 4.7 | MECH | Design constraint | Low | NON-COMPLIANT | R18 | When the ECA is assembled, a gap of 3,5 mm towards surface B with a profile tolerance of ±1 mm to the nominal dimensions shall be provided. The surface roughness of the ECA opposite to surface B shall be equal or finer than Ra 3,2 µm. |
| CR-MECH-0012 | 4.8 | MECH | Design constraint | Low | COMPLIANT | — | The ECA shall be adapted for 6 pcs M8 flange screws described by Scania STD4435 |
| CR-MECH-0013 | — | MECH | Design constraint | Low | NON-COMPLIANT | R16R19R32 | P 1 Page 4.4 ECA shall not interfere with any geometry in the 3D envelope -1 1_RFQ2030.stp except where interference fits or other types of functional contacts are required. |
| CR-SYS-0027 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The surface roughness of the ECA opposite to surface B shall be equal or finer than Ra 3,2 µm. |
| CR-MECH-0014 | 4.9 | MECH | Design constraint | Low | COMPLIANT | — | The ECA shall be adapted for 2 pcs 10 mm guide pins Figure 5 - Gearbox flange |
| CR-MECH-0015 | 4.10 | MECH | Design constraint | Low | NON-COMPLIANT | R17R18R32 | The guide pin holes in the ECA shall be Ø 10,1±0.05 mm and at least 12 mm deep. The holes shall also block the guide pin from protruding more than 14 mm from the gearbox housing. Both depths measured from the center of the oval hole in the Gearbox/ECA flange. |
| CR-MECH-0016 | 4.11 | MECH | Design constraint | Low | NON-COMPLIANT | R10R21R26R34 | The ECA shall be able to be held by the guide pins only while being exposed to the max clutch load, (req. 4.22) up to 50 times. The clutch load will be removed and the screw interface tightened between every load occasion. Surface indents in the contacts are allowed as long as the structural integrity is unaffected |
| CR-MECH-0017 | 4.12 | MECH | Design constraint | Low | COMPLIANT | — | The pushrod end that makes contact with the clutch lever shall be a Ø15,93±0,07 mm steel sphere. |
| CR-CYBER-0033 | 4.13 | CYBER | Design constraint | Low | NON-COMPLIANT | R18R19R24 | It shall be possible to pull the pushrod 50 times with a force of 300 N without risk for it to come loose from the ECA. Alternatively it can have a loose fit in the ECA, but it shall be possible to reconnect it by pushing it back by hand. |
| CR-MECH-0018 | 4.14 | MECH | Design constraint | Low | COMPLIANT | — | The ECA shall allow space for external tools according to the cylinders in the 3D envelope attached. |
| CR-MECH-0019 | 4.15 | MECH | Design constraint | Low | NON-COMPLIANT | R21 | The ECA shall have a window where the volume shown in Figure 6 – Snap in tool space, could pass through(See req. 4.4). |
| CR-MECH-0020 | 4.16 | MECH | Design constraint | Low | NON-COMPLIANT | R16R19R34 | The ECA shall provide a support for a clutch snap in tool on the marked surface in Figure 4 ISO view of 3D envelope. The maximum force is 1kN. Surface indents are allowed as long as it does not affect other requirements or the structural integrity of the ECA. |
| CR-MECH-0021 | — | MECH | Design constraint | Low | COMPLIANT | — | The holes shall also block the guide pin from protruding more than 14 mm from the gearbox housing. |
| CR-SYS-0028 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Alternatively it can have a loose fit in the ECA, but it shall be possible to reconnect it by pushing it back by hand. |
| CR-MECH-0022 | 4.17 | MECH | Design constraint | Low | NON-COMPLIANT | R17R18R21 | The hole shall be equipped with a cover possible to assemble and disassemble at least 50 times without tools. If an interference fit is chosen, the maximum force to assemble/disassemble shall be 50 N in room temperature. It shall still remain intac t and keep tightness after vibration testing (See req.10.5) |
| CR-MECH-0023 | 4.18 | MECH | Design constraint | Low | NON-COMPLIANT | R16 | When the cover is assembled it shall not be possible to insert an object larger than Ø0,2 mm into the gearbox housing between the cover and ECA. A wire could be used as test object. Figure 6 - Snap in tool space |
| CR-MECH-0024 | 4.19 | MECH | Design constraint | Low | NON-COMPLIANT | R7R18R21 | The ECA shall have a loop or similar feature where the cable can be fixated with a cable tie Optionally an M8 screw thread and rotation stop for a sheet metal bracket indicated in Figure 4 - ISO view of 3D envelope, can be provided. The loop or Scania assembled bracket shall be located close to the centre ( ± 20 mm) of the cable section between the connector and last cable fixation point on the gearbox |
| CR-MECH-0025 | 4.20 | MECH | Design constraint | Low | NON-COMPLIANT | R18 | The connector for communication and power shall be positioned as indicated in Figure 4 ISO view of 3D envelope, when connected. Details regarding actual length and positioning tolerances shall be agreed in design phase. |
| CR-SYS-0029 | 4.21 | SYS | Functional | Low | NON-COMPLIANT | R16R21 | If the ECA is powered up with the PP in the utmost forward position (for example when not connected to the clutch lever) it shall move AP to its utmost reversed position. |
| CR-MECH-0026 | — | MECH | Design constraint | Low | NON-COMPLIANT | R17 | If an interference fit is chosen, the maximum force to assemble/disassemble shall be 50 N in room temperature. |
| CR-SYS-0030 | — | SYS | Functional | Low | NON-COMPLIANT | R19 | Details regarding actual length and positioning tolerances shall be agreed in design phase. |
| CR-SYS-0031 | 4.23 | SYS | Functional | Low | NON-COMPLIANT | R18 | The actuator shall apply a preload force for the release bearing. The preload force measured on the push rod shall be 150N to 250N independent of the clutch position |
| CR-MECH-0027 | 4.25 | MECH | Design constraint | Low | NON-COMPLIANT | R24R32 | It must be possible to assemble the actuator independent of the lever position without any power connection. This means that the push rod shall be possible to move by hand. Maximum force allowed is 300N. |
| CR-SYS-0032 | — | SYS | Functional | Medium | NON-COMPLIANT | R16R21R26 | 4.26 When the clutch is fully engaged, the active control mode is position or torque control mode and there is no active request to extract the pushrod (clutch opening motion), the ECA shall not apply a force outside of limits in preload force defined in req. |
| CR-SYS-0033 | — | SYS | Functional | Medium | NON-COMPLIANT | R17R21 | P 1 Page 5 Clutch engage and disengage 5.1 It shall be possible to disengage the clutch in 180ms (= Ts) with accuracy according to ,and max speed set to 125mm/s (see |
| CR-SYS-0034 | — | SYS | Functional | Low | NON-COMPLIANT | R21R24R34 | This shall be measured against the maximum disengage force (See Appendix A) Figure 7 – Maximum disengage time |
| CR-SYS-0035 | — | SYS | Functional | Low | NON-COMPLIANT | R17R21 | P 1 Page 5.2 It shall be possible to engage the clutch in 180ms (=Ts) with accuracy according to re q.5.10, and the max speed set to 125mm/s (see ). |
| CR-SYS-0036 | — | SYS | Functional | Low | NON-COMPLIANT | R21R24R34 | This shall be measured against the minimum engage force (See Appendix A) Figure 8 - Maximum engage time |
| CR-MECH-0028 | 5.3 | MECH | Design constraint | Low | NON-COMPLIANT | R21 | The clutch actuator shall report the absolute position of the current actuator stroke (AP) (Ref 14.14). |
| CR-MECH-0029 | 5.4 | MECH | Design constraint | Low | NON-COMPLIANT | R21R24R26 | It shall also report the position that corresponds to a fully closed clutch position (FCCP), expressed in absolute position of the actuator stroke and relative to the absolute zero position (See req. 6.5). |
| CR-SYS-0037 | 5.5 | SYS | Functional | Low | NON-COMPLIANT | R21 | The clutch actuator shall be equipped with a displacement sensor measuring the movement of the push rod, (Ref 14.14) |
| CR-SYS-0038 | 5.6 | SYS | Functional | Low | NON-COMPLIANT | R1R2R10R17R19R21 | The actuator must be able to determine the pushrod position according to the following Accuracy (maximum difference between measured pushrod position and actual pushrod position): +/- 1.6mm. Resolution (smallest discernible unit of change along the X axis): 0.0125mm. Repeatability (maximum variation between measurements at the same position and in the same unit, with equal environmental conditions): +/- 0.1mm. Range: 85mm (AP) |
| CR-MECH-0030 | 5.7 | MECH | Design constraint | Low | NON-COMPLIANT | R18R19R26 | For each stroke that the actuator performs it shall adjust to the current wear of the clutch. This means that is shall be possible to request a relative stroke from the fully closed clutch position and achieve the step accuracy as defined in req. 5.10. The implementation can be either a pure mechanical solution or it can be implemented using a software based solution. |
| CR-SYS-0039 | 5.9 | SYS | Functional | Low | NON-COMPLIANT | R21 | The maximum stationary position error relative to real FCCP (i e self-adjustment error + step response error) shall be ±0.15mm. |
| CR-MECH-0031 | — | MECH | Design constraint | Medium | COMPLIANT | — | The FCCP after a clutch engage shall be updated to 90% of the step within 0,2 s per mm that the FCCP have changed during the stroke. |
| CR-SYS-0040 | — | SYS | Functional | Low | NON-COMPLIANT | R17R18 | P 1 Page 5.10 The actuator shall move the pushrod according to the following points: Actuator maximum speed: The maximum achievable speed of the pushrod shall be at least 125 mm/s. |
| CR-SYS-0041 | — | SYS | Functional | Low | NON-COMPLIANT | R34 | The actuator shall move the pushrod at the highest possible speed, limited only by its maximum achievable speed and the maximum speed request. |
| CR-SYS-0042 | — | SYS | Functional | Low | NON-COMPLIANT | R17R19R21 | 6.4) Dynamics start of movement: The requested speed (or 125mm/s, if requested speed > 125mm/s) shall be achieved within 50ms from when a new value for requested position is sent. |
| CR-SYS-0043 | — | SYS | Functional | Low | COMPLIANT | — | Dynamics end of movement: The requested speed shall be kept until 2 mm from the target position. |
| CR-SYS-0044 | — | SYS | Functional | Low | NON-COMPLIANT | R1R2 | 100ms after reaching 2 mm from target, the maximum position error should be ±0.1mm. |
| CR-MECH-0032 | — | MECH | Design constraint | Low | NON-COMPLIANT | R19 | Maximum overshoot is 0.2 mm When a new position is requested, but the stroke is too short to reach requested speed, the ECA shall complete the stroke in minimum time with dynamic in compliance with the , 5.2 and this section. |
| CR-SYS-0045 | 5.11 | SYS | Functional | Low | NON-COMPLIANT | R26 | Req. 5.10 shall be tested with a step response test cycle, according to description and Figure 10 - Step response test cycle. Step from FCCP to 0.5x fully open position Wait 2 seconds Step to fully open position Wait 2 seconds Step to 0.5x fully open position Wait 2 seconds Step to FCCP Figure 10 - Step response test cycle |
| CR-SYS-0046 | — | SYS | Design constraint | Low | COMPLIANT | — | 5.10 shall be tested with a step response test cycle, according to description and Figure 10 - Step response test cycle. |
| CR-SYS-0047 | — | SYS | Design constraint | Low | NON-COMPLIANT | R10R19R32 | P 1 Page 5.12 The ECA shall be able to run the 4 second test cycle in Figure 11 - Release frequency test continuously for 5 hours without any degradation or failure. |
| CR-SYS-0048 | — | SYS | Functional | Low | NON-COMPLIANT | R19R21R34 | The test shall be done with the highest operating temperature (see ) and maximum clutch force (See Appendix A) Figure 11 - Release frequency test |
| CR-CYBER-0034 | 5.14 | CYBER | Design constraint | Low | NON-COMPLIANT | R18R19R21R24 | It shall be possible to keep the clutch disengaged continuously without risk of loss of function for 120 min. This shall be measured against the maximum disengage force (Appendix A) and an highest operating temperature (see req. 8.1). |
| CR-SYS-0049 | — | SYS | Functional | Low | NON-COMPLIANT | R19R32 | Between 16V and loss of power the ECA shall hold its current position or move towards requested position without any time requirement. |
| CR-SYS-0050 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The strategy shall be disc ussed and approved with Traton. |
| CR-SYS-0051 | — | SYS | Functional | Low | NON-COMPLIANT | R19R21R24R34 | This shall be measured against the maximum disengage force (Appendix A) and an highest operating temperature (see req. |
| CR-SYS-0052 | 6.2 | SYS | Design constraint | Low | NON-COMPLIANT | R7R21 | The ECA will be controlled by messages on the CAN bus and by the PWM signal specified in req. 7.24-7.33. The CAN communication messages are specified in PD2497100 (Ref 14.14). It shall be followed to its full extent. If needed, some messages might be complemented with additional checksums and message counters |
| CR-SYS-0053 | — | SYS | Design constraint | Low | COMPLIANT | — | P 1 Page 6 SW functionality 6.1 TB4684 shall be applied. |
| CR-SYS-0054 | — | SYS | Design constraint | Low | NON-COMPLIANT | R24 | It shall be followed to its full extent. |
| CR-SW-0001 | 6.3.1 | SW | Functional | Low | NON-COMPLIANT | R18R19R21 | When requesting Absolute Position Control the actuator shall move to the actuator position defined by the Requested Position (RP). The RP can in this mode correspond to the full wear travel of the clutch (see req. 4.3) It is allowed to control movement to protect the ECA and clutch from hardware damage. Specific cases shall be approved with Traton. Control mode Absolute position 0x01 |
| CR-SW-0002 | 6.3.2 | SW | Functional | Low | NON-COMPLIANT | R16R19R21R26 | Control (RPC) the actuator shall move to an offset that corresponds to the Requested Position from the Fully Closed Clutch Position (FCCP). The RP can be up to a full Release Travel (22,4 mm) in this mode. How the FCCP can be identified is described in 6.5. When RP = 0 the actuator is allowed to have a position that is less than the FCCP but not more, since this would open the clutch. Control mode Relative position 0x02 |
| CR-SYS-0055 | — | SYS | Functional | Low | COMPLIANT | — | When requesting Absolute Position Control the actuator shall move to the actuator position defined by the Requested Position (RP). |
| CR-SYS-0056 | — | SYS | Design constraint | Low | COMPLIANT | — | Specific cases shall be approved with Traton. |
| CR-SW-0003 | — | SW | Functional | High | COMPLIANT | — | Control mode Relative position 0x02 6.3.3 When requesting Torque Control (TC) the actuator shall actuate the requested motor torque. |
| CR-SYS-0057 | 6.4 | SYS | Functional | Low | NON-COMPLIANT | R5R16R34 | A maximum allowed speed of the actuator is sent as a separate signal on CAN. If the actuator can move faster than this value it shall be controlled in a such way that it does not exceed this limit. |
| CR-SYS-0058 | 6.5.2 | SYS | Functional | Low | NON-COMPLIANT | R19 | The value shall be frozen at the last identified position and used for RPC. Self-adjustment disabled 0x3 |
| CR-SYS-0059 | — | SYS | Functional | Low | COMPLIANT | — | 6.3.4 When requesting Test Mode, the actuator shall perform tests to detect latent faults. |
| CR-SW-0004 | — | SW | Functional | Low | NON-COMPLIANT | R19R21 | ECA behavior and additional requirements for this mode can be found in (Ref 14.16) Control mode Test mode 0x04 6.3.5 When this Control Mode is sent the actuator shall behave as if the power supply was cut with aspect to control of the actuator. |
| CR-SYS-0060 | — | SYS | Design constraint | Low | COMPLIANT | — | CAN communication shall still be active. |
| CR-SYS-0061 | — | SYS | Functional | Low | NON-COMPLIANT | R16R34 | If the actuator can move faster than this value it shall be controlled in a such way that it does not exceed this limit. |
| CR-SYS-0062 | — | SYS | Design constraint | Low | COMPLIANT | — | 6.5 Self-adjustment The self-adjustment signal defines the restrictions of how the FCCP shall be identified. |
| CR-SYS-0063 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The value of the FCCP shall be reported via CAN(Ref 14.14) Req. |
| CR-SYS-0064 | — | SYS | Functional | Low | NON-COMPLIANT | R19 | The value shall be frozen at the last identified position and used for RPC. |
| CR-VAL-0006 | 6.9 | VAL | Design constraint | Low | COMPLIANT | — | The ECA shall report a unique ECA individual identification number |
| CR-SYS-0065 | 6.10 | SYS | Design constraint | Low | COMPLIANT | — | The ECA shall report supplier code 5 via CAN. |
| CR-VAL-0007 | 6.11 | VAL | Design constraint | Low | NON-COMPLIANT | R19 | The ECA shall report a complete SW version number. The number is decided by the supplier and can be in the range 0-64255. |
| CR-VAL-0008 | 6.12 | VAL | Design constraint | Low | NON-COMPLIANT | R19 | The ECA shall report a complete HW version number. The number is decided by the supplier and can be in the range 0-64255. |
| CR-HW-0008 | 6.14 | HW | Design constraint | Low | COMPLIANT | — | The ECA shall report its current System State. Valid states are explained in requirements 6.14.1 - 6.14.9. |
| CR-SYS-0066 | — | SYS | Functional | Low | COMPLIANT | — | 6.6.1 When low accuracy mode is requested, the maximum push rod position(PP) error can be ±0.5mm Accuracy mode Low accuracy 0x0 6.6.2 Accuracy according to 5.10 shall be fulfilled. |
| CR-SW-0005 | — | SW | Functional | Medium | NON-COMPLIANT | R19 | 6.13 Error State Diagnostic - ESD and Error State Action - ESA The ECA shall send a bit field via CAN containing errors present Additionally, see , |
| CR-VAL-0009 | — | VAL | Design constraint | Low | NON-COMPLIANT | R19R21 | ESA definition( Ref 14.16) The supplier shall provide documentation for the ESD bits and related faults . |
| CR-SYS-0067 | 6.14.2 | SYS | Functional | Low | NON-COMPLIANT | R24 | This value shall be sent when the ECA is actuating Absolute Position Control. 0x1 |
| CR-SYS-0068 | 6.14.3 | SYS | Functional | Low | NON-COMPLIANT | R24 | This value shall be sent when the ECA is actuating Relative Position Control. 0x2 |
| CR-SYS-0069 | 6.14.4 | SYS | Functional | Highest | NON-COMPLIANT | R24 | This value shall be sent when the ECA is actuating Torque Control. The torque being controlled is the torque of the motor. 0x4 |
| CR-SYS-0070 | 6.14.5 | SYS | Design constraint | Low | NON-COMPLIANT | R16R19R21R24 | This value shall be sent when the ECA is performing a Self-Adjustment procedure that is not part of a RPC or TC request (i.e. passing FCCP). 0x5 |
| CR-SW-0006 | 6.14.6 | SW | Functional | Low | NON-COMPLIANT | R7R16R19R24 | This value shall be sent when the ECA is performing its initiation routine and is not yet available for control. 0xA |
| CR-SYS-0071 | 6.14.8 | SYS | Functional | Low | NON-COMPLIANT | R19R24 | This value shall be sent when the actuator is in debug or test control state. 0xC |
| CR-SYS-0072 | 6.14.9 | SYS | Functional | Low | NON-COMPLIANT | R24 | This value shall be sent when the actuator is performing a motor brake simulation. 0xD |
| CR-SW-0007 | — | SW | Functional | Low | COMPLIANT | — | 6.14.1 Boot Mode If the actuator is in boot mode, 0x00 shall be reported as active state. |
| CR-SYS-0073 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R19 | 0xA 6.14.7 Shut down This value shall be sent when the ECA is performing its shut down routing and is not available for control. |
| CR-HW-0009 | 6.15 | HW | Design constraint | Low | NON-COMPLIANT | R21 | The ECA shall report the current system temperature.(Ref 14.14) |
| CR-SYS-0074 | 6.16 | SYS | Functional | Medium | NON-COMPLIANT | R19R21 | The ECA shall calculate and report the actuator motor torque. (Ref 14.14) |
| CR-SYS-0075 | 6.17 | SYS | Functional | Low | NON-COMPLIANT | R18R21 | The ECA shall report the current for each phase of the actuator. These values shall be calculated using a moving mean filter. The filter time shall equal the update frequency . (Ref 14.14) |
| CR-HW-0010 | 6.18 | HW | Design constraint | Low | NON-COMPLIANT | R21 | The ECA shall report the current system voltage. (input voltage) (Ref 14.14) |
| CR-VAL-0010 | 6.19.1 | VAL | Design constraint | Low | NON-COMPLIANT | R19 | The ECA shall store and report its accumulated operational hours. |
| CR-VAL-0011 | 6.19.2 | VAL | Design constraint | Low | COMPLIANT | — | The ECA shall report its accumulated lifetime travel length. |
| CR-SYS-0076 | 6.20 | SYS | Design constraint | Low | NON-COMPLIANT | R21 | CVS120 shall be applied (Ref 14.12). |
| CR-SW-0008 | 6.21 | SW | Functional | Medium | NON-COMPLIANT | R8R17 | Cybersecurity shall be considered through a separate process with the latest Traton workflow in mind. The following apply: Mandatory: TRATON secure updates - CVS31,CVS32,CVS123-2,CVS154 TRATON secure diagnostics - CVS31,CVS32,CVS151 TRATON Specification on Unified diagnostic Services CVS124 Other applicable documents considered as supporting specifications: CVS30, CVS33, CVS34,CVS121,CVS122,SecureBoot,Vehicle Baseline Requirements, ECU Baseline Requirements Additional standards/documents will be made available, if applicable. |
| CR-SYS-0077 | — | SYS | Design constraint | Low | NON-COMPLIANT | R24 | These values shall be calculated using a moving mean filter. |
| CR-SYS-0078 | — | SYS | Design constraint | Low | COMPLIANT | — | The filter time shall equal the update frequency . |
| CR-VAL-0012 | 6.23 | VAL | Design constraint | Low | NON-COMPLIANT | R1R2R10R19 | The reported ESD must be able to be validated and invalidated. |
| CR-SW-0009 | 6.24 | SW | Functional | Low | NON-COMPLIANT | R9R19R21R32R34 | The gearbox control unit(TCU) shall be responsible for setting DTCs based on received notifications from ECA via ESD, including time-stamps, occurrence counters etc. One unique DTC will be set per bit in the ESD signal. If higher resolution is required for the supplier to properly troubleshoot any individual occurrence, then the ECA is responsible for storing these parameters internally. Internally stored parameters may be accessible only using supplier defined tools . |
| CR-SYS-0079 | 6.25 | SYS | Design constraint | Low | NON-COMPLIANT | R19R32 | Any data logged or stored shall be agreed upon together with Traton. |
| CR-HW-0011 | 6.26 | HW | Design constraint | Low | NON-COMPLIANT | R16R18R21 | When storing data in the device, the supplier shall take measures to prevent corruption of data which can occur for example when suffering power loss during read or write cycles. The supplier shall also ensure that systems are in place that ensure that data corruption is handled without loss of data, or loss of function. This could be designed with for example data mirroring. It is acceptable if purely statistical data (e.g. operation hours) from the active operation cycle is not stored in case of an abnormal shutdown. |
| CR-SYS-0080 | 6.27 | SYS | Design constraint | Low | NON-COMPLIANT | R16R18 | There shall only be one calibration set of the ECA that is delivered to Traton, i.e, the calibration shall not be dependent of installation variants. |
| CR-FUSA-0001 | 6.28 | FUSA | Functional | High | NON-COMPLIANT | R17R24R26R32 | It shall be possible to reset the ECA application with a power off/on cycle after all functional safety events. Handling to be agreed with Traton. |
| CR-SYS-0081 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19R32R34 | If higher resolution is required for the supplier to properly troubleshoot any individual occurrence, then the ECA is responsible for storing these parameters internally. |
| CR-SYS-0082 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | Internally stored parameters may be accessible only using supplier defined tools . |
| CR-SYS-0083 | — | SYS | Design constraint | Low | COMPLIANT | — | The supplier shall also ensure that systems are in place that ensure that data corruption is handled without loss of data, or loss of function. |
| CR-SYS-0084 | 7.1 | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R21 | The electrical design must ensure that an internal short circuit through one of H -bridges (“shoot through”) is avoided. |
| CR-HW-0012 | 7.3 | HW | Design constraint | Low | NON-COMPLIANT | R1R2R5 | A safe boot sequence must be set to prevent unwanted or undefined behavior during or after loss of power, or corruption of stored data. |
| CR-FUSA-0002 | 7.4 | FUSA | Functional | Medium | NON-COMPLIANT | R1R2R5R17R20R21 | A safe memory read/write sequence must also be implemented during actuator movement, in order to ensure safe and predictable behavior during operation, or in case of power lo ss. Relates to Safety Goals set in PD3339794 (Ref 14.16). |
| CR-HW-0013 | 7.5 | HW | Design constraint | Low | NON-COMPLIANT | R18R26R32 | All external electrical connectors shall be geometrically coded. If internal components are included in repair kits, the internal electrical connectors shall also be geometrically coded. |
| CR-HW-0014 | — | HW | Design constraint | Low | NON-COMPLIANT | R2 | 7.2 Short circuit protection shall be implemented by hardware. |
| CR-HW-0015 | — | HW | Design constraint | Low | COMPLIANT | — | If internal components are included in repair kits, the internal electrical connectors shall also be geometrically coded. |
| CR-HW-0016 | — | HW | Design constraint | Low | NON-COMPLIANT | R18R21 | 7.8 ECU tab headers shall comply with TB1787.(Ref 14.6) 7.9 ECU tab headers shall be made of self-extinguishing materials (i.e. |
| CR-HW-0017 | 7.12 | HW | Design constraint | Low | NON-COMPLIANT | R19R26R32 | The ECA can be connected to the battery+ (30) permanently through the system fuse or through a master switch that physically cuts off power. All power used by the ECA shall be taken from this battery connection. |
| CR-MECH-0033 | 7.13 | MECH | Design constraint | Low | NON-COMPLIANT | R16R19 | The ECA is connected directly to the battery GND (31). This ground connection will act as system ground and reference for the entire ECA. The ground shall not be DC connected to the ECA housing. Requirements Power cable dimension: Operating parameters Remark Min Typ. Max. Unit |
| CR-SYS-0085 | 7.18 | SYS | Functional | Low | NON-COMPLIANT | R1R2R19 | CVS41 limits may go below this value. Valid only for ECU and communication function. For clutch actuation see req. 5.13 |
| CR-HW-0018 | — | HW | Design constraint | Low | NON-COMPLIANT | R26R32 | All power used by the ECA shall be taken from this battery connection. |
| CR-MECH-0034 | — | MECH | Design constraint | Low | NON-COMPLIANT | R16 | The ground shall not be DC connected to the ECA housing. |
| CR-HW-0019 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R21 | 7.23 Quiescent current: According to CVS41 (Ref 14.2), must be met independent of input and output conditions. |
| CR-HW-0020 | — | HW | Design constraint | Low | NON-COMPLIANT | R24 | It shall be used to control the power up sequence to the µP. |
| CR-SYS-0086 | — | SYS | Design constraint | Low | COMPLIANT | — | The Wake-up signal shall also be connected to a digital input on the µP. |
| CR-SYS-0087 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Special precautions shall be taken to prevent direct connection between Wake-up and 30 in case of a single failure. |
| CR-SYS-0088 | — | SYS | Functional | Low | NON-COMPLIANT | R18R35 | After the wake-up line goes to high state: The ECA shall communicate on the CAN line within 250ms in case of a normal start -up The ECA shall be ready to open the clutch within 350ms in case of a normal start -up The ECA shall be ready to open the clutch as soon as possible after necessary movements in case of an abnormal start-up. |
| CR-SYS-0089 | — | SYS | Functional | Low | NON-COMPLIANT | R18 | After movement and reset, the ECA shall communicate on the CAN line within 250ms After movement and reset, the ECA shall be ready to open the clutch within 400ms In the case if the wake-up goes "high" at the same time as U30 signal the ECA should be ready to open the clutch within 3 seconds. |
| CR-SYS-0090 | — | SYS | Functional | Low | NON-COMPLIANT | R10R19 | Definition ready to open clutch: The actuator position shall be between FCCP and FCCP -3mm and the ECA is capable to move to disengaged clutch directly when requeste d. |
| CR-SYS-0091 | — | SYS | Design constraint | Low | COMPLIANT | — | Redundancies due improper shutdown shall be aligned with Traton. |
| CR-SYS-0092 | — | SYS | Functional | Low | COMPLIANT | — | If a signal for disengaging the clutch is received the ECA shall actuate the request regardless of CAN-request. |
| CR-SYS-0093 | 7.34 | SYS | Design constraint | Low | NON-COMPLIANT | R18R21R32 | The ECA has one CAN bus. Any watchdog circuit shall have no influence on the CAN bus The CAN front end shall be designed to comply with TB1905 (Ref 14.3), with the following additional information in this chapter. |
| CR-SYS-0094 | 7.35 | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The controller and transceiver shall be CAN FD ready Parameter Limit values Unit Remarks Min. Typ. Max. |
| CR-SYS-0095 | — | SYS | Design constraint | Low | NON-COMPLIANT | R32 | Any watchdog circuit shall have no influence on the CAN bus. |
| CR-SYS-0096 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The CAN front end shall be designed to comply with TB1905 (Ref 14.3), with the following additional information in this chapter. |
| CR-SW-0010 | — | SW | Design constraint | Low | NON-COMPLIANT | R17R18 | 7.36 Termination resistance: - 2 x 60 - Ω 1% resistors shall be used 7.37 Baud rate: 250 500 1000 kbit/s Flashing in production shall be possible with 1000kbit/s. |
| CR-SYS-0097 | 7.39 | SYS | Design constraint | Low | NON-COMPLIANT | R7R17R19R26 | The layout shall always be present on the PCB and the supplier must be flexible in changing/removing the CAN related components in this section. |
| CR-SYS-0098 | 7.40 | SYS | Design constraint | Low | NON-COMPLIANT | R16R18R19R21 | CAN shield. Footprint prepared for internal connection to system ground 31_ECA via a resistor and a capacitor in series. The components shall not be populated by default. The CAN front end shall be designed to comply with TB1905. (Ref 14.3) |
| CR-SYS-0099 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | The components shall not be populated by default. |
| CR-SYS-0100 | — | SYS | Design constraint | Low | COMPLIANT | — | The CAN front end shall be designed to comply with TB1905. |
| CR-SYS-0101 | 7.45 | SYS | Design constraint | Low | NON-COMPLIANT | R18R20 | The air inside the electronics enclosure shall be ventilated with the use of a membrane. The following requirements shall be fulfilled: The unit shall withstand the salt-spray environment, according to CVS40 §6.1.6, without clogging of the membrane. The membrane shall be placed so that it is protected against blunt force, falling dust and dripping salt-water. The design shall be made to prevent accumulation of water on top of the membrane, or in the cavity of the membrane. |
| CR-SYS-0102 | — | SYS | Functional | Low | NON-COMPLIANT | R19 | The quality of the wire bonding and position shall be properly analyzed. |
| CR-HW-0021 | — | HW | Design constraint | Low | NON-COMPLIANT | R19 | The material shall be lead free and of ”high temperatures solder type”. |
| CR-SYS-0103 | — | SYS | Functional | Low | NON-COMPLIANT | R2R19 | The melting point of the soldering material and the composition of the soldering material shall be declared by supplier. |
| CR-VAL-0013 | — | VAL | Design constraint | Low | NON-COMPLIANT | R1R2R16R19R32 | The PCB must be supported and must not bent in any direction during the process. |
| CR-SYS-0104 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R26R32 | Conformal coating or lacquer shall cover the entire PCB and all solder joints. |
| CR-SYS-0105 | — | SYS | Design constraint | Low | NON-COMPLIANT | R20 | The layout of the PCB, including component placement, shall take the applying of conformal coating into consideration so that the aforementioned requirement can be met. |
| CR-SYS-0106 | — | SYS | Design constraint | Low | COMPLIANT | — | shall be specified in the initial offer. |
| CR-VAL-0014 | — | VAL | Design constraint | Low | NON-COMPLIANT | R17R19 | The conformal coating process and materials shall apply to the latest versions of IPC/EIA J-STD-001 (with applicable standards as e.g. |
| CR-SYS-0107 | — | SYS | Design constraint | Low | COMPLIANT | — | HDBK-001, IPC-CC-830 and HDBK-830) and the visual appearance of the final coating shall be consistent with the latest version of IPC-A-610. |
| CR-SYS-0108 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R19 | Water based and silicone lacquers shall not be used. |
| CR-SYS-0109 | — | SYS | Design constraint | Low | NON-COMPLIANT | R18 | The following requirements shall be fulfilled: The unit shall withstand the salt-spray environment, according to CVS40 §6.1.6, without clogging of the membrane. |
| CR-SYS-0110 | — | SYS | Design constraint | Low | NON-COMPLIANT | R20 | The membrane shall be placed so that it is protected against blunt force, falling dust and dripping salt-water. |
| CR-SYS-0111 | — | SYS | Design constraint | Low | COMPLIANT | — | The design shall be made to prevent accumulation of water on top of the membrane, or in the cavity of the membrane. |
| CR-SYS-0112 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R16R32 | 7.46 Forbidden components: BGA capsule in any form must not be used. |
| CR-HW-0022 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R16 | Tantalum capacitors must not be used Serial resistors on power supply circuits must not be used. |
| CR-SYS-0113 | 8.3 | SYS | Functional | Low | COMPLIANT | — | The clutch actuator shall withstand 6 500 000 actuations with the test cycle described in Appendix B. |
| CR-SYS-0114 | 8.5 | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | The ECA must be maintenance free over the whole life time |
| CR-SYS-0115 | 8.8 | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The maintenance window cover (See req. 4.17) shall be provided as a spare part |
| CR-SYS-0116 | 8.9 | SYS | Functional | Low | COMPLIANT | — | In a situation where the ECA has jammed, and is holding the clutch open, it shall be possible to remove the clutch force by following an instruction documented on the ECA drawing. It is allowed to destroy the ECA in the process. |
| CR-SYS-0117 | — | SYS | Functional | Low | COMPLIANT | — | 8.4 Six consecutive units shall run past 6.5M actuations at the supplier, and continue to end of life. |
| CR-SYS-0118 | — | SYS | Functional | Low | COMPLIANT | — | Three consecutive units shall run past 6.5M actuations at Scania, and continue to end of life. |
| CR-HW-0023 | — | HW | Design constraint | Low | NON-COMPLIANT | R17R19R34 | 8.6 Failure rate for ECU and electronics shall be less than: 0ppm @ “0” km 200ppm/year during year 1-5 400ppm/year during year 6-10 1000ppm/year during year 11-15 8.7 External vulnerable components might need to be replaceable. |
| CR-SYS-0119 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Spare parts or repair kits shall be defined together in agreement. |
| CR-SYS-0120 | — | SYS | Design constraint | Low | COMPLIANT | — | 4.17) shall be provided as a spare part. |
| CR-MECH-0035 | 9.1 | MECH | Design constraint | Low | NON-COMPLIANT | R7R16R18R19R21 | The ECA shall fulfil the requirements stated in STD3868 STD3868 is a comprehensive document referring to several underlying standards. Out of a recycling and environmental perspective the following standards shall be taken under consideration in addition to CVS55(Ref 14.32): STD4158, Chemical substances which shall not be used – Scania Black list. STD4159, Chemical substances with limited use – Scania Grey list. CVS 83, Material declaration according to Scania IMDS reporting std. The different parts of the housing shall be marked according to material content. The ECA shall be lead free. |
| CR-SYS-0121 | 9.2 | SYS | Design constraint | Medium | NON-COMPLIANT | R17R18R26R32 | All included parts shall fulfil applicable sections of Part 9 in Annex B to the latest ADR ,as applicable at the time of type approval. For type approval, the vehicle and its components shall comply with ECE Regulation No. 105 and with European Directive 2008/68/EC, as amended. |
| CR-HW-0024 | — | HW | Design constraint | Low | NON-COMPLIANT | R16R18R19R21 | Out of a recycling and environmental perspective the following standards shall be taken under consideration in addition to CVS55(Ref 14.32): STD4158, Chemical substances which shall not be used – Scania Black list. |
| CR-MECH-0036 | — | MECH | Design constraint | Low | COMPLIANT | — | The different parts of the housing shall be marked according to material content. |
| CR-SYS-0122 | — | SYS | Design constraint | Low | COMPLIANT | — | The ECA shall be lead free. |
| CR-SYS-0123 | — | SYS | Design constraint | Low | COMPLIANT | — | For type approval, the vehicle and its components shall comply with ECE Regulation No. |
| CR-SYS-0124 | 10.1 | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R21 | The ECA must fulfil the general requirements for Electronic Control Units (ECUs), which are stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2). |
| CR-SYS-0125 | 10.2 | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R16R19R21 | The ECA must not be dependent on software for protection against requirements stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2). |
| CR-SYS-0126 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | CAN communication shall not be affected. |
| CR-HW-0025 | — | HW | Design constraint | Low | COMPLIANT | — | Memory functions shall remain Class A. |
| CR-SYS-0127 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Accepted behaviour in this case shall be agreed upon between Traton and Supplier. |
| CR-MECH-0037 | 10.4 | MECH | Design constraint | Low | NON-COMPLIANT | R18R21R26R32R34 | For this unit, the following definitions of test procedure I and test procedure II shall be used Test procedure I A comprehensive test where all functional requirements are verified. This test shall be performed before and after exposure. Test procedure I (See Figure 17 - Test procedure I) shall at least contain: - Full stroke to evaluate speed - Staircase to evaluate accuracy - Power loss to evaluate safety Figure 17 - Test procedure I Test procedure II A reduced function test where the fundamental requirements are verified. This test shall be possible to perform during exposure. Reduced versions of test procedure II may be agreed and used during various tests. Alternative 1: Test cycle according to Appendix B, frequency 10 to 30 strokes per minute. Alternative 2: Release frequency test according to req. 5.12. |
| CR-SYS-0128 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R24 | This test shall be performed before and after exposure. |
| CR-MECH-0038 | — | MECH | Design constraint | Medium | NON-COMPLIANT | R21R34 | Test procedure I (See Figure 17 - Test procedure I) shall at least contain: - Full stroke to evaluate speed - Staircase to evaluate accuracy - Power loss to evaluate safety Figure 17 - Test procedure I Test procedure II A reduced function test where the fundamental requirements are verified. |
| CR-SYS-0129 | — | SYS | Design constraint | Low | NON-COMPLIANT | R24 | This test shall be possible to perform during exposure. |
| CR-SYS-0130 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19 | Reduced versions of test procedure II may be agreed and used during various tests. |
| CR-MECH-0039 | 10.5.16 | MECH | Design constraint | Low | COMPLIANT | — | CVS40 §5.10 TC-10 Ingress protection The ECA shall also fulfil IP54 without mounted connectors. IP classes to test: IP6K6K, IP6K7, and IP6K9K Y |
| CR-SYS-0131 | 10.5.33 | SYS | Design constraint | Low | NON-COMPLIANT | R20R21R32 | CVS40 §8.1 TS-01 Flammability In order to fulfil flammability demands, any plastic materials (i.e. tab headers) shall be made of self- extinguishing materials (i.e. UL94). Y |
| CR-SYS-0132 | — | SYS | Design constraint | Low | COMPLIANT | — | tab headers) shall be made of self- extinguishing materials (i.e. |
| CR-SYS-0133 | 10.7.27 | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R32 | CVS46 §5.1 Vehicle test ESD Traton performs Vehicle test, Traton may need support from supplier with any issues originating from the component. Y |
| CR-SYS-0134 | 10.7.34 | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | CVS46 §5.4 Vehicle test RI: Immunity of vehicles to radiated fields Traton performs Vehicle test, Traton may need support from supplier with Y |
| CR-FUSA-0003 | — | FUSA | Functional | High | NON-COMPLIANT | R19 | P 1 Page 11 Functional safety The ECA is a part of a safety critical system and shall be handled as such. |
| CR-FUSA-0004 | — | FUSA | Functional | High | NON-COMPLIANT | R19 | The ECA shall therefore be developed and implemented in accordance with the objectives and requirements of ISO 26262 "Road vehicles - Functional Safety". |
| CR-CYBER-0035 | — | CYBER | Design constraint | High | NON-COMPLIANT | R32 | The supplier shall analyse risks of individua l HW and SW components, mechanics, and any other technologies, independently of the scope of ISO 26262. |
| CR-SYS-0135 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | For this purpose possible causes must be systematically identified. |
| CR-FUSA-0005 | — | FUSA | Functional | High | NON-COMPLIANT | R34 | For these analyses at least the methods in ISO 26262 shall be applied. |
| CR-SYS-0136 | 12.3 | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R32 | The supplier of the unit must write software to enable his own testing of the unit during development, production and on any claimed unit. |
| CR-SYS-0137 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R17R19R26R32 | ID Verification methods 12.1 Conformance to Requirement Specification A1 The supplier must do conformance test of all external and internal I/O. |
| CR-SYS-0138 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R17R19R24R26R32 | This test must verify that all internal and external I/O fulfils the requirements in this specification. |
| CR-HW-0026 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R19R21 | A2 The supplier must perform full DV (Design Verification at B-sample level) and full PV (Product Validation at C-sample level) environmental test programs according to CVS40 and CVS41 (incl. |
| CR-SYS-0139 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | the suppler must carry out two full test rounds according to the Traton test requirements. |
| CR-SYS-0140 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19 | Additional tests initiated and performed by the supplier must be discussed with Traton. |
| CR-HW-0027 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2 | A3 The supplier must test the connectors according to TB1787. |
| CR-SYS-0141 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | A4 The supplier must do EMC tests with the unit alone. |
| CR-SYS-0142 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R21R26R32 | The supplier must certify the ECA according to UN ECE R10 (EMC), according to the latest revision with all amendments. |
| CR-SYS-0143 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R7R19R32 | A5 The supplier must check that both prototypes and serial units fulfil the dimension requirement according to any relevant Traton supplied drawings. |
| CR-SYS-0144 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R26R32 | A6 All prototypes and serial ECA’s shall fulfil requirements according to TB1822, IPC/EIA J-STD-001 class 3 and IPC-A-610 class 3. |
| CR-SYS-0145 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R7R19 | However, dividing sample phases into several generations must be agreed upon between Traton and the supplier. |
| CR-SYS-0146 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | All samples shall be functionally tested before sent to Traton. |
| CR-SYS-0147 | — | SYS | Design constraint | Low | COMPLIANT | — | Deviations shall be reported as a part of the sample delivery. |
| CR-SYS-0148 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Dimensional checks shall be performed for B and C-samples prior to delivery to Traton. |
| CR-SYS-0149 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | The supplier must use the sample denominations requested by Traton. |
| CR-SYS-0150 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19 | Unless otherwise stated, valid version is the latest available as of 1st May 2026. |
| CR-SYS-0151 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17 | P 1 Page Appendix B – Life length test The life time testing of the ECA shall consist of 6500000 repetitions of the test cycle described in ”I – Test cycle” Two different test profiles/setups can be used. |
| CR-SYS-0152 | — | SYS | Functional | Low | NON-COMPLIANT | R1R2R26 | Between the two movements the actuator should remain in the fully disengaged position. |
| CR-SYS-0153 | — | SYS | Functional | Low | NON-COMPLIANT | R1R2 | After the complete engagement the actuator should remain in this position until the next disengagement is requested. |
| CR-SYS-0154 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R18R19 | • A function test rig shall be used for function tests between intervals • At 6.25M cycles a function test at -40C as well as the release frequency test is performed, before the rigs are put into run-to-failure mode • Run-to-failure mode implies cycling at intermediate load and RT/80C until failure • @Temp durability will start with 15/min frequency to verify if 30/min is feasible • One rig at RT shall run at 15/min as a reference unit for cycle acceleration. |
| CR-SW-0011 | — | SW | Design constraint | Low | NON-COMPLIANT | R1R2R19R21R32 | TRATON Software Update Variant 2 (SUV2) sequence Foreword This Commercial Vehicle Standard (“CVS123-2”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates. |
| CR-SYS-0155 | — | SYS | Design constraint | Low | COMPLIANT | — | The User shall apply the latest version of this CVS123-2. |
| CR-SW-0012 | — | SW | Functional | High | NON-COMPLIANT | R1R2R19 | The reason to why an ECU must implement two or more diagnostic servers is that it needs to support two or more different ECU configurations: one for which no application is installed and one or more for which applications are installed in the ECU. |
| CR-SYS-0156 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R16R19R24R26 | It should be noted that a single server view is not completely achievable and that clients still need to be aware of two physical servers. |
| CR-SYS-0157 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19 | Clients may prefer to implement programming support using other service parameter values or even another set of programming steps than |
| CR-SYS-0158 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | For this reason, only the server is required to support the specified sequence. |
| CR-SYS-0159 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R24 | It must be clearly separated from the application software. |
| CR-SYS-0160 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | For this reason, it is located in a separate memory area and must also be erasable and programmable independently of the application software. |
| CR-SYS-0161 | — | SYS | Design constraint | Low | COMPLIANT | — | shall be implemented in the boot software code. |
| CR-HW-0028 | — | HW | Design constraint | Low | NON-COMPLIANT | R19 | Satisfied programming precondition A programming precondition agreed between supplier and vehicle manufacturer which, together with other agreed programming preconditions, shall be fulfilled before an ECU is made eligible for programming. |
| CR-SW-0013 | — | SW | Functional | High | NON-COMPLIANT | R21 | The implementation of the client and the server shall be compliant with (ISO14229-1:2020) and the Traton Specification on Unified diagnostic Service (UDS) requirements (CVS124) with the clarifications, extensions and exceptions stated in this specification. |
| CR-SYS-0162 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R21 | Requirements in (CVS124) which are not explicitly stated to apply to the application only (such as communication parameters) shall apply to the boot loader as well. |
| CR-SYS-0163 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | All deviations from this specification shall be agreed with the applicable vehicle manufacturer(s). |
| CR-SYS-0164 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R21R26R32 | The programming requirements in this specification shall apply to the programming of all kinds of software modules (application, application data and boot loader), unless explicitly otherwise stated. |
| CR-SW-0014 | — | SW | Design constraint | Low | NON-COMPLIANT | R5R16 | an ECU will not support boot loader reprogramming, the boot loader SW shall be in a protected area of the memory. |
| CR-SYS-0165 | — | SYS | Design constraint | Low | NON-COMPLIANT | R5R19 | A SW or HW protection mechanism shall be used to protect the software from being accidentally erased or overwritten. |
| CR-SYS-0166 | — | SYS | Design constraint | Low | COMPLIANT | — | If the microcontroller supports HW protection, this shall be used. |
| CR-SYS-0167 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R26R32 | The server shall support programming of all application software and application data modules and any subset of such modules in a single sequence without any intermediate reset service requests. |
| CR-SW-0015 | — | SW | Design constraint | Low | NON-COMPLIANT | R16R19 | Programming of a subset of modules may lead to that the consistency check at the end of a programming sequence fails but shall not lead to that those programmed modules need to be reprogrammed from the beginning. |
| CR-SYS-0168 | — | SYS | Design constraint | Low | COMPLIANT | — | Boot loader updating according to this specification shall be supported during development, from A-samples and onwards. |
| CR-SW-0016 | — | SW | Functional | Low | NON-COMPLIANT | R5R16R19R21 | A server shall be programmable according to this specification (i.e., not only using supplier tools) regardless of whether one or more DTCs are currently active, or one or more functions are currently degraded. |
| CR-SW-0017 | — | SW | Functional | Medium | NON-COMPLIANT | R5R19 | A server shall be programmable while integrated in the vehicle network and as a standalone server without further conditions and without further interventions by the diagnostic tester as per this specification. |
| CR-SW-0018 | — | SW | Design constraint | Medium | NON-COMPLIANT | R9R17R21 | The solution for maintaining/reorganizing data (EEPROM data, operational data, adaptive data etc.) before and after reprogramming of software modules shall be discussed and agreed with the vehicle manufacturer. |
| CR-SYS-0169 | — | SYS | Design constraint | Low | COMPLIANT | — | The supplier shall provide, for each committed software delivery, a document that describes the programming procedure together with any requirement exceptions and ECU specific behaviours. |
| CR-SYS-0170 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | Normal and worst-case performance values shall be documented for: • Total time for the programming sequence (programming steps prefixed “P1Pro”, see section Programming step of phase #1 – Download of application software and data). |
| CR-SYS-0171 | — | SYS | Design constraint | Low | COMPLIANT | — | The supplier shall document the versioning concept for supplier specific DIDs. |
| CR-SW-0019 | — | SW | Functional | Medium | NON-COMPLIANT | R21 | System name (DID 0xF197), diagnostic address and bitrate shall be persisted in an application data module dedicated for boot parameters, referred to as “boot parameter module”. |
| CR-SYS-0172 | — | SYS | Design constraint | Low | COMPLIANT | — | When this module is programmed the parameter values in it shall override default parameter values persisted in the boot loader software module. |
| CR-HW-0029 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R7R17R24 | It should be possible to reuse the generic bootloader for future currently unknown purposes/applications without a need to create a new part number for the platform. |
| CR-SW-0020 | — | SW | Functional | Medium | NON-COMPLIANT | R16R17R21 | When the boot loader software in an ECU has not yet been parameterized (a boot parameter module has not been programmed) the boot loader software shall apply project specific default values, typically: • diagnostic address 0xA7 • baud rate 500 kb/s • DID 0xF197 |
| CR-SYS-0173 | — | SYS | Design constraint | Low | COMPLIANT | — | Default values for EOL parameters shall be implemented in a dedicated application data module, referred to as “EOL parameters module”. |
| CR-SYS-0174 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The partitioning of the ECU software into modules shall be discussed and agreed with the vehicle manufacturer. |
| CR-CYBER-0036 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R5 | A software released for integration test, production or service market shall be hashed so its integrity can be verified by the server. |
| CR-SYS-0175 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26 | Flash files delivered from the supplier shall never have to be modified by the vehicle manufacturer. |
| CR-CYBER-0037 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The supplier shall deliver the necessary information to verify the integrity of the flash files. |
| CR-CYBER-0038 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2 | In case the supplier delivers encrypted flash files to the vehicle manufacturer, the supplier should also provide the necessary information so the flash files can be verified as part of flash files update procedure. |
| CR-SYS-0176 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R18R19 | Whether or not the ECU shall be delivered from the supplier to the vehicle manufacturer with a pre-programmed application and pre-programmed application data shall be discussed and agreed with the vehicle manufacturer. |
| CR-SYS-0177 | — | SYS | Design constraint | Low | NON-COMPLIANT | R10R19R32 | Regardless of if the ECU will be delivered from the supplier with a pre-programmed application and application data, the corresponding flash files shall be possible to request by vehicle manufacturer to be able to perform software verification at any time in vehicle manufacturer production site. |
| CR-SW-0021 | — | SW | Functional | Low | COMPLIANT | — | When the application module is pre-programmed by the supplier, ECU and software identifiers 0xF187 and 0xF188 shall be set to product specific vehicle manufacturer defined values. |
| CR-SW-0022 | — | SW | Functional | Low | NON-COMPLIANT | R19 | Otherwise 0xF187 and 0xF188 shall be set to default values, see CVS124. |
| CR-SYS-0178 | — | SYS | Design constraint | Low | COMPLIANT | — | Programmable servers shall support the full programming sequence described in this chapter. |
| CR-SYS-0179 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R21 | Non-programmable servers shall support the pre-programming and post-programming steps of the programming sequence described in this chapter (phase 1 and 2). |
| CR-SYS-0180 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The programming sequence described in this chapter shall be supported when a valid application is present as well as when no valid application is present in the ECU. |
| CR-SYS-0181 | — | SYS | Design constraint | Low | COMPLIANT | — | The full set of addressing modes, SPRMIB values and other parameter values that the server shall support for each service are specified with implementation requirements in CVS124. |
| CR-SW-0023 | — | SW | Functional | Low | COMPLIANT | — | To enable access to diagnostic services in the programming sequence, an authentication sequence shall be performed between the client and the server by means of the Authentication 0x29 service. |
| CR-SW-0024 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The server shall receive a diagnostic service authentication (0x29) with SubFunction deAuthenticate (0x00) message from the client to disable authorized access to diagnostic programming services after an update is considered fulfilled. |
| CR-CYBER-0039 | — | CYBER | Design constraint | High | NON-COMPLIANT | R1R2R7R17 | As example, the client may read certificate validity time and/or RBAC configuration file to verify if the appropriate entities are stored in the server. |
| CR-CYBER-0040 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R1R2R7 | As example, the client may have identified that the RBAC configuration file requires update and perform the appropriate set to update the entities stored in the server. |
| CR-SW-0025 | — | SW | Design constraint | Low | NON-COMPLIANT | R1R2R26 | Alternatively, it may be a client strategy to always update certain entities prior to a software update. |
| CR-SW-0026 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R21 | Since Link Control is only applicable in production when no application has been programmed by the supplier, the application may return NRC 0x7F (serviceNotSupportedInActiveSession) to this service request and expect the client to proceed to the next step. |
| CR-SW-0027 | — | SW | Functional | Medium | NON-COMPLIANT | R7R10R21 | For the server to verify the integrity of the software, the information to verify shall be available to the server before step P1Pro6: Routine Control (erase Memory). |
| CR-CYBER-0041 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R10 | If the SW to be updated is encrypted, decryption keys shall be available to the server before step P1Pro9. |
| CR-SYS-0182 | — | SYS | Design constraint | Low | COMPLIANT | — | Before the server executes the TransferData service, the server shall check if the data received during RequestDownload requests needs to be decrypted before writing the received data to non-volatile memory. |
| CR-CYBER-0042 | — | CYBER | Design constraint | High | NON-COMPLIANT | R1R2R16 | Implementation hint: The integrity information may contain parts of memory not programmed, regardless of this the server verifies the integrity according to the supplied information on SDSC, see 9. |
| CR-SYS-0183 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | If the application was started, it checks if application initialization is required. |
| CR-HW-0030 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R9R17R21 | If so, the server performs the required checks/reorganization measures for the data structures (EEPROM data, operational data, adaptive data etc.), executes the self-test and stores event memory entries, default values, DIDs F1AB, F1AA, F1A9 etc. |
| CR-SW-0028 | — | SW | Design constraint | Low | NON-COMPLIANT | R1R2R21 | Implementation hint: The ECU application checks the reprogrammed flag (C3, see programming step P1Pro11) to see if application initialization is required. |
| CR-CYBER-0043 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R1R2 | As example, the client may have identified that the new software requires an updated RBAC configuration file and therefore set the entity on the server via EMP. |
| CR-SYS-0184 | — | SYS | Design constraint | Low | COMPLIANT | — | ECUs that will be programmed stand-alone at the vehicle manufacturer over DoCAN shall support 1 Mbit transfer speed. |
| CR-HW-0031 | — | HW | Design constraint | Low | NON-COMPLIANT | R16R18R19 | Whether or not the ECU shall support stand-alone programming at the vehicle manufacturer premises shall be discussed and agreed with the vehicle manufacturer. |
| CR-SW-0029 | — | SW | Functional | Medium | NON-COMPLIANT | R5 | A server that is running in the application shall respond with the same diagnostic address after a switch to boot. |
| CR-HW-0032 | — | HW | Design constraint | Low | NON-COMPLIANT | R19R24 | It shall be possible to downgrade server software modules as long as the programmed modules are compatible with each other and with the hardware configuration. |
| CR-SYS-0185 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R32 | Application software and application data modules shall be programmable in any order. |
| CR-SYS-0186 | — | SYS | Design constraint | Low | NON-COMPLIANT | R10R32 | The server shall be able to update an individual module independently from any other module. |
| CR-SYS-0187 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | cannot be met, a compression method shall be implemented. |
| CR-SYS-0188 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R19 | The LZSS algorithm with a dictionary size of 1 023 bytes or a newer compression/decompression method with a higher compression ratio shall be used as the compression/decompression algorithm. |
| CR-SYS-0189 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17 | The use of alternative compression/decompression algorithms shall be agreed with the vehicle manufacturer. |
| CR-SYS-0190 | — | SYS | Design constraint | Low | NON-COMPLIANT | R24 | It shall be possible to program the same software version repeatedly. |
| CR-HW-0033 | — | HW | Design constraint | Low | NON-COMPLIANT | R16R17 | If at startup the ECU hardware/software is consistent and a programming request is not pending, the boot manager shall start and execute the application. |
| CR-SW-0030 | — | SW | Functional | Low | NON-COMPLIANT | R17R19 | Otherwise if at startup the ECU hardware/software is inconsistent the boot manager shall start and execute the boot loader and reset DIDs 0xF181, 0xF187 and 0xF188 and 0xF1A1 to default values. |
| CR-SYS-0191 | — | SYS | Design constraint | Low | COMPLIANT | — | If at startup the boot manager starts and executes the application, the application shall read and apply the parameter values persisted in the boot parameter module. |
| CR-SYS-0192 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Otherwise if at startup the boot manager starts and executes the boot loader and a valid boot parameter module has been successfully programmed, the boot loader shall read and apply these parameter values from the boot parameter module. |
| CR-SYS-0193 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Otherwise if no boot parameter module has been successfully programmed, the boot loader shall apply the corresponding parameter values persisted in the boot loader module. |
| CR-SW-0031 | — | SW | Design constraint | Low | COMPLIANT | — | After reprogramming, the application shall store DIDs F1AB, F1AA, F1A9. |
| CR-SYS-0194 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The technical implementation of the programming preconditions shall be agreed between the supplier and the vehicle manufacturer. |
| CR-HW-0034 | — | HW | Design constraint | Low | NON-COMPLIANT | R5R19 | A programmable server shall guarantee re-programmability within the normal operating voltage range specified by [11] for 24V systems or [12] for 12V systems. |
| CR-SYS-0195 | — | SYS | Design constraint | Low | NON-COMPLIANT | R5R16R18R19R21R26R32 | A server that is restarted for any reason or thrown back to DefaultSession due to lack of TesterPresent or unfulfilled preconditions shall always support programming from the start of the programming sequence (programming step P1Pre), i.e., shall not depend on any state from an interrupted programming sequence. |
| CR-VAL-0015 | — | VAL | Design constraint | Low | COMPLIANT | — | The server shall guarantee re-programmability in the event of error conditions during the programming process regardless of cause. |
| CR-SW-0032 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The causes specified in (ISO14229-1:2020) shall be regarded as examples. |
| CR-SYS-0196 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R21 | The server shall be re-programmable (standalone and in the vehicle) regardless of whether the application and application data is valid or has been corrupted. |
| CR-SW-0033 | — | SW | Functional | Medium | COMPLIANT | — | Diagnostic services support shall be as per CVS124. |
| CR-CYBER-0044 | — | CYBER | Design constraint | Low | COMPLIANT | — | ECU identification data support shall be as per CVS124. |
| CR-SYS-0197 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R17R19R21R26R32R34 | When programmed in the vehicle manufacturer’s production facility the total time for programming of all modules shall not exceed 90 seconds with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2). |
| CR-SW-0034 | — | SW | Design constraint | Low | NON-COMPLIANT | R1R2R16R24R26R32 | This does not apply to ECUs for which all software modules are pre-programmed in supplier premises, even if a software update capability is required in vehicle manufacturer production premises, e.g., for bug fixing. |
| CR-SYS-0198 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R17R19R21R26R32R34 | When programmed in the workshop the total time for programming of all modules shall not exceed 10 minutes with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2). |
| CR-SW-0035 | — | SW | Functional | Low | NON-COMPLIANT | R7 | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request. |
| CR-HW-0035 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R20 | In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint. |
| CR-SW-0036 | — | SW | Functional | Low | NON-COMPLIANT | R7R21 | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules). |
| CR-SW-0037 | — | SW | Functional | Low | NON-COMPLIANT | R32 | Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error. |
| CR-SW-0038 | — | SW | Functional | Low | NON-COMPLIANT | R19 | If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x24 |
| CR-SYS-0199 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R21 | (requestSequenceError) and shall accept programming to proceed from the state at which it was executing before this non-permitted service was requested. |
| CR-SYS-0200 | — | SYS | Design constraint | Low | COMPLIANT | — | For each received RequestDownload request, the server shall check if there is a VerificationEntry match in SDSC. |
| CR-CYBER-0045 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R16R19R32 | The server shall check whether any part of the received data is encrypted or not by checking the address ranges for a match in EncryptionEntry defined in SDSC. |
| CR-SW-0039 | — | SW | Functional | Low | NON-COMPLIANT | R7R16 | The server shall not execute the new software until it can be verified using routine 0xFF01. |
| CR-SW-0040 | — | SW | Functional | Low | COMPLIANT | — | The server shall support service negative response as per ISO14229-1:2020. |
| CR-CYBER-0046 | — | CYBER | Design constraint | Low | COMPLIANT | — | In case a software is encrypted, the server shall decrypt the software before decompression and software hash comparison verification are performed. |
| CR-SYS-0201 | — | SYS | Design constraint | Low | COMPLIANT | — | In case a software is compressed, the server shall decompress the software before software hash comparison verification is performed. |
| CR-SYS-0202 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R19 | The server shall verify the software hash after decryption and/or decompression are performed. |
| CR-SW-0041 | — | SW | Functional | Low | COMPLIANT | — | The server shall support request formatted according to ISO14229-1:2020. |
| CR-SW-0042 | — | SW | Functional | Low | COMPLIANT | — | The server shall support positive response formatted according to ISO14229-1:2020. |
| CR-SW-0043 | — | SW | Functional | Low | NON-COMPLIANT | R32 | If for any reason an error occurs during decryption of data, the server shall return NRC 0x10. |
| CR-SW-0044 | — | SW | Functional | Low | COMPLIANT | — | The server shall support parameter blockSequenceCounter formatted according to ISO14229-1:2020. |
| CR-SW-0045 | — | SW | Functional | Low | COMPLIANT | — | The server shall support parameter transferRequestParameterRecord formatted according to ISO14229-1:2020. |
| CR-SYS-0203 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | The server shall not support transferRequestParameterRecord parameter. |
| CR-SYS-0204 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | The server shall not support transferResponseParameterRecord parameter. |
| CR-SW-0046 | — | SW | Functional | Low | COMPLIANT | — | The server shall support service 0x84 according to CVS32. |
| CR-SW-0047 | — | SW | Functional | Low | COMPLIANT | — | The server shall support request formatted according to ISO14229-1:2020. |
| CR-SW-0048 | — | SW | Functional | Low | COMPLIANT | — | The server shall support positive response formatted according to ISO14229-1:2020. |
| CR-SYS-0205 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support negative response codes according to CVS32. |
| CR-SW-0049 | — | SW | Functional | Low | COMPLIANT | — | The server shall support parameter Administrative Parameter formatted according to ISO14229-1:2020. |
| CR-CYBER-0047 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R17R21 | The server shall support parameter Signature/Encryption Calculation (SIGENCRYPT) according to CVS32. |
| CR-SYS-0206 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The server shall support parameter Anti-replay Counter (ANTIREPLAYCNT) according to CVS32. |
| CR-SYS-0207 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall verify the programmed software module by calculating a checksum on the programmed data by matching this checksum with a pre-calculated checksum. |
| CR-SYS-0208 | — | SYS | Design constraint | Low | COMPLIANT | — | The pre-calculated checksum shall be provided as part of the data submitted with the TransferData service request. |
| CR-SYS-0209 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R21R26 | The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested. |
| CR-HW-0036 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R20 | In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint. |
| CR-SW-0050 | — | SW | Design constraint | Low | NON-COMPLIANT | R16R18 | In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area. |
| CR-SW-0051 | — | SW | Functional | Low | NON-COMPLIANT | R7R21R32 | When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see section Software and data identification): • If boot software (any part) is erased, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules). |
| CR-SW-0052 | — | SW | Functional | Low | NON-COMPLIANT | R16R18R21 | The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e., the erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase. |
| CR-SW-0053 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R21 | E.g., 02, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements & |
| CR-SW-0054 | — | SW | Functional | Low | NON-COMPLIANT | R10R24 | This RoutineIdentifier shall be able to execute independent from programming sequence |
| CR-SW-0055 | — | SW | Functional | Low | NON-COMPLIANT | R1R2 | The client may opt to execute this routineIdentifier as a standalone procedure to check to perform a software consistency check. |
| CR-SYS-0210 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The server shall check whether the individual modules are complete and compatible with one another. |
| CR-SYS-0211 | — | SYS | Functional | Low | NON-COMPLIANT | R17R19R21 | In addition, a check shall be made to determine whether the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data). |
| CR-SYS-0212 | — | SYS | Design constraint | Low | NON-COMPLIANT | R2R17 | The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer. |
| CR-SYS-0213 | — | SYS | Design constraint | Low | COMPLIANT | — | The consistency check shall be carried out solely by the server. |
| CR-CYBER-0048 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The server shall verify the integrity of the software as a part of the consistency check. |
| CR-CYBER-0049 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The integrity information shall be supplied to the server before the software is updated. |
| CR-CYBER-0050 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The integrity check shall be carried out solely by the server. |
| CR-SW-0056 | — | SW | Functional | Medium | NON-COMPLIANT | R19R21 | If the server set routineResult as 0x00 (CorrectResult) the server shall reject with NRC 0x24 the following diagnostic services and routines until a new SDSC is provided |
| CR-SW-0057 | — | SW | Functional | Low | COMPLIANT | — | The server shall hash the receipt number with the routineStatus routineResult parameter, in this respective order. |
| CR-SYS-0214 | — | SYS | Design constraint | Low | COMPLIANT | — | The hash algorithm shall be SHA512. |
| CR-SYS-0215 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall sign the hashed output using the receipt-keys. |
| CR-CYBER-0051 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall use ED25519 as signature algorithm. |
| CR-SW-0058 | — | SW | Functional | Low | COMPLIANT | — | The server shall return in the parameter routineResultProof the signed hash. |
| CR-SW-0059 | — | SW | Functional | Low | COMPLIANT | — | The client shall send the Servers routineStatus routineResult response to the backend. |
| CR-SYS-0216 | — | SYS | Design constraint | Low | COMPLIANT | — | Once a SDSC has being accepted by the server, the server shall store in the NVM the receipt number sent over as part of the EMP request. |
| CR-SW-0060 | — | SW | Functional | Medium | NON-COMPLIANT | R7 | Once a SDSC has being accepted by the server, the server shall accept the following diagnostic services and routines: • Routine 0xFF00 Erase Memory |
| CR-SW-0061 | — | SW | Functional | Low | NON-COMPLIANT | R7 | The server shall support the routine negative response according to CVS33. |
| CR-SYS-0217 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support the parameter EMP message according to CVS33. |
| CR-CYBER-0052 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R1R2R19R21 | The information required for the server for verifying software integrity and optionally decrypt the transported data from a trusted source, is described in a Software Data Security Container (SDSC). |
| CR-SYS-0218 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall implement SDSC structure as defined in CVS154. |
| CR-HW-0037 | — | HW | Design constraint | Low | COMPLIANT | — | The range start field shall be the memory address offset from the dataLocator field. |
| CR-SYS-0219 | — | SYS | Design constraint | Low | COMPLIANT | — | The range length field shall be the number of bytes to be verified. |
| CR-SYS-0220 | — | SYS | Design constraint | Low | COMPLIANT | — | The supplier shall propose for each software module an identification to be used in dataLocator field in SDSC. |
| CR-VAL-0016 | — | VAL | Design constraint | Low | NON-COMPLIANT | R19R26 | The vehicle manufacturer shall review and accept the proposals for every dataLocator. |
| CR-SYS-0221 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R19 | The start address shall be used as an offset in the software module while the length can be utilized to know which areas of the software module are to be verified and/or decrypted. |
| CR-SYS-0222 | — | SYS | Design constraint | Low | COMPLIANT | — | Before accepting the SDSC as valid, the server shall perform the sanity check of the received SDSC as defined in CVS154. |
| CR-SYS-0223 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17 | If the sanity check returns fail/invalid, the server shall reject SDSC as described in CVS34. |
| CR-SYS-0224 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall validate each VerificationEntry found in the SDSC. |
| CR-SYS-0225 | — | SYS | Design constraint | Low | NON-COMPLIANT | R2 | Software hashes in the SDSC shall be verified by the server considering the ranges which are stated in the SDSC. |
| CR-SYS-0226 | — | SYS | Design constraint | Low | COMPLIANT | — | The Ranges dictates the data range that the server shall begin, and end read from NVM for hashing. |
| CR-HW-0038 | — | HW | Design constraint | Low | NON-COMPLIANT | R7R19 | The Ranges can be one or several if there are gaps between memory areas which shall be excluded from the hash calculation for some reason. |
| CR-SYS-0227 | — | SYS | Design constraint | Low | COMPLIANT | — | When hashing software, the whole memory range, including erased-only bytes of a memory module, shall be possible to include in the hash calculation. |
| CR-SW-0062 | — | SW | Design constraint | Low | NON-COMPLIANT | R2R17R19R21 | The byte value of an erased data byte (typically FF or 00) depends on the MCU/Flash memory and shall be specified by the software supplier as an input for the hashing process. |
| CR-HW-0039 | — | HW | Design constraint | Low | NON-COMPLIANT | R10 | The server shall be able to verify that erased-only blocks covered in range of memory are erased. |
| CR-SYS-0228 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R26R32 | When the server has verified all verificationEntries, a result OK/NOT_OK shall be returned. |
| CR-SYS-0229 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | If NOT_OK is returned, the server shall not accept the new software for execution. |
| CR-CYBER-0053 | — | CYBER | Design constraint | Medium | COMPLIANT | — | If OK is returned, the server shall accept that installed software is valid in terms of integrity. |
| CR-SYS-0230 | — | SYS | Design constraint | Low | COMPLIANT | — | The server may execute other checks to verify the software before concluding if the installed software shall be accepted. |
| CR-CYBER-0054 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R16 | For the received data, where a match is found in the EncryptionEntry of the DSC, the server shall initialize a cipher if not previously initialized. |
| CR-CYBER-0055 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R5R21 | An initialized data (i.e., cipher scheme) shall be kept active until no more received data matches the current EncryptionEntry. |
| CR-CYBER-0056 | — | CYBER | Design constraint | Low | COMPLIANT | — | The cipher shall be reinitialized for each new Encryption entry. |
| CR-SYS-0231 | — | SYS | Design constraint | Low | COMPLIANT | — | According to best practise received data shall be decrypted “on the fly” before storing to NVM. |
| CR-SYS-0232 | — | SYS | Design constraint | Low | COMPLIANT | — | Other methods shall be agreed upon with OEM. |
| CR-SYS-0233 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19 | The received data to decrypt may only be parts of a software module and it will be based on the range defined. |
| CR-CYBER-0057 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R21 | #00BFFFFF #008B0000 #0092FFFF Module hashData #00AFAAAA #00AFAAAB When ECU recieves data that matches an address range in an EncryptionEntry (here in Module B), the server must decrypt the data received by TransferData request. |
| CR-CYBER-0058 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R19R21R34 | Module B is encrypted meaning that when the server receives data within a range (given as address and size in RequestDownload) the server must decrypt the data before storing it. |
| CR-SYS-0234 | — | SYS | Design constraint | Low | COMPLIANT | — | The User shall apply the latest version of this CVS124. |
| CR-SYS-0235 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R8R19R26R32R34 | Foreword This CVS124 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable. |
| CR-SYS-0236 | — | SYS | Design constraint | Low | NON-COMPLIANT | R32 | • Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch. |
| CR-SYS-0237 | — | SYS | Design constraint | Low | NON-COMPLIANT | R5R16 | An implementation which does not include a particular option shall be prepared to interoperate with another implementation which does include the option, though perhaps with reduced functionality. |
| CR-SYS-0238 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R21 | In the same vein an implementation which does include a particular option shall be prepared to interoperate with another implementation which does not include the option (except, of course, for the feature the option provides). |
| CR-SYS-0239 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R16R19 | If valid data is not needed for the use-case and system at hand, default values should be used. |
| CR-SYS-0240 | — | SYS | Design constraint | Low | NON-COMPLIANT | R9 | E Mandatory for ECUs which shall be compliant with OBD legislation Worldwide like ISO27145,J1979 etc C Conditional U User optional. |
| CR-SYS-0241 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Shall be agreed between the supplier and the vehicle manufacturer. |
| CR-SW-0063 | REQ_UDS_0001 | SW | Functional | Low | NON-COMPLIANT | R19 | The implementation of the client and the server shall be compliant with ISO 14229-1 with the |
| CR-SYS-0242 | REQ_UDS_0002 | SYS | Design constraint | Low | NON-COMPLIANT | R18R19R26R32 | All deviations and extensions shall be agreed with the applicable vehicle manufacturer and shall be documented. |
| CR-SW-0064 | REQ_UDS_0005 | SW | Design constraint | Low | NON-COMPLIANT | R24 | This DID shall be stored under flash memory module in flash memory. |
| CR-SW-0065 | REQ_UDS_0232 | SW | Design constraint | Low | NON-COMPLIANT | R24 | This DID shall be stored under dataset module stored in flash memory. |
| CR-SW-0066 | REQ_UDS_0233 | SW | Design constraint | Low | NON-COMPLIANT | R24 | This DID shall be stored under dataset module stored in flash memory. |
| CR-SYS-0243 | — | SYS | Design constraint | Low | NON-COMPLIANT | R18R19R26 | Minimum length shall be 8 bytes and the assigned value shall be unique for every unit provided by one supplier per project. |
| CR-SW-0067 | REQ_UDS_0236 | SW | Design constraint | Low | NON-COMPLIANT | R24 | This DID shall be stored under flash memory module in flash memory. |
| CR-SYS-0244 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | The format should follow the pattern: Appl: <Diag.family> <Diag.generation> Boot: <Diag.family> <Diag.generation>_BOOT |
| CR-HW-0040 | REQ_UDS_0027 | HW | Design constraint | Low | NON-COMPLIANT | R24 | This DID shall contain a snapshot of the mandatory lifetime ECU-runtime operational data |
| CR-SW-0068 | REQ_UDS_0029 | SW | Design constraint | Low | NON-COMPLIANT | R19R24 | This DID shall report a snapshot of the mileage of the vehicle as received on CAN or other ECU-external source at the first reception of the signal with a good signal status after a software update. |
| CR-SW-0069 | REQ_UDS_0238 | SW | Design constraint | Low | NON-COMPLIANT | R24 | This DID shall be stored under flash memory module in flash memory. |
| CR-SW-0070 | REQ_UDS_0040 | SW | Functional | Medium | NON-COMPLIANT | R5 | A default diagnostic session shall be supported. |
| CR-SW-0071 | REQ_UDS_0042 | SW | Functional | Medium | NON-COMPLIANT | R5 | A non-default diagnostic session referred to as “extendedDiagnosticSession” shall be supported. |
| CR-SW-0072 | REQ_UDS_0043 | SW | Functional | High | NON-COMPLIANT | R16 | Diagnostic sessions not defined in this document shall be agreed with the vehicle manufacturer. |
| CR-SW-0073 | REQ_UDS_0046 | SW | Functional | Low | NON-COMPLIANT | R19 | The mapping of RoutineControl service routines to sessions shall be discussed and agreed with the vehicle manufacturer. |
| CR-CYBER-0059 | REQ_UDS_0047 | CYBER | Design constraint | Medium | NON-COMPLIANT | R21 | The server shall implement support for RBAC (Role Based Access Control) based on CVS151. |
| CR-CYBER-0060 | REQ_UDS_0048 | CYBER | Design constraint | Medium | NON-COMPLIANT | R2R19 | CVS31 and CVS32 requirements preconditions per service shall be defined by the RBAC Configuration file in the ECU. |
| CR-SW-0074 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | The conditions that shall be checked are • Vehicle speed ~ 0 • Engine speed ~ 0 (for vehicles with IC engines) • High Voltage system disengaged ( for vehicles with high Voltage battery system) • Gear Box in neutral • Parking brake engaged Diagnostics safe state is not intended for ensuring the vehicle safety rather its conditions that are checked to prevent executing Diagnostics services during vehicle operation |
| CR-SYS-0245 | REQ_UDS_0051 | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The server implementation shall comply with the following state diagram and the following state |
| CR-SYS-0246 | REQ_UDS_0338 | SYS | Design constraint | Low | NON-COMPLIANT | R19R32 | The session transitions stated below shall be possible to request both physically or functionally |
| CR-SW-0075 | REQ_UDS_0052 | SW | Functional | Low | COMPLIANT | — | Project specific DID shall be added to ranges defined as system supplier specific in ISO 14229 |
| CR-SW-0076 | REQ_UDS_0055 | SW | Functional | Low | NON-COMPLIANT | R21 | The SPRMIB shall be supported for services as specified in (ISO 14229-1). |
| CR-SW-0077 | REQ_UDS_0056 | SW | Functional | Low | NON-COMPLIANT | R19 | Negative response codes specified in ISO 14229-1 Annex A.1 shall only be supported if explicitly specified by this specification or its normative references. |
| CR-SW-0078 | REQ_UDS_0342 | SW | Functional | Low | COMPLIANT | — | Negative response code 0x22, conditionsNotCorrect , shall be used if a service request is denied due to insufficient rights according to the RBACC check. |
| CR-SW-0079 | REQ_UDS_0057 | SW | Functional | Low | NON-COMPLIANT | R5 | A DiagnosticSessionControl service request with parameter diagnosticSessionType set to ProgrammingSession shall be processed only if normal communication is currently switched off as a result of a previous call to the Communication Control service. |
| CR-SW-0080 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | The application shall respond with NRC 0x22 (conditionsNotCorrect) if communication has not been switched off. |
| CR-SYS-0247 | REQ_UDS_0059 | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | Following an accepted request to switch to the ProgrammingSession, the application shall make all preparations to guarantee trouble-free programming operation. |
| CR-SW-0081 | — | SW | Functional | Low | NON-COMPLIANT | R26R32 | In this process, it shall end all routines and functions that influence programming and ensure that the server checked for safe state conditions at minimal. |
| CR-SYS-0248 | REQ_UDS_0061 | SYS | Design constraint | Low | COMPLIANT | — | Positive response shall be sent before the actual switch in case switching to Programming session. |
| CR-SW-0082 | REQ_UDS_0241 | SW | Functional | Low | COMPLIANT | — | Response parameter diagnosticSessionType shall be as per ISO 14229-1. |
| CR-SW-0083 | REQ_UDS_0242 | SW | Functional | Low | COMPLIANT | — | Response parameter sessionParameterRecord shall be as per ISO 14229-1. |
| CR-SW-0084 | REQ_UDS_0062 | SW | Functional | Medium | NON-COMPLIANT | R5R16 | An ECUReset shall not be executed if the vehicle safety can be compromised. |
| CR-SYS-0249 | REQ_UDS_0063 | SYS | Design constraint | Low | COMPLIANT | — | ECU shall execute the reset only after sending a positive response to the ECU reset service |
| CR-SW-0085 | REQ_UDS_0065 | SW | Functional | Low | NON-COMPLIANT | R34 | The server shall be available for ECU identification within one second after sending positive response message to an ECUReset request. |
| CR-HW-0041 | REQ_UDS_0066 | HW | Design constraint | Low | NON-COMPLIANT | R34 | After ECU reset, ECU shall be restarted and re-initialized within 2sec. |
| CR-SYS-0250 | REQ_UDS_0067 | SYS | Design constraint | Low | NON-COMPLIANT | R19R34 | The maximum time it takes from the positive response is sent from the server until it responds to new requests shall be agreed with vehicle manufacturer and documented. |
| CR-SW-0086 | REQ_UDS_0069 | SW | Functional | Low | NON-COMPLIANT | R17R21 | The ECUReset service with requestParameter value 0x01 (hardReset) shall simulate the power-on / start-up sequence performed after a server has been previously disconnected from its power supply (i.e. |
| CR-SYS-0251 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | the disconnect from the battery shall not be simulated. |
| CR-SYS-0252 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | The implementation of hardReset shall first ensure that data corruption will not occur. |
| CR-SW-0087 | REQ_UDS_0070 | SW | Functional | High | NON-COMPLIANT | R18R19R21 | The ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall simulate the turning of the ignition key off and back on and shall ensure that the values of non-volatile memory locations are preserved and the volatile memory will be initialized. |
| CR-SW-0088 | REQ_UDS_0071 | SW | Functional | Low | NON-COMPLIANT | R21R26 | The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that every server task is finished prior sending a positive response. |
| CR-SW-0089 | REQ_UDS_0072 | SW | Functional | Low | NON-COMPLIANT | R21 | The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that the volatile memory buffered data is stored into non volatile memory prior sending a positive response. |
| CR-SW-0090 | — | SW | Functional | Low | NON-COMPLIANT | R19 | The server shall send an ECUReset positive response message after the server tasks above are finished but before the server performs the actual resetType. |
| CR-SW-0091 | REQ_UDS_0245 | SW | Functional | Low | COMPLIANT | — | Response parameter resetType shall be as per ISO 14229-1. |
| CR-SW-0092 | REQ_UDS_0075 | SW | Functional | Low | NON-COMPLIANT | R16 | Servers involved in engine start shall not process CommunicationControl service requests until 2 seconds after terminal 15 goes active. |
| CR-SW-0093 | — | SW | Functional | Low | NON-COMPLIANT | R19R21 | If a request is received before this time has passed the server shall respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) (and process the request and send a final response when 2 seconds have passed) or NRC 0x22 (conditionsNotCorrect). |
| CR-SW-0094 | REQ_UDS_0076 | SW | Functional | High | COMPLIANT | — | When receiving CommunicationControl service request, Gateway server applications shall ensure quieting down of network to ECUs without diagnostic server which are present in their sub-buses |
| CR-FUSA-0006 | REQ_UDS_0077 | FUSA | Functional | Medium | NON-COMPLIANT | R19 | Safety conditions are project specific and shall be checked before accepting a request to disable communication. |
| CR-SW-0095 | — | SW | Design constraint | Low | NON-COMPLIANT | R1R2R16R17R19R21 | Communication control service should not only be used to improve the bandwidth situation during flashing /parametrisation but also for inhibiting systems in vehicle (like engine start) to ensure safety. |
| CR-SYS-0253 | REQ_UDS_0081 | SYS | Design constraint | Low | NON-COMPLIANT | R16R32 | If the parameter suppressPosRespMsgIndicationBit = true in a functionally addressed request message, the service request shall not influence any ongoing physically addressed service |
| CR-SYS-0254 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R5R32 | A functionally addressed TesterPresent may arrive at any time during another request. |
| CR-SW-0096 | REQ_UDS_0249 | SW | Functional | Low | NON-COMPLIANT | R19 | Request format and parameter shall be as per ISO 14229-1. |
| CR-SW-0097 | REQ_UDS_0343 | SW | Functional | Low | NON-COMPLIANT | R16R21 | Servers shall reject a ControlDTCSetting service request (DTC setting type = off) with NRC 0x22 (conditionsNotCorrect) if programming preconditions are not satisfied. |
| CR-SW-0098 | REQ_UDS_0344 | SW | Functional | High | NON-COMPLIANT | R16R18R19R21 | The execution of this service in the application shall only impact the DTC setting - diagnostic tests for safety and degradations shall not be impacted (shall work as normal). |
| CR-SYS-0255 | REQ_UDS_0082 | SYS | Design constraint | Low | NON-COMPLIANT | R10R34 | The server shall be able to switch baud rate within one second. |
| CR-SYS-0256 | REQ_UDS_0083 | SYS | Design constraint | Low | COMPLIANT | — | The boot loader shall inherit the selected baud rate if the LinkControl service request was received when the server was executing in the application. |
| CR-SYS-0257 | REQ_UDS_0084 | SYS | Design constraint | Low | COMPLIANT | — | Positive response shall be sent before the actual switch of the baud-rate takes place. |
| CR-HW-0042 | REQ_UDS_0087 | HW | Design constraint | Low | NON-COMPLIANT | R9R21 | If ECU supports request containing more than one data identifier it shall be documented (like in CDD, ODX etc). |
| CR-SW-0099 | REQ_UDS_0255 | SW | Functional | Low | COMPLIANT | — | DataIdentifier parameter definition shall be as per ISO 14229-1. |
| CR-SW-0100 | REQ_UDS_0089 | SW | Functional | Low | NON-COMPLIANT | R32 | The sequence of writing data records with service 0x2E WriteDataByIdentifier shall be independent of any specific order |
| CR-SW-0101 | REQ_UDS_0091 | SW | Functional | Low | NON-COMPLIANT | R19R21R26R32 | All changed data shall be valid and stored into non-volatile memory at the latest after an ECU Reset(0x11) subfunction 0x02 requested from client. |
| CR-SW-0102 | REQ_UDS_0092 | SW | Functional | High | NON-COMPLIANT | R17R19R21R32 | If it is necessary to force an explicit transfer of buffered data into non-volatile memory then this shall be supported both with ECU-Reset Service subfunction 0x02 and ignition (IGN) key Off/On (power cycle). |
| CR-SW-0103 | — | SW | Functional | Low | NON-COMPLIANT | R19R21 | If this action is necessary then it shall be integrated implicitly into ECU Reset (0x11) Service subfunction 0x02. |
| CR-SW-0104 | REQ_UDS_0258 | SW | Functional | Low | NON-COMPLIANT | R19 | Request format and parameter shall be as per ISO 14229-1. |
| CR-SW-0105 | REQ_UDS_0262 | SW | Functional | Low | COMPLIANT | — | groupOfDTC parameter definition shall be as per ISO 14229-1. |
| CR-SW-0106 | REQ_UDS_0266 | SW | Functional | Low | COMPLIANT | — | ReportNumberOfDTCByStatusMask parameter format shall be as per ISO 14229-1. |
| CR-SW-0107 | REQ_UDS_0267 | SW | Functional | Low | COMPLIANT | — | DTCStatusMask parameter format shall be as per ISO 14229-1. |
| CR-SYS-0258 | REQ_UDS_0097 | SYS | Design constraint | Low | NON-COMPLIANT | R24 | It shall be mandatory to utilize SPNs & FMIs according to SAE J1939. |
| CR-SW-0108 | REQ_UDS_0268 | SW | Functional | Low | COMPLIANT | — | DTCSnapshotRecordNumber parameter format shall be as per ISO 14229-1. |
| CR-SW-0109 | REQ_UDS_0269 | SW | Functional | Low | COMPLIANT | — | Response parameter FunctionalGroupIdentifier shall be as per ISO 14229-1. |
| CR-SW-0110 | REQ_UDS_0270 | SW | Functional | Low | COMPLIANT | — | DTCSeverityMaskRecord parameter format shall be as per ISO 14229-1. |
| CR-SW-0111 | REQ_UDS_0271 | SW | Functional | Low | COMPLIANT | — | DTCSeverityMask parameter format shall be as per ISO 14229-1. |
| CR-SW-0112 | REQ_UDS_0273 | SW | Functional | Low | COMPLIANT | — | Response parameter DTCStatusAvailabilityMask shall be as per ISO 14229-1. |
| CR-SW-0113 | REQ_UDS_0274 | SW | Functional | Low | COMPLIANT | — | Response parameter DTCFormatIdentifier shall be as per ISO 14229-1. |
| CR-SW-0114 | REQ_UDS_0275 | SW | Functional | Low | COMPLIANT | — | Response parameter DTCCount shall be as per ISO 14229-1. |
| CR-SW-0115 | REQ_UDS_0276 | SW | Functional | Low | COMPLIANT | — | Response parameter DTCAndStatusRecord shall be as per ISO 14229-1. |
| CR-SW-0116 | REQ_UDS_0277 | SW | Functional | Low | COMPLIANT | — | Response parameter DTCRecord shall be as per ISO 14229-1. |
| CR-VAL-0017 | — | VAL | Design constraint | Low | NON-COMPLIANT | R16 | If a mechanic is working on the vehicle, the driveline shall report Not Ready and place the vehicle in the state PropulsionNotReady. |
| CR-HW-0043 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R16R19R20R21R26 | Range tion #54 ECU start-up and alive reasons Bits 0-3 (start-up reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6-0xE: Reserved 0xF: Not available Bits 4-7 (alive reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6: Stay alive 0x7-0xE: Reserved 0xF: Not available Note 1: While the reason for keeping the ECU alive may change during execution startup reason and alive reason are always identical at ECU startup. |
| CR-SW-0117 | — | SW | Functional | Low | NON-COMPLIANT | R19R21 | dependent depend ent depende nt U #65+N+M- #66+N+M dataIdentifier 0x0000 – #67+N+M +P Data required by law or regulations Signal dependent depend ent depende nt C1 #68+N+M +P DTCSnapshotRecordNumber#2 (Latest Snapshot captured) 0x02 M #69+N+M +P DTCSnapshotRecordNumberOfIdentifiers#2 0x00 : 0xFF M #70+N+M +P : #70+2*(N +M+P) See specification for DTCSnapshotRecord[]#1 This latest snapshot shall contain the same type of data and format as DTCSnapshotRecord[]#1. |
| CR-SW-0118 | REQ_UDS_0304 | SW | Functional | Low | NON-COMPLIANT | R19 | DTCSnapshotRecordNumber#1 & DTCSnapshotRecordNumber#2 shall correspond to first time DTC happened and latest time DTC happened correspondingly. |
| CR-SW-0119 | — | SW | Functional | Low | NON-COMPLIANT | R21R26R32 | For these ECUs these bytes shall contain default value 0xFF (all bytes). |
| CR-SW-0120 | — | SW | Functional | Low | NON-COMPLIANT | R16R21R26R32 | Byte Description Range Resolu tion 0: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m #35..#38 Total vehicle distance at the latest DTC activation [4-byte int, big endian] in section 5.7.4.1 Not used for TRATON External engine and marine ECUsFor these ECUs these bytes shall contain default value 0xFF (all bytes). |
| CR-SW-0121 | — | SW | Functional | Low | NON-COMPLIANT | R17R21R26R32 | 0: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m 0xFFF FFFFF 5 m/bit 0xFF (all bytes) C #41+(2p+1) +1 DTCExtDataRecordNumber#4 This byte shall be set to value 0x14. |
| CR-SW-0122 | REQ_UDS_0278 | SW | Functional | Low | COMPLIANT | — | Response parameter FunctionalGroupIdentifier shall be as per ISO 14229-1. |
| CR-SW-0123 | REQ_UDS_0279 | SW | Functional | Low | COMPLIANT | — | Response parameter DTCSeverityAvailabilityMask shall be as per ISO 14229-1. |
| CR-SW-0124 | REQ_UDS_0280 | SW | Functional | Low | COMPLIANT | — | Response parameter DTCAndSeverityRecord shall be as per ISO 14229-1. |
| CR-SW-0125 | REQ_UDS_0282 | SW | Functional | Low | COMPLIANT | — | Negative response codes shall be as per ISO 14229-1. |
| CR-SW-0126 | REQ_UDS_0102 | SW | Functional | Low | COMPLIANT | — | The data identifier ranges specified in ISO 14229-1 shall be followed. |
| CR-SW-0127 | REQ_UDS_0284 | SW | Functional | Low | COMPLIANT | — | ControlEnableMaskRecord parameter format shall be as per ISO 14229-1. |
| CR-SW-0128 | REQ_UDS_0106 | SW | Functional | Low | COMPLIANT | — | Request parameter routineIdentifier shall be as per ISO 14229-1. |
| CR-SW-0129 | REQ_UDS_0288 | SW | Functional | Low | COMPLIANT | — | Request parameter routineControlOptionRecord shall be as per ISO 14229-1. |
| CR-SW-0130 | REQ_UDS_0108 | SW | Functional | Low | NON-COMPLIANT | R7 | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request. |
| CR-HW-0044 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R20 | In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint. |
| CR-SW-0131 | REQ_UDS_0109 | SW | Functional | Low | NON-COMPLIANT | R7R21 | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules). |
| CR-SW-0132 | REQ_UDS_0110 | SW | Functional | Low | NON-COMPLIANT | R32 | Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error. |
| CR-SW-0133 | REQ_UDS_0111 | SW | Functional | Low | NON-COMPLIANT | R19 | If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x12 (sub |
| CR-SW-0134 | REQ_UDS_0291 | SW | Functional | Low | COMPLIANT | — | MemoryAddress parameter definition shall be as per ISO 14229-1. |
| CR-SW-0135 | REQ_UDS_0292 | SW | Functional | Low | COMPLIANT | — | MemorySize parameter definition shall be as per ISO 14229-1. |
| CR-SW-0136 | REQ_UDS_0294 | SW | Functional | Low | NON-COMPLIANT | R19 | Refer to ISO 14229-1 for negative response format and codes shall be as per ISO 14229-1. |
| CR-SW-0137 | REQ_UDS_0296 | SW | Functional | Low | COMPLIANT | — | MemoryAddress parameter definition shall be as per ISO 14229-1. |
| CR-SW-0138 | REQ_UDS_0297 | SW | Functional | Low | COMPLIANT | — | MemorySize parameter definition shall be as per ISO 14229-1. |
| CR-SYS-0259 | REQ_UDS_0122 | SYS | Design constraint | Low | NON-COMPLIANT | R16 | The transferRequestParameterRecord shall not be supported. |
| CR-SYS-0260 | REQ_UDS_0124 | SYS | Design constraint | Low | NON-COMPLIANT | R16 | The transferRequestParameterRecord shall not be supported. |
| CR-SYS-0261 | REQ_UDS_0125 | SYS | Design constraint | Low | NON-COMPLIANT | R24 | This service shall be used when transmitting data in a secured mode, see CVS32. |
| CR-SW-0139 | REQ_UDS_0126 | SW | Functional | Low | COMPLIANT | — | Data parameter definition shall be as per ISO 14229-1. |
| CR-SYS-0262 | REQ_UDS_0127 | SYS | Design constraint | Low | COMPLIANT | — | Positive response shall be as per CVS32. |
| CR-SYS-0263 | REQ_UDS_0128 | SYS | Design constraint | Low | COMPLIANT | — | Negative response shall be as per CVS32 5.5.17.3.1 Supported negative response codes |
| CR-SW-0140 | REQ_UDS_0129 | SW | Functional | Low | NON-COMPLIANT | R21 | Negative response format shall be as per ISO 14229-1 5.5.18 Authentication (0x29) service |
| CR-SW-0141 | REQ_UDS_0130 | SW | Functional | Low | NON-COMPLIANT | R19R21 | Authentication (0x29) service shall be used for authentication of client and server. |
| CR-SW-0142 | REQ_UDS_0133 | SW | Functional | Low | NON-COMPLIANT | R21 | The Authentication (0x29) service shall be implemented according to CVS31 . |
| CR-SYS-0264 | REQ_UDS_0139 | SYS | Design constraint | Low | NON-COMPLIANT | R19 | For detailed error cases and the mapping to the corresponding NRCs the Authentication service implementation specification CVS31 shall be used. |
| CR-SYS-0265 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | If the file is not stored at the location the file shall be added. |
| CR-SW-0143 | — | SW | Functional | Low | NON-COMPLIANT | R21 | M 0x04 ReadFile This value shall be used to read the file (upload) at the location defined by the filePathAndName parameter. |
| CR-SW-0144 | — | SW | Functional | Low | COMPLIANT | — | U 0x05 ReadDir This value shall be used to read the directory defined in the filePathAndName parameter. |
| CR-SW-0145 | — | SW | Functional | Low | COMPLIANT | — | U 0x06 ResumeFile This value shall be used to resume downloading the file defined in the filePathAndName parameter at the returned filePosition indicator. |
| CR-HW-0045 | — | HW | Design constraint | Low | COMPLIANT | — | The file specified in the filePathAndName shall already exist in the ECU’s file system. |
| CR-SW-0146 | REQ_UDS_0142 | SW | Functional | Low | COMPLIANT | — | Refer to ISO 14229-1 for parameter sub-function format shall be as per ISO 14229-1. |
| CR-SW-0147 | REQ_UDS_0146 | SW | Functional | Low | COMPLIANT | — | Supported negative response codes shall be as per ISO 14229-1. |
| CR-SYS-0266 | REQ_UDS_0147 | SYS | Design constraint | Low | COMPLIANT | — | The programming preconditions shall be agreed with the vehicle manufacturer. Preconditions to |
| CR-FUSA-0007 | — | FUSA | Functional | Low | NON-COMPLIANT | R16R19 | Preconditions to be discussed with the vehicle manufacturer shall include but not be limited to Diag safe state conditions. |
| CR-SYS-0267 | REQ_UDS_0148 | SYS | Design constraint | Low | NON-COMPLIANT | R34 | The decision on conditions of the programming precondition shall be based on minimum two independent sources of information. |
| CR-SYS-0268 | REQ_UDS_0149 | SYS | Design constraint | Low | NON-COMPLIANT | R16 | If information is not available for checking a programming precondition the programming precondition shall be considered fulfilled. |
| CR-HW-0046 | — | HW | Design constraint | Low | NON-COMPLIANT | R19R32 | If the ECU received the information related to any of the conditions during the same driving cycle then it shall use that information. |
| CR-SW-0148 | REQ_UDS_0150 | SW | Functional | Low | NON-COMPLIANT | R7R19R24R32 | This routine shall be supported in Extended session of both Application and Boot. |
| CR-SW-0149 | REQ_UDS_0151 | SW | Functional | Low | NON-COMPLIANT | R16 | Request parameter RoutineControlOptionRecord shall not be supported. |
| CR-SW-0150 | REQ_UDS_0152 | SW | Functional | Low | NON-COMPLIANT | R16R21 | Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported. |
| CR-SW-0151 | REQ_UDS_0156 | SW | Functional | Low | NON-COMPLIANT | R26R32 | If all preconditions are satisfied, no routineStatus byte shall be reported. |
| CR-SYS-0269 | REQ_UDS_0158 | SYS | Design constraint | Low | NON-COMPLIANT | R19R21R26 | The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested. |
| CR-HW-0047 | — | HW | Design constraint | Low | NON-COMPLIANT | R1R2R20 | In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint. |
| CR-SW-0152 | REQ_UDS_0159 | SW | Design constraint | Low | NON-COMPLIANT | R16R18 | In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area. |
| CR-SW-0153 | REQ_UDS_0160 | SW | Functional | Low | NON-COMPLIANT | R19 | When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see |
| CR-SW-0154 | REQ_UDS_0161 | SW | Functional | Low | NON-COMPLIANT | R16R21 | The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e. |
| CR-HW-0048 | — | HW | Design constraint | Low | COMPLIANT | — | the erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase. |
| CR-SW-0155 | REQ_UDS_0162 | SW | Functional | Low | NON-COMPLIANT | R7R24 | This routine shall be supported in Programming session. |
| CR-SW-0156 | REQ_UDS_0164 | SW | Functional | Low | NON-COMPLIANT | R16R21 | Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported 5.6.2.2 Request parameter addressAndLengthFormatIdentifier |
| CR-SW-0157 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R21 | 02, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements & & |
| CR-SW-0158 | REQ_UDS_0166 | SW | Functional | Low | COMPLIANT | — | When the addressAndLengthFormatIdentifier is set to 0x01 the following defined module to index mapping shall apply for the memoryStartAddress: 1 – Boot loader 2 – Application 3 – Application Data 4 ... |
| CR-MECH-0040 | REQ_UDS_0169 | MECH | Design constraint | Low | NON-COMPLIANT | R1R2R19 | The RoutineIdentifier may verify the authenticity of the received file package. See CVS123 and |
| CR-CYBER-0061 | REQ_UDS_0170 | CYBER | Design constraint | Low | NON-COMPLIANT | R26R32 | If authenticity verification is valid the server shall initiate all necessary steps for installation of the received file. |
| CR-SW-0159 | REQ_UDS_0171 | SW | Functional | Low | NON-COMPLIANT | R32 | The server shall send a response to RoutineIdentifier 0x2401 Software Installation without any further inputs from the client. |
| CR-SW-0160 | REQ_UDS_0172 | SW | Functional | Low | NON-COMPLIANT | R19R21 | If authenticity verification fails the server shall send the positive response with AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) set to 0x02 (Authenticity Verification Failed) and SoftwareInstallationStatus bit 7-6 (InstallationStatus) set to 0x02 (Installation Failed). |
| CR-SW-0161 | REQ_UDS_0173 | SW | Functional | Low | NON-COMPLIANT | R7R24 | This routine shall be supported in Programming session. |
| CR-SW-0162 | REQ_UDS_0174 | SW | Functional | Low | NON-COMPLIANT | R16 | Request parameter RoutineControlOptionRecord shall not be supported. |
| CR-SW-0163 | REQ_UDS_0175 | SW | Functional | Low | NON-COMPLIANT | R21 | Positive responses to RoutineControl (Software Installation) service requests shall be formatted |
| CR-CYBER-0062 | REQ_UDS_0177 | CYBER | Design constraint | Low | NON-COMPLIANT | R21 | AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall remain as 0x0 (Software Authenticity Invalid) until the verification completes. |
| CR-SW-0164 | REQ_UDS_0178 | SW | Functional | Low | NON-COMPLIANT | R21 | If no authenticity verification will take place as part of RoutineIdentifier, the AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall be changed to 0x1 (Authenticity Verification Successful). |
| CR-SYS-0270 | REQ_UDS_0180 | SYS | Design constraint | Low | NON-COMPLIANT | R21 | SoftwareInstallationStatus bit 7-6 (InstallationStatus) shall remain as 0x0 (Installation On-going) until the installation completes. |
| CR-SYS-0271 | — | SYS | Design constraint | Low | COMPLIANT | — | Information shall be provided in percentage. |
| CR-SYS-0272 | REQ_UDS_0182 | SYS | Design constraint | Low | COMPLIANT | — | TimeRemaningEstimative shall inform the time estimative to complete the installation of the file. |
| CR-SYS-0273 | — | SYS | Design constraint | Low | COMPLIANT | — | Information shall be provided in seconds. |
| CR-SW-0165 | — | SW | Functional | Low | NON-COMPLIANT | R9R16R19R21 | Whereas the result of the dependency check is returned as part of a positive response, a negative response code (NRC) shall be returned if the normal conditions according to (ISO 14229-1) (authentication, service request length, parameter range check etc) for performing the service are not correct. |
| CR-SW-0166 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R10R19R24 | This RoutineIdentifier value allows the client to start a consistency check of the server and should be able to execute independent from programming sequence. |
| CR-SYS-0274 | REQ_UDS_0183 | SYS | Design constraint | Low | NON-COMPLIANT | R16R19 | The server shall check whether or not the individual modules are complete and compatible with |
| CR-SYS-0275 | — | SYS | Functional | Low | NON-COMPLIANT | R16R17R19R21 | In addition, a check shall be made to determine whether or not the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data). |
| CR-SYS-0276 | REQ_UDS_0184 | SYS | Design constraint | Low | NON-COMPLIANT | R2R17 | The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer. |
| CR-SYS-0277 | REQ_UDS_0185 | SYS | Design constraint | Low | COMPLIANT | — | The consistency check shall be carried out solely by the server. |
| CR-CYBER-0063 | REQ_UDS_0186 | CYBER | Design constraint | Medium | NON-COMPLIANT | R19 | The server shall verify the authenticity and integrity of the software as a part of the consistency check. |
| CR-CYBER-0064 | REQ_UDS_0187 | CYBER | Design constraint | Medium | NON-COMPLIANT | R19 | The authenticity and integrity information shall be supplied to the server before the software is updated. |
| CR-CYBER-0065 | REQ_UDS_0188 | CYBER | Design constraint | Medium | NON-COMPLIANT | R19 | The authenticity and integrity check shall be carried out solely by the server. |
| CR-SW-0167 | REQ_UDS_0189 | SW | Functional | Low | NON-COMPLIANT | R7R24 | This routine shall be supported in Programming session. |
| CR-SW-0168 | REQ_UDS_0195 | SW | Functional | Low | NON-COMPLIANT | R7R19R24R26R32 | This routine shall be supported in all sessions of Application and Boot. |
| CR-SW-0169 | REQ_UDS_0197 | SW | Functional | Low | NON-COMPLIANT | R16R32 | DTC status bits shall not make use of any vehicle manufacturer specific reset condition (e.g. |
| CR-SYS-0278 | REQ_UDS_0198 | SYS | Design constraint | Low | NON-COMPLIANT | R34 | The occurrence counter minimum value shall be zero (0). |
| CR-SYS-0279 | REQ_UDS_0199 | SYS | Design constraint | Low | NON-COMPLIANT | R34 | The occurrence counter maximum value shall be 126. |
| CR-SYS-0280 | REQ_UDS_0200 | SYS | Design constraint | Low | COMPLIANT | — | The occurrence counter default value shall be zero (0). |
| CR-SYS-0281 | REQ_UDS_0201 | SYS | Design constraint | Low | COMPLIANT | — | The occurrence counter shall increment by one (1) only. |
| CR-SYS-0282 | REQ_UDS_0202 | SYS | Design constraint | Low | NON-COMPLIANT | R16R34 | The occurrence counter shall increment if it’s value is not at it’s maximum value already. |
| CR-SW-0170 | REQ_UDS_0203 | SW | Functional | Low | NON-COMPLIANT | R19R32 | The occurrence counter shall increment at a change of DTC status bits 0 testFailed and 3 confirmedDTC both from 0 to 1. |
| CR-SW-0171 | REQ_UDS_0204 | SW | Functional | Low | COMPLIANT | — | The occurrence counter shall increment at a change of DTC status bit 0 testFailed from 0 to 1, |
| CR-SW-0172 | REQ_UDS_0205 | SW | Functional | Low | COMPLIANT | — | The occurrence counter shall increment at a change of DTC status bit 3 confirmedDTC from 0 to 1, if bit 0 testFailed is 1 already. |
| CR-SYS-0283 | REQ_UDS_0206 | SYS | Design constraint | Low | COMPLIANT | — | The occurrence counter value 127 shall be defined as "errors with the counter". |
| CR-SW-0173 | REQ_UDS_0207 | SW | Functional | Low | COMPLIANT | — | The timestamp default value shall be a 0xFF in each data. |
| CR-SW-0174 | REQ_UDS_0210 | SW | Functional | Low | NON-COMPLIANT | R19R21 | The latest occurrence shall be updated at a change of DTC status bits 0 (testFailed) and 3 |
| CR-SW-0175 | REQ_UDS_0210 | SW | Functional | Low | NON-COMPLIANT | R21 | The latest occurrence shall be updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already. |
| CR-SW-0176 | REQ_UDS_0211 | SW | Functional | Low | COMPLIANT | — | If occurrence counter is set to 1, the timestamp of the latest occurrence shall be set to 0xFF. |
| CR-SW-0177 | REQ_UDS_0212 | SW | Functional | Low | NON-COMPLIANT | R19R21 | The first occurrence shall be updated at the first change of DTC status bits 0 (testFailed) and 3 5.7.4 Vehicle distance at occurrence |
| CR-SYS-0284 | REQ_UDS_0213 | SYS | Design constraint | Low | NON-COMPLIANT | R2R17R21 | The vehicle distance shall be represented by a four byte integer, big endian, with five meter per bit (5m/bit). |
| CR-SW-0178 | REQ_UDS_0214 | SW | Functional | Low | NON-COMPLIANT | R26R32 | If all sources of vehicle distance information present no current data, the distance information shall be set to 0xFF at all bytes. |
| CR-SW-0179 | REQ_UDS_0219 | SW | Functional | Low | NON-COMPLIANT | R26R32 | If all sources of operational hours information present no current data, the operational hours information shall be set to 0xFF at all bytes. |
| CR-SW-0180 | REQ_UDS_0223 | SW | Functional | Medium | NON-COMPLIANT | R34 | The server shall be available for complete diagnostic communication within two seconds after a power on. |
| CR-SW-0181 | REQ_UDS_0224 | SW | Functional | Medium | NON-COMPLIANT | R1R2R16R21R34 | If diagnostic data is not available in time the ECU should respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) for maximum allowed time. |
| CR-SW-0182 | — | SW | Functional | Low | NON-COMPLIANT | R1R2 | for Linux based systems still running in boot, the server should indicate with DID 0xF1AD that it is running in boot. |
| CR-SYS-0285 | REQ_UDS_0225 | SYS | Design constraint | Low | NON-COMPLIANT | R18 | For P2Server, the minimum value shall be 0 ms, a maximum value shall be 50 ms. |
| CR-SYS-0286 | REQ_UDS_0226 | SYS | Design constraint | Low | COMPLIANT | — | For P2Client, a value of 150 ms shall be used. |
| CR-SYS-0287 | REQ_UDS_0227 | SYS | Design constraint | Low | NON-COMPLIANT | R18 | For P2*Server, the minimum value shall be 0ms, the maximum value shall be 4000ms. |
| CR-SW-0183 | REQ_UDS_0228 | SW | Functional | Low | COMPLIANT | — | For P2*Client, the value estimation given in ISO 14229-2 shall be used. |
| CR-SYS-0288 | REQ_UDS_0229 | SYS | Design constraint | Low | NON-COMPLIANT | R34 | The value for P4_Server_max shall be maximum 30 seconds. |
| CR-SYS-0289 | REQ_UDS_0230 | SYS | Design constraint | Low | COMPLIANT | — | The system supplier shall document the implemented value for P4_Server_max. |
| CR-SW-0184 | — | SW | Functional | Medium | NON-COMPLIANT | R1R2R19R21R32 | RBAC for diagnostics Foreword This Commercial Vehicle Standard (“CVS151”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates. |
| CR-SYS-0290 | — | SYS | Design constraint | Low | COMPLIANT | — | The User shall apply the latest version of this CVS151. |
| CR-SW-0185 | — | SW | Functional | Highest | NON-COMPLIANT | R1R2R21 | 1 Scope Concepts such as secure-update (CVS37) requires Role Based Access Control (RBAC) for diagnostics (UDS). |
| CR-SW-0186 | — | SW | Functional | Medium | NON-COMPLIANT | R1R2R7R17 | Before a client can execute diagnostics services that are under RBAC, the client must perform some type of authorization procedure towards the server/ECU. |
| CR-CYBER-0066 | — | CYBER | Design constraint | Low | COMPLIANT | — | Each RBACC shall only contain one role-configuration per each supported role. |
| CR-CYBER-0067 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R17R34 | If conflicting/overlapping rules are found within a role-configuration, the server shall enforce that deny rule takes precedence over the allow rule. |
| CR-SYS-0291 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R19R26R32 | If a matching allow/deny rule is found and all the rule settings are fulfilled, the server shall accept/deny the request. |
| CR-SYS-0292 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R19R26R32 | If a matching rule is found and not all the rule settings are fulfilled, the server shall consider the request rejected for that rule. |
| CR-CYBER-0068 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall deny a request if no matching rule is found on RBACC. |
| CR-CYBER-0069 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R26R32 | All RBACC ALLOW rules have a setting that dictates if a request, matching the rule, must be 14229-1:2020). |
| CR-CYBER-0070 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall evaluate each role-configuration independently from each other. |
| CR-SW-0187 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The server shall require that requests are authenticated for allow rules, using e.g., SecuredDataTransmission 0x84 (see CVS31, ISO-14229-1:2020). |
| CR-CYBER-0071 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R19R21 | The server and client shall define the RBACC as per the following ASN.1 definition: RBACC ::= SEQUENCE { version OCTET STRING (SIZE(2)), rbacc-id OCTET STRING (SIZE(16)), role-configurations SEQUENCE (SIZE(0..MAX)) OF Role-configuration } Role-configuration ::= SEQUENCE { role INTEGER(0..MAX), pattern-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), pattern-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), did-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), did-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)) } |
| CR-SYS-0293 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support in the version field two octets. |
| CR-SYS-0294 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The server shall support major version value 3 and minor version value 0. |
| CR-SYS-0295 | — | SYS | Design constraint | Low | NON-COMPLIANT | R18R19 | If other versions shall be supported is out of the scope of this document and shall be agreed upon between projects in Traton. |
| CR-CYBER-0072 | — | CYBER | Design constraint | Low | COMPLIANT | — | Before RBACC is stored, the server shall verify that the server supports the structure indicated in the version number. |
| CR-SYS-0296 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | If the version number does not comply with the server implementation, the server shall reject storing the data. |
| CR-SW-0188 | — | SW | Functional | Low | COMPLIANT | — | The server shall report the currently stored RBACC’s version via diagnostics. |
| CR-CYBER-0073 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall support 16 octets in the rbacc-id field. |
| CR-SW-0189 | — | SW | Functional | Low | COMPLIANT | — | The server shall report the currently stored RBACC’s rbacc-id via diagnostics. |
| CR-CYBER-0074 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall support role-configurations using 32-bit unsigned integer. |
| CR-SW-0190 | — | SW | Functional | Medium | NON-COMPLIANT | R26 | The server shall support for every entry in the pattern-rules one octet for the pattern rule settings followed by the diagnostic pattern of variable length. |
| CR-SYS-0297 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26 | The server shall support for every entry in the did-rules one octet which represents the did-rule settings followed by two octets that represent the DID. |
| CR-SYS-0298 | — | SYS | Design constraint | Low | COMPLIANT | — | The byte order for DID shall be big endian. |
| CR-SYS-0299 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R17R26 | 4 Read 0 == This rule is not applicable when the DID is being read 1 == This rule is applicable when the DID is being read 5 Write 0 == This rule is not applicable when the DID is being written 1 == This rule is applicable when the DID is being written 6 IO-control 0 == This rule is not applicable when the DID is being used for IO-control 1 == This rule is applicable when the DID is being used for IO-control 7 N/A Reserved for future use 3.9 rid-rules The server shall support for every entry in the rid-rules one octet which represents the rid-rule settings followed by two octets that represent the RID. |
| CR-CYBER-0075 | — | CYBER | Design constraint | Highest | NON-COMPLIANT | R17R19R32 | If conflicting/overlapping rules are found between the client certificate D-RBACC extension and any rules in the RBAC-configuration in the RBACC, the server shall enforce the rules in the client certificate D-RBACC extension. |
| CR-CYBER-0076 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R21 | The server shall interpret the extnValue (see snipped above) as of one instance of a RBACC (see 3.3). |
| CR-SYS-0300 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R7R16R17R19R21R24 | It can also be useful if you want to add or remove access rights from a client/tester, that needs access to one or several roles, but should not have access to everything (or should have more access) specified for the assigned roles. |
| CR-SW-0191 | — | SW | Functional | High | COMPLIANT | — | The server shall exert the RBACC roles based on the ECU-diagnostics-Role extension on the client’s certificate. |
| CR-CYBER-0077 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The server shall implement RBAC internal logic as per Figure 4. |
| CR-CYBER-0078 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The server shall implement RBAC pattern rule evaluation logic as per Figure 5. |
| CR-SW-0192 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R21 | E.g: For the evaluate pattern the rule setting Confidentiality is set to 0x01 (Confidentiality is required). |
| CR-CYBER-0079 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The server shall implement RBAC did rule evaluate as per Figure 6. |
| CR-CYBER-0080 | — | CYBER | Design constraint | Medium | COMPLIANT | — | The server shall implement RBAC rid rule evaluate as per Figure 7. |
| CR-SW-0193 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R10R17R26R32 | Meaning, role 0 is particularly useful for defining services, DIDs and RIDs that should be available to all clients/users, regardless of their diagnostics role and/or authorization/authentication status. |
| CR-CYBER-0081 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall allow requests that are contained in role 0 rules regardless of the client authentication state. |
| CR-SW-0194 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The server shall allow request that are contained in role 0 rule regardless if the request is data authenticated e.g over e.g., SecuredDataTransmission 0x84 (See CVS31, ISO 14229-1:2020). |
| CR-CYBER-0082 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall allow request that are contained in role 0 rule regardless of the value of Confidentiality field setting. |
| CR-SW-0195 | — | SW | Functional | Medium | NON-COMPLIANT | R26 | The server shall always allow reception of UDS authenticate 0x29 requests regardless of the RBACC settings. |
| CR-SW-0196 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R16 | For 0x29 requests a corresponding matching rule in the RBACC is not required for the server to accept the request. |
| CR-SW-0197 | — | SW | Functional | Medium | COMPLIANT | — | The server shall evaluate the reported internal service using the RBACC rules whenever it receives a UDS Service 0x84 requests. |
| CR-SW-0198 | — | SW | Functional | Medium | NON-COMPLIANT | R26 | The server shall always allow reception of UDS SecuredDataTransmission 0x84 requests regardless of the RBACC settings. |
| CR-SW-0199 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R16R19 | For 0x84 requests a corresponding matching rule in the RBACC is not required for the server to accept the 0x84 request but the server must find a corresponding matching rule for the internal request contained in the 0x84 prior to execute it. |
| CR-SW-0200 | — | SW | Functional | Medium | NON-COMPLIANT | R26 | The server shall always allow reception of UDS TesterPresent 0x3E requests regardless of the RBACC settings. |
| CR-SW-0201 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R16 | For 0x3E requests a corresponding matching rule in the RBACC is not required for the server to accept the request. |
| CR-CYBER-0083 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R1R2R21 | Annex D DynamicallyDefineDataIdentifier When this service is being used, each DID included in the request must be evaluated against the rules that are applicable for the client (the rules in the client’s certificate and in the RBACC). |
| CR-SYS-0301 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19R26R32 | The client must have read access for all included DIDs and have access to the service themselves. |
| CR-SYS-0302 | — | SYS | Design constraint | Low | NON-COMPLIANT | R7R19R21R26R32 | When the client is performing the actual read operation (ReadDataByIdentifier [7]), the conditions and rules for all DIDs, aliased by the dynamically defined identifier, must be met, otherwise the request shall be rejected with an appropriate NRC. |
| CR-SYS-0303 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R17R19R21 | Since reading of DIDs can be allowed by either a pattern-rule (starting with 22 [7]) and/or a DID-rule, both the pattern-rules and the DID-rules must be parsed when evaluating each DID. |
| CR-CYBER-0084 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R19R21R32 | Data Security Container base definition Foreword This Commercial Vehicle Standard (“CVS154”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates. |
| CR-SYS-0304 | — | SYS | Design constraint | Low | COMPLIANT | — | The User shall apply the latest version of this CVS154. |
| CR-SYS-0305 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The server shall support a DSC Metadata block containing version and id fields. |
| CR-SYS-0306 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The server shall support the Major and Minor version as specified in 3.2. |
| CR-SYS-0307 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support a DSC containing verificationEntries. |
| CR-CYBER-0085 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall support a DSC containing encryptionEntries. |
| CR-SYS-0308 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support a DSC containing itemEntries. |
| CR-SYS-0309 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall expect an ASN.1 SEQUENCE tag with length zero for verificationEntries that contains no VerificationEntry items in a DSC transmitted by the client. |
| CR-CYBER-0086 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall expect an ASN.1 SEQUENCE tag with length zero for encryptionEntries that contains no EncryptionEntry items in a DSC transmitted by the client. |
| CR-SYS-0310 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall expect an ASN.1 SEQUENCE tag with length zero for ItemEntries that contains no items in a DSC transmitted by the client. |
| CR-CYBER-0087 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R21 | The server shall support an empty DSC containing only Metadata (version and id) and the empty sequences for verificationEntries, encryptionEntries and ItemEntries. |
| CR-CYBER-0088 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R5R16R19 | A DSC containing only version and id states that verification and encryption is not to be performed by the server, although the server shall have the support. |
| CR-SYS-0311 | — | SYS | Design constraint | Low | COMPLIANT | — | VerificationEntry hashCmp states that a hash comparison shall be used to verify the data. |
| CR-SYS-0312 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R19 | However, the instance specification may state specialized actions: • Server processes each VerificationEntry one by one. |
| CR-SYS-0313 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | • hashAlgorithm: States which HashAlgorithm (see RFC 6234) shall be used for hashing the data to verify. |
| CR-CYBER-0089 | — | CYBER | Design constraint | Low | COMPLIANT | — | • dataRanges: sequence of Range items - Range: Information on which data chunks that shall be verified. |
| CR-SYS-0314 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support the SHA512 HashAlgorithm as referred in 3.2 ASN1 definition. |
| CR-SYS-0315 | — | SYS | Design constraint | Low | NON-COMPLIANT | R2R32 | For crypto agility reasons, both of the choices shall be supported by the server. |
| CR-SYS-0316 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The initial counter value shall be set to 0 (zero). |
| CR-SYS-0317 | — | SYS | Design constraint | Low | COMPLIANT | — | Range: Information on which data chunks that shall be decrypted. |
| CR-SYS-0318 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The structure version for this document release shall be: Major ‘04’ and Minor ‘00’ |
| CR-CYBER-0090 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R21 | The server shall have support for the ASN.1 contents as defined: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp } |
| CR-SYS-0319 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | Upon reception of a DSC to the server, before the DSC is stored in NVM, the DSC shall be semantically verified by parsing all its content. |
| CR-SYS-0320 | — | SYS | Design constraint | Low | COMPLIANT | — | The length of the version field shall be verified. |
| CR-SYS-0321 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | The version shall be verified with the servers supported Major and Minor version of the DSC logic for compliancy. |
| CR-SYS-0322 | — | SYS | Design constraint | Low | COMPLIANT | — | The length of the id field shall be verified. |
| CR-SYS-0323 | — | SYS | Design constraint | Low | NON-COMPLIANT | R2 | The hashAlgorithm shall be supported by the server. |
| CR-SYS-0324 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26 | The length of every referenceHash shall be consistent with the output size of the hash algorithm specified in the hashAlgorithm. |
| CR-CYBER-0091 | — | CYBER | Design constraint | Low | COMPLIANT | — | The verification of servers support of specified dataRanges in the VerificationEntry, shall be stated for the DSC instance. |
| CR-CYBER-0092 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R2 | The EncryptionEntry algorithm shall be supported by the server. |
| CR-CYBER-0093 | — | CYBER | Design constraint | High | NON-COMPLIANT | R19 | The length of key and iv shall be verified accordingly to the algorithm stipulated in EncryptionEntry. |
| CR-CYBER-0094 | — | CYBER | Design constraint | Low | COMPLIANT | — | The verification of servers support of specified dataRanges in the EncryptionEntry, shall be stated for the DSC instance. |
| CR-SYS-0325 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | If the DSC instance is rejected by the server (see Annex A) when transmitted with EMP, an error code shall be returned to the client. |
| CR-CYBER-0095 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R19R21 | The sequence tags for verificationEntries, encryptionEntries and itemEntries are required but empty (zero length). |
| CR-SYS-0326 | — | SYS | Design constraint | Low | COMPLIANT | — | The User shall apply the latest version of this CVS31. |
| CR-SYS-0327 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R8R19R26R32R34 | Foreword This CVS31 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable. |
| CR-SYS-0328 | — | SYS | Design constraint | Low | NON-COMPLIANT | R32 | • Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch. |
| CR-SW-0202 | 1.1 | SW | Functional | Low | NON-COMPLIANT | R16R19R20R21R32 | The purpose of this document is to clarify vehicle manufacture specific extensions and exceptions to the Authentication 0x29 service specified in ISO 14229-1:2020. CVS150 Cryptographic Specification CVS32 SecuredDataTransmis sion 0x84 CVS151 RBAC CVS33 Entity Management Protocol (EMP) CVS31 Authenticate 0x29 CVS124 Traton Specification on Unified diagnostic services (UDS) CVS30 X.509 Specification CVS34 EMP – Basic Entities Figure 1 – Overview of relation between specifications The following documents are normative and indispensable for the application of this document: • Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) • ISO 14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements Whenever a requirement in this specification or the Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) is non-compliant with one or more requirements in ISO 14229-1:2020 the requirements in this specification and (CVS124) take precedence. Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer. It is the vehicle manufacturer that decides if a deviation can be accepted or not. Multiple security concepts are available in the Authentication (ISO 14229-1:2020) service, however, only APCE (ISO 14229-1:2020) is supported by the concept described in this document, see Figure 2. |
| CR-SYS-0329 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R32 | Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer. |
| CR-SYS-0330 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | Shall be agreed between the supplier and the vehicle manufacturer. |
| CR-SW-0203 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message. |
| CR-SW-0204 | — | SW | Functional | Low | COMPLIANT | — | If such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response. |
| CR-CYBER-0096 | — | CYBER | Design constraint | Low | COMPLIANT | — | The request for verifyCertificateBidirectional subfunction shall be formatted according to |
| CR-CYBER-0097 | — | CYBER | Design constraint | Low | COMPLIANT | — | If upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request. |
| CR-CYBER-0098 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R2R7R19 | The column “Included in proofOfOwnershipServer”, present in several message-definition tables, indicates whether the corresponding field shall be covered by the proofOfOwnershipServer signature computed by the server and included in its response. |
| CR-CYBER-0099 | — | CYBER | Design constraint | Medium | COMPLIANT | — | If the server verifies the client certificate as valid, the server shall create the requested client authentication pending state. |
| CR-SYS-0331 | — | SYS | Design constraint | Low | COMPLIANT | — | If an authentication pending state already exists, the server shall replace the existing |
| CR-SYS-0332 | — | SYS | Design constraint | Low | NON-COMPLIANT | R24 | This field shall consists of 32 octets. |
| CR-SW-0205 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The challengeClient (ISO 14229-1:2020) shall be generated using a CRNG. |
| CR-SW-0206 | — | SW | Functional | Low | COMPLIANT | — | The expected range values of lengthOfCertificateClient shall be from 0x00C8 to 0x0800. |
| CR-CYBER-0100 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request. |
| CR-SW-0207 | — | SW | Functional | Low | NON-COMPLIANT | R16R21R34 | If the lengthOfCertificateClient value is not within the expected range, the server shall send negative response code 0x13 (incorrectMessageLengthOrInvalidFormat). |
| CR-SYS-0333 | — | SYS | Design constraint | Low | COMPLIANT | — | Upon positively responding, the server shall start the Authentication completion timer. |
| CR-SYS-0334 | — | SYS | Design constraint | Low | COMPLIANT | — | The challengeServer field shall consists of 32 octets generated using a CRNG. |
| CR-CYBER-0101 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R17 | The proof/signature shall be generated according to the pseudo code below. |
| CR-SW-0208 | — | SW | Functional | Low | NON-COMPLIANT | R21 | If upon reception of verifyCertificateBidirectional request the Authentication delay timer is running, the server shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x37, indicating requiredTimeDelayNotExpired. |
| CR-SW-0209 | — | SW | Functional | High | NON-COMPLIANT | R21 | If the server verifies the client certificate as invalid, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x10, indicating generalReject. |
| CR-SW-0210 | — | SW | Functional | Low | NON-COMPLIANT | R16R19R21 | If the server fails or cannot determine that the authentication pending state was stored, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. |
| CR-CYBER-0102 | — | CYBER | Design constraint | Low | COMPLIANT | — | If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client. |
| CR-HW-0049 | — | HW | Design constraint | Low | COMPLIANT | — | If an existing authentication pending state is found, the server shall verify if the Authentication completion timer is currently running. |
| CR-HW-0050 | — | HW | Design constraint | Low | COMPLIANT | — | If the Authentication completion timer is currently running, the server shall continue to process the client’s proofOfOwnership request. |
| CR-CYBER-0103 | — | CYBER | Design constraint | Low | COMPLIANT | — | If the client proofOfOwnership signature verification fails, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request. |
| CR-SYS-0335 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R19 | If the server fails or cannot determine that the authentication state was stored, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request. |
| CR-CYBER-0104 | — | CYBER | Design constraint | Low | COMPLIANT | — | If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client. |
| CR-SYS-0336 | — | SYS | Design constraint | Low | COMPLIANT | — | If an active authentication state already exists, the server shall replace the existing state with the newly established one. |
| CR-SYS-0337 | — | SYS | Design constraint | Low | COMPLIANT | — | The proofOfOwnershipClient shall be generated according to the pseudo code below. |
| CR-CYBER-0105 | — | CYBER | Design constraint | Low | COMPLIANT | — | The signature shall be generated according to the pseudo code below. |
| CR-SW-0211 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | If the server determines that the client does not have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError. |
| CR-SW-0212 | — | SW | Functional | Low | NON-COMPLIANT | R19R21 | If the server determines that the client have an existing authentication pending state and the Authentication completion timer is expired, the server shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError. |
| CR-SW-0213 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | If the server cannot determine if the client does have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. |
| CR-SW-0214 | — | SW | Functional | Low | NON-COMPLIANT | R21 | If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server determines that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x10, indicating generalReject. |
| CR-SW-0215 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server cannot determine that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. |
| CR-SW-0216 | — | SW | Functional | Low | NON-COMPLIANT | R21 | If the server is deleting the authentication pending state as consequence of failure to store the authentication state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable. |
| CR-SYS-0338 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17 | The server shall delete/invalidate the client’s authentication prior to positively responding to the deAuthenticate request. |
| CR-SW-0217 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | If the server determines that the client is not currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x24, indicating a requestSequenceError. |
| CR-SW-0218 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | If the server cannot determine that the client is currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x94, indicating a ResourceTemporarilyNotAvailable. |
| CR-SW-0219 | — | SW | Functional | Low | NON-COMPLIANT | R10R16R19R21 | If the server is unable to delete the client's authentication state or cannot verify its presence, it shall respond to the deAuthenticate request with Negative Response Code (NRC) 0x94, |
| CR-SW-0220 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R10R16R19 | If the server is unable to delete the client’s authentication state or cannot retrieve it due to internal errors, the server responds NRC 0x94.This informs the client that the authentication state may still exist on the server. |
| CR-CYBER-0106 | — | CYBER | Design constraint | Low | COMPLIANT | — | The signature algorithm used throughout the authentication process shall be ED25519. |
| CR-CYBER-0107 | — | CYBER | Design constraint | Highest | COMPLIANT | — | The client shall use the private key corresponding to the client certificate to generate the signatures. |
| CR-CYBER-0108 | — | CYBER | Design constraint | Highest | COMPLIANT | — | The server shall use the private key corresponding to the server certificate to generate the signatures. |
| CR-CYBER-0109 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R19R21 | The format and the structure of the certificates shall be based on (CVS30). |
| CR-CYBER-0110 | — | CYBER | Design constraint | Highest | COMPLIANT | — | The server shall reject a received client’s certificate, sent using the verifyCertificateBidirectional subFunction, if it matches the server’s own certificate. |
| CR-CYBER-0111 | — | CYBER | Design constraint | Highest | NON-COMPLIANT | R1R2R16R17R24 | It should not be possible to “unlock” the server using its own key/certificate. |
| CR-CYBER-0112 | — | CYBER | Design constraint | High | COMPLIANT | — | The server shall verify the client certificate, sent using the verifyCertificateBidirectional subFunction, according to Figure 3. |
| CR-CYBER-0113 | — | CYBER | Design constraint | High | COMPLIANT | — | The server shall verify the Signature of the Client certificate using the AUTH-CA EMP entity public key. |
| CR-SW-0221 | — | SW | Functional | High | NON-COMPLIANT | R16R21 | • If the server NodeUID is not found in the NodeUID extension, the server shall reject the certificate and generate NRC 0x10 (generalReject). |
| CR-SYS-0339 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16 | If the NodeUID extension is not detected, the operation shall continue as in |
| CR-SW-0222 | — | SW | Functional | High | COMPLIANT | — | The ECU-Diagnostic role extension shall be included in the client certificate. |
| CR-SYS-0340 | — | SYS | Design constraint | Low | COMPLIANT | — | The roles shall correspond to a bit pattern-octet string. |
| CR-CYBER-0114 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R19 | The interpretation of the roles should follow as the example below: • Role 1 -> 0000 0000 0000 0000 0000 0000 0000 0001 – 00 00 00 01 • Role 32 -> 1000 0000 0000 0000 0000 0000 0000 0000 – 80 00 00 00 • Role 2 and 4 -> 0000 0000 0000 0000 0000 0000 0000 1010 – 00 00 00 0A. |
| CR-SW-0223 | — | SW | Functional | Low | NON-COMPLIANT | R1R2R32 | While the ECU-Diagnostic Role extension specifies the roles assigned to a client, the D-RBACC extension may both grant additional permissions and restrict permissions beyond those derived from the client’s roles. |
| CR-CYBER-0115 | — | CYBER | Design constraint | Low | COMPLIANT | — | If D-RBACC extension is detected, the server shall overrule the RBACC with the D-RBACC permissions. |
| CR-CYBER-0116 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R26R32 | • The server shall validate the D-RBACC by parsing all its content. If content is invalid, |
| CR-SW-0224 | — | SW | Functional | High | NON-COMPLIANT | R21 | If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject. |
| CR-CYBER-0117 | — | CYBER | Design constraint | Low | COMPLIANT | — | • The server shall verify that the D-RBACC version provided by the client is compatible with the server’s supported D-RBACC version. |
| CR-SW-0225 | — | SW | Functional | High | NON-COMPLIANT | R21 | If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject. |
| CR-SYS-0341 | — | SYS | Design constraint | Low | COMPLIANT | — | The basicConstraints extension CA field shall be False. |
| CR-CYBER-0118 | — | CYBER | Design constraint | Highest | NON-COMPLIANT | R21 | The Key Usage extension (RFC 5280) shall be included in the client certificate. |
| CR-CYBER-0119 | — | CYBER | Design constraint | High | COMPLIANT | — | The Key Usage extension shall contain DigitalSignature. |
| CR-CYBER-0120 | — | CYBER | Design constraint | Highest | NON-COMPLIANT | R21 | The Extended Key Usage extension (RFC 5280) shall be included in the client certificate. |
| CR-SYS-0342 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The extension ExtendedKeyUsage shall contain clientAuth (1.3.6.1.5.5.7.3.2). |
| CR-CYBER-0121 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R21 | The extension SignatureAlgorithm shall contain ED25519 (1.3.101.112). |
| CR-CYBER-0122 | — | CYBER | Design constraint | High | NON-COMPLIANT | R20 | The server shall validate the certificate so that: 𝑛𝑜𝑡𝐵𝑒𝑓𝑜𝑟𝑒 ≤ 𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒-𝑡𝑖𝑚𝑒 ≤ 𝑛𝑜𝑡𝐴𝑓𝑡𝑒𝑟 |
| CR-SW-0226 | — | SW | Functional | Medium | NON-COMPLIANT | R21 | If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication pending state. |
| CR-HW-0051 | — | HW | Design constraint | Low | NON-COMPLIANT | R19R21 | If a client and server have successfully completed the authentication process, the server shall invalidate the authentication state in the event of: • The server is reset (i.e server is power cycled). |
| CR-SW-0227 | — | SW | Functional | Medium | NON-COMPLIANT | R21 | If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication state. |
| CR-SYS-0343 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21R34 | The server’s authentication pending state shall contain the minimum of (non-exhaustive list): • Client address that issued the authentication request. |
| CR-SYS-0344 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21R34 | The server’s authentication state shall contain the minimum of (non-exhaustive list): • SessionKey. |
| CR-SYS-0345 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support only one authentication state. |
| CR-SYS-0346 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall support only one authentication pending state. |
| CR-CYBER-0123 | — | CYBER | Design constraint | Low | COMPLIANT | — | The private keys shall be generated using a CRNG. |
| CR-SYS-0347 | — | SYS | Design constraint | Low | COMPLIANT | — | The sessionKey shall be generated according to the pseudo code below. |
| CR-SYS-0348 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The server shall ensure that the sessionKey is exclusively used for the application responsible for communication over securedDataTransmission (CVS32). |
| CR-SYS-0349 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | Solution for a CRNG shall be according to (CVS150). |
| CR-SW-0228 | — | SW | Functional | Low | NON-COMPLIANT | R21R26 | The server shall always allow the Authentication 0x29 service (ISO 14229-1:2020) regardless of |
| CR-SYS-0350 | — | SYS | Design constraint | Low | COMPLIANT | — | Only Passive time-based de-authentication shall be supported. |
| CR-SYS-0351 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall start the timer (A3) after a valid proofOfOwnership has been received. |
| CR-SYS-0352 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26 | The server shall restart the timer (A3) every time a request is received by the same client. |
| CR-SYS-0353 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | If the A3 timer timeouts before a new request is received (from the same client), the server shall invalidate the authentication state. |
| CR-SYS-0354 | — | SYS | Design constraint | Low | COMPLIANT | — | The parameter for passive timeout based deAuthenticate shall be decided in the project. |
| CR-SYS-0355 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R16R19 | The A3 timer differs from S3 timer in terms of expected behavior during timeout and should not be implemented as a single timer. |
| CR-CYBER-0124 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R34 | The delay timer represents the required minimum time between verifyCertificateBidirectional |
| CR-SYS-0356 | — | SYS | Design constraint | Low | COMPLIANT | — | The delay timer shall be set to 1 second. |
| CR-CYBER-0125 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R16 | If the delay timer is not running, the server shall start it as part of verifyCertificateBidirectional request. |
| CR-SYS-0357 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R32 | If the server can determine that a delay is not running after reset, it shall accept a subsequent authentication request without any delay. |
| CR-SYS-0358 | — | SYS | Design constraint | Low | NON-COMPLIANT | R16R32 | If the server cannot determine that a delay is not running after reset, it shall not accept a subsequent authentication request without any delay. |
| CR-SYS-0359 | — | SYS | Design constraint | Low | COMPLIANT | — | The Authentication completion timer shall be set to 1 minute. |
| CR-SYS-0360 | — | SYS | Design constraint | Low | COMPLIANT | — | The User shall apply the latest version of this CVS32. |
| CR-SYS-0361 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R8R19R26R32R34 | Foreword This CVS32 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable. |
| CR-SYS-0362 | — | SYS | Design constraint | Low | NON-COMPLIANT | R32 | • Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch. |
| CR-SW-0229 | 1.3 | SW | Functional | Medium | NON-COMPLIANT | R1R2R7R9R19R26R32 | The mnemonics defined in the ISO14229-1:2020 [1] standard are reused throughout this document. Some paragraphs in this document includes pseudo code. The pseudo code make use of the following notation: 𝑋 || 𝑌 The concatenation of the octet strings 𝑋 and 𝑌 𝑋𝑠𝑒𝑟𝑣𝑒𝑟 𝑋 is owned by the Server 𝑋𝑐𝑙𝑖𝑒𝑛𝑡 𝑋 is owned by the Client The first occurrence of an abbreviation or term in this document will appear italicized to indicate that it is explained in section 1.4 Abbreviations or section 1.5 Terminology. All paragraphs from here on in this document are assigned unique tags, composed of a prefix and an identification number for non-ambiguous identification. SDT_REQ X identifies a requirement, and tag SDT_INFO X is used to denote informational text. Whether a requirement refers to client-side or server-side behavior is clear from the context and the requirement text itself. The keywords “shall”, “should”, “must” and so forth are used in this document and are to be interpreted in accordance with “Key words for use in RFCs to Indicate Requirement Levels” [10]. |
| CR-CYBER-0126 | — | CYBER | Design constraint | High | NON-COMPLIANT | R1R2R9 | The keywords “shall”, “should”, “must” and so forth are used in this document and are to be interpreted in accordance with “Key words for use in RFCs to Indicate Requirement Levels” [10]. |
| CR-SYS-0363 | — | SYS | Design constraint | Low | NON-COMPLIANT | R21 | The implementation of SDT (SecuredDataTransmission) shall follow the information provided in |
| CR-SW-0230 | — | SW | Functional | Low | COMPLIANT | — | Whenever a requirement in this document deviates from requirements in ISO14229-1 [1] the requirements of this document shall take precedence. |
| CR-SW-0231 | — | SW | Functional | High | NON-COMPLIANT | R19R26R32 | one diagnostic server in the boot-loader and one in the application, shall support SDT in all execution states. |
| CR-SW-0232 | — | SW | Functional | Low | NON-COMPLIANT | R19 | The SDT server shall use the diagnostic tester address of the SDT client to identify the authentication state and hence the SecuredDataTransmissionKey. |
| CR-SYS-0364 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2R21 | (There may be more than one authentication state). |
| CR-SW-0233 | — | SW | Functional | Low | NON-COMPLIANT | R16R21 | The server shall not allow an SDT message with service 0x84 as the application layer service (service 0x84 encapsulated inside another service 0x84). |
| CR-SW-0234 | — | SW | Functional | Low | COMPLIANT | — | The server shall respond with application layer NRC 0x39, i.e. |
| CR-SYS-0365 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | the response shall be a properly formatted SDT positive 3 ISO 14299-1:2020 Clarifications and Deviations 3.1 Anti-replay Protection and Transaction Coherency Anti-replay protection for SDT messages is provided by the ANTIREPLAYCNT protocol element. |
| CR-SYS-0366 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R32 | Both client and server shall maintain instances of the state variables PREQARC and PRESARC. |
| CR-SYS-0367 | — | SYS | Design constraint | Low | COMPLIANT | — | At construction of an SDT request, the client shall increment PREQARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value. |
| CR-SYS-0368 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R34 | At reception of an SDT request, the server shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PREQARC, and if the message can be otherwise verified, update PREQARC to reflect the new value, i.e. |
| CR-SYS-0369 | — | SYS | Design constraint | Low | COMPLIANT | — | At construction of an SDT response, the server shall increment PRESARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value. |
| CR-SYS-0370 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R34 | At reception of an SDT response, the client shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PRESARC, and if the message can be otherwise verified, update PRESARC to reflect the new value, i.e. |
| CR-SYS-0371 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | The client should populate the ANTIREPLAYCNT protocol element of the first request of an |
| CR-SYS-0372 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | The server should populate the ANTIREPLAYCNT protocol element of the first response of an SDT sequence with the value zero (0), and set PRESARC accordingly. |
| CR-SW-0235 | — | SW | Functional | Low | NON-COMPLIANT | R19R21R34 | If either PREQARC or PRESARC reaches the maximum value 65535 (0xFFFF), the client shall re-authenticate if it wishes to send more messages. |
| CR-SYS-0373 | — | SYS | Design constraint | Low | COMPLIANT | — | The client shall maintain the state variable PREQTAG. |
| CR-CYBER-0127 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R19 | The CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305 shall be supported. |
| CR-CYBER-0128 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R17 | At SDT message reception, the recipient shall verify/decrypt the message using the CipherScheme indicated by the SIGENCRYPT protocol element. |
| CR-CYBER-0129 | — | CYBER | Design constraint | Low | COMPLIANT | — | In case of a positive SDT response, the server shall respond to a client request with the same CipherScheme used in the request. |
| CR-CYBER-0130 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R34 | The client may alter the CipherScheme between SDT requests within the same SDT sequence. |
| CR-CYBER-0131 | — | CYBER | Design constraint | High | NON-COMPLIANT | R1R2 | Client and server should keep state variables that indicate which CipherScheme, and resulting key, was used in the previous SDT transaction. |
| CR-CYBER-0132 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R17 | At construction of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the client should re-run the KDF, and if and only if the authentication/encryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values. |
| CR-CYBER-0133 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R1R2R17 | At reception of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the server should re-run the KDF, and if and only if the verification/decryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values. |
| CR-CYBER-0134 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R21 | Client Server PREQARC = X PREQTAG=TAG_X PSIGENCRYPT=3 PKEY=p..p Check: ANTIREPLAYCNT > PREQARC SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r decrypt(data, TAG_X+1)->ok Check: ANTIREPLAYCNT > PRESARC decrypt(data||PREQTAG, TAG_Y+1)->ok PRESARC = Y+1 PRESARC = Y+1 PREQARC = X PSIGENCRYPT=3 PKEY=p..p encrypt(data)->TAG_X+1 encrypt(data||TAG_X+1)->TAG_Y+1 S1 S2 S3 C1 C2 C3 SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r Figure 4 – Change of CipherScheme mid sequence 3.2.1 HKDF Key Derivation Client and server shall support the HKDF [2] key derivation function using HMAC-SHA512 [3]. |
| CR-SW-0236 | — | SW | Functional | Low | COMPLIANT | — | ikm : The ikm argument to the HKDF function shall be the octet string containing the SecuredDataTransmissionKey from the service 0x29 authentication state. |
| CR-CYBER-0135 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R21 | salt: The salt argument to the HKDF function shall be set as the zero length octet string (null). |
| CR-SW-0237 | — | SW | Functional | Low | NON-COMPLIANT | R19 | info: The info argument to the HKDF function shall be set as the concatenation of the “SDT_0x84_KEY” octet string and the CipherScheme identifier. |
| CR-CYBER-0136 | — | CYBER | Design constraint | Low | COMPLIANT | — | The L argument to the HKDF function shall be set to 64. |
| CR-CYBER-0137 | — | CYBER | Design constraint | Highest | COMPLIANT | — | Octets 0-31 of the okm shall be used as key by the client to encrypt, and the server to decrypt, the request. |
| CR-CYBER-0138 | — | CYBER | Design constraint | Highest | COMPLIANT | — | Octets 32-63 of the okm shall be used as key by the server to encrypt, and the client to decrypt, the response. |
| CR-CYBER-0139 | — | CYBER | Design constraint | Highest | NON-COMPLIANT | R18R19R21 | Figure 5 – Use of HKDF output key material (okm) with SDT_CHACHA20_POLY1305 In subsequent sections (3.2.2.1 and 3.2.2.2) the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets. |
| CR-SYS-0374 | — | SYS | Design constraint | Low | NON-COMPLIANT | R18 | 𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT. |
| CR-SYS-0375 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R21 | 𝑃: The 𝑃 (Plaintext) argument shall be the octet string that is the concatenation of the INTMSGREQID and SRVSPECPARAM. |
| CR-SYS-0376 | — | SYS | Design constraint | Low | COMPLIANT | — | 𝐶: When injected into, or extracted from an SDT message, the first octet of 𝐶 shall correspond to INTMSGREQID, and the remaining octets to SRVSPECPARAM. |
| CR-CYBER-0140 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R19 | The client shall encrypt and authenticate the SDT request with the 𝐴 argument set to the |
| CR-SYS-0377 | — | SYS | Design constraint | Low | NON-COMPLIANT | R20 | The client shall populate the APAR protocol element in the request so that bits 0, 4, 5 and 6 are set to true. |
| CR-SW-0238 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The client shall populate the SIGLEN protocol element in the request with 16 (0x0010). |
| CR-SYS-0378 | — | SYS | Design constraint | Low | COMPLIANT | — | The client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺. |
| CR-SYS-0379 | — | SYS | Design constraint | Low | COMPLIANT | — | The client shall store 𝑇𝐴𝐺 in its state variable PREQTAG. |
| CR-CYBER-0141 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R17R21 | 𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑑𝑒𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝐶, 𝑇𝐴𝐺) → 𝑜𝑘/𝑛𝑜𝑘, 𝑃 The client shall decrypt and verify the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN, ANTIREPLAYCNT protocol elements of the response and the value stored in the state variable PREQTAG. |
| CR-CYBER-0142 | — | CYBER | Design constraint | Low | COMPLIANT | — | The server shall decrypt and verify the SDT request with the 𝐴 argument set to the concatenated octet string comprised of the SDT, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements. |
| CR-CYBER-0143 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R21 | 𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑒𝑛𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝑃) → 𝐶, 𝑇𝐴𝐺 The server shall encrypt and authenticate the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the octet string carried by the SIGMACBYTE protocol element of the corresponding request. |
| CR-SYS-0380 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19R20 | The server shall populate the APAR protocol element in the response so that bits 4 and 5 are set to true. |
| CR-SW-0239 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The server shall populate the SIGLEN protocol element in the request with 16 (0x0010). |
| CR-SYS-0381 | — | SYS | Design constraint | Low | COMPLIANT | — | The server shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺. |
| CR-SYS-0382 | — | SYS | Design constraint | Low | NON-COMPLIANT | R1R2 | one octet, and the rest should go in the SRVSPECPARAM protocol element. |
| CR-CYBER-0144 | — | CYBER | Design constraint | Low | COMPLIANT | — | The L argument to the HKDF function shall be set to 64. |
| CR-CYBER-0145 | — | CYBER | Design constraint | Medium | COMPLIANT | — | Octets 0-31 of the okm shall be used as key by the client to authenticate, and the server to verify, the request. |
| CR-CYBER-0146 | — | CYBER | Design constraint | Medium | COMPLIANT | — | Octets 32-63 of the okm shall be used as key by the server to authenticate, and the client to verify, the response. |
| CR-CYBER-0147 | — | CYBER | Design constraint | Highest | NON-COMPLIANT | R18R19R21 | Figure 7 – Use of HKDF output key material (okm) with SDT_POLY1305 In subsequent sections (3.2.3.1 and 3.2.3.2), the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets. |
| CR-SYS-0383 | — | SYS | Design constraint | Low | NON-COMPLIANT | R18 | 𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT. |
| CR-SYS-0384 | — | SYS | Design constraint | Low | COMPLIANT | — | The client shall authenticate the SDT request with the 𝐴 argument set to the octet string |
| CR-SYS-0385 | — | SYS | Design constraint | Low | NON-COMPLIANT | R20 | The client shall populate the APAR protocol element in the request so that bits 0, 5 and 6 are set to true. |
| CR-SW-0240 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The client shall populate the SIGLEN protocol element in the request with 16 (0x0010). |
| CR-SYS-0386 | — | SYS | Design constraint | Low | COMPLIANT | — | The client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺. |
| CR-SYS-0387 | — | SYS | Design constraint | Low | COMPLIANT | — | The client shall store 𝑇𝐴𝐺 in its state variable PREQTAG. |
| CR-SYS-0388 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | The client shall verify the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string stored in the state variable PREQTAG. |
| CR-SYS-0389 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | The server shall verify the SDT request with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element. |
| CR-SYS-0390 | — | SYS | Design constraint | Low | NON-COMPLIANT | R26R32 | The server shall authenticate the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string carried by the SIGMACBYTE protocol element of the corresponding request. |
| CR-SYS-0391 | — | SYS | Design constraint | Low | NON-COMPLIANT | R20 | The server shall populate the APAR protocol element in the response so that bit 5 is set to true. |
| CR-SW-0241 | — | SW | Functional | Low | NON-COMPLIANT | R21 | The server shall populate the SIGLEN protocol element in the response with 16 (0x0010). |
| CR-SYS-0392 | — | SYS | Design constraint | Low | COMPLIANT | — | The client shall populate the SIGMACBYTE protocol element in the response with 𝑇𝐴𝐺. |
| CR-SW-0242 | — | SW | Functional | Medium | NON-COMPLIANT | R1R2 | The SDT positive response may of course contain an encapsulated negative UDS response. |
| CR-SW-0243 | — | SW | Functional | Low | COMPLIANT | — | Other than the NRCs 0x3A, 0x13 and 0x21, specified by ISO14229-1:2020 [1], the server shall support the NRC 0x34 “authenticationRequired”. |
| CR-CYBER-0148 | — | CYBER | Design constraint | Low | COMPLIANT | — | At reception of an SDT request, if the security sub-layer is busy, the server shall respond with |
| CR-SW-0244 | — | SW | Functional | Low | COMPLIANT | — | At reception of an SDT request, if the requesting client is unauthenticated, the server shall respond with an SDT negative response using the NRC 0x34. |
| CR-SW-0245 | — | SW | Functional | Low | NON-COMPLIANT | R19 | At reception of an SDT request, if the request is too short or otherwise malformed, the server shall respond with an SDT negative response using the NRC 0x13. |
| CR-SW-0246 | — | SW | Functional | Low | COMPLIANT | — | At reception of an SDT request, if ANTIREPLAYCNT ≤ PREQARC, the server shall respond with an SDT negative response using the NRC 0x3A. |
| CR-SW-0247 | — | SW | Functional | Low | COMPLIANT | — | At reception of an SDT request, if PRESARC is exhausted, the server shall respond with an SDT negative response using the NRC 0x3A. |
| CR-SW-0248 | — | SW | Functional | Low | NON-COMPLIANT | R16 | At reception of an SDT request, if SIGENCRYPT is not supported, the server shall respond with an SDT negative response using the NRC 0x3A. |
| CR-SW-0249 | — | SW | Functional | Low | COMPLIANT | — | At reception of an SDT request, if APAR is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A. |
| CR-SW-0250 | — | SW | Functional | Low | COMPLIANT | — | At reception of an SDT request, if SIGLEN is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A. |
| CR-SW-0251 | — | SW | Functional | Low | NON-COMPLIANT | R17 | At reception of an SDT request, if the server fails to verify/decrypt the request, the server shall respond with an SDT negative response using the NRC 0x3A. |
| CR-SYS-0393 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R21 | The server shall update its state, (set PREQARC to the value received in the ANTIREPLAYCNT protocol element in the SDT request), if and only if it successfully verifies/decrypts the SDT request. |
| CR-CYBER-0149 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R17R21 | The server shall update its state, (increment PRESARC by one (1)), if and only if it can successfully authenticate/encrypt the SDT response (“S3”). |
| CR-CYBER-0150 | — | CYBER | Design constraint | Medium | NON-COMPLIANT | R17R21 | The client shall update its state, (increment PREQARC by one (1), if and only if it can successfully authenticate/encrypt the SDT request (“C2”). |
| CR-SYS-0394 | — | SYS | Design constraint | Low | COMPLIANT | — | At reception of an SDT response, if the client is unauthenticated, the client shall discard the |
| CR-SYS-0395 | — | SYS | Design constraint | Low | NON-COMPLIANT | R19 | At reception of an SDT response, if the request is too short or otherwise malformed, the client shall discard the response. |
| CR-SYS-0396 | — | SYS | Design constraint | Low | COMPLIANT | — | At reception of an SDT response, if ANTIREPLAYCNT ≤ PRESARC, the client shall discard the |
| CR-CYBER-0151 | — | CYBER | Design constraint | Low | NON-COMPLIANT | R16 | At reception of an SDT response, if SIGENCRYPT is not supported, the client shall discard the |
| CR-CYBER-0152 | — | CYBER | Design constraint | Low | COMPLIANT | — | At reception of an SDT response, if APAR is in conflict with SIGENCRYPT, the client shall discard the response. |
| CR-CYBER-0153 | — | CYBER | Design constraint | Low | COMPLIANT | — | At reception of an SDT response, if SIGLEN is in conflict with SIGENCRYPT, the client shall discard the response. |
| CR-SYS-0397 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17 | At reception of an SDT response, if the client fails to verify/decrypt the response, the client shall discard the response. |
| CR-SYS-0398 | — | SYS | Design constraint | Low | NON-COMPLIANT | R17R21 | The client shall update its state, (set PRESARC to the value received in the ANTIREPLAYCNT protocol element in the SDT response), if and only if it successfully verifies/decrypts the SDT response (“C3”). |
| CR-SW-0252 | — | SW | Functional | Low | NON-COMPLIANT | R21 | If the client determines an SDT request to be lost in transit, or, if it receives an SDT negative response with NRC BRR (0x21), the client shall • repeat the request byte for byte and leave state variables unchanged. |
Stakeholder needs (202)
| Need ID | Area | Stakeholder | Need statement | Derived SSR(s) | Prio |
|---|---|---|---|---|---|
| N-CYBER-001 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to implement the defined cybersecurity concept. | SSR-CYBER-0001, SSR-CYBER-0002, SSR-CYBER-0003, SSR-CYBER-0002-2, SSR-CYBER-0003-2 | High |
| N-CYBER-002 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to provide the specified engineering evidence. | SSR-CYBER-0004, SSR-CYBER-0005 | Low |
| N-CYBER-003 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to provide the cybersecurity risk-analysis evidence. | SSR-CYBER-0006, SSR-CYBER-0007, SSR-CYBER-0008, SSR-CYBER-0009, SSR-CYBER-0010 | Medium |
| N-SYS-001 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to support the specified approval gate. | SSR-SYS-0001, SSR-SYS-0002, SSR-SYS-0003, SSR-SYS-0004, SSR-SYS-0005, SSR-SYS-0006, SSR-SYS-0005-2, SSR-SYS-0005-3 | Medium |
| N-VAL-001 | VAL | KA project organization | The KA project organization needs the ECA to provide the specified engineering evidence. | SSR-VAL-0001, SSR-VAL-0002, SSR-VAL-0003, SSR-VAL-0004, SSR-VAL-0002-2 | Medium |
| N-CYBER-004 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the cybersecurity obligation defined in the traced customer requirements. | SSR-CYBER-0011, SSR-CYBER-0012, SSR-CYBER-0013, SSR-CYBER-0014, SSR-CYBER-0015, SSR-CYBER-0016 | Low |
| N-CYBER-005 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the cybersecurity obligation defined in the traced customer requirements. | SSR-CYBER-0017, SSR-CYBER-0018, SSR-CYBER-0019, SSR-CYBER-0020, SSR-CYBER-0021, SSR-CYBER-0022 | Low |
| N-CYBER-006 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the cybersecurity obligation defined in the traced customer requirements. | SSR-CYBER-0023, SSR-CYBER-0024, SSR-CYBER-0025, SSR-CYBER-0026, SSR-CYBER-0027, SSR-CYBER-0028 | High |
| N-CYBER-007 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to undergo the specified cybersecurity testing. | SSR-CYBER-0029 | High |
| N-SYS-002 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0007, SSR-SYS-0008, SSR-SYS-0009, SSR-SYS-0010, SSR-SYS-0011, SSR-SYS-0012 | Low |
| N-SYS-003 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0013, SSR-SYS-0014, SSR-SYS-0015, SSR-SYS-0016, SSR-SYS-0017, SSR-SYS-0018 | Low |
| N-SYS-004 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0019, SSR-SYS-0020, SSR-SYS-0021, SSR-SYS-0022, SSR-SYS-0023, SSR-SYS-0024 | Low |
| N-SYS-005 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0025, SSR-SYS-0026, SSR-SYS-0027, SSR-SYS-0028, SSR-SYS-0029, SSR-SYS-0030 | Low |
| N-SYS-006 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0031, SSR-SYS-0032, SSR-SYS-0033, SSR-SYS-0034, SSR-SYS-0035, SSR-SYS-0036 | Low |
| N-SYS-007 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0037, SSR-SYS-0038, SSR-SYS-0039, SSR-SYS-0040, SSR-SYS-0041, SSR-SYS-0042, SSR-SYS-0039-2 | Low |
| N-SYS-008 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0043, SSR-SYS-0044, SSR-SYS-0045, SSR-SYS-0046, SSR-SYS-0047, SSR-SYS-0048 | Low |
| N-SYS-009 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0049, SSR-SYS-0050, SSR-SYS-0051, SSR-SYS-0052, SSR-SYS-0053, SSR-SYS-0054 | Low |
| N-SYS-010 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0055, SSR-SYS-0056, SSR-SYS-0057, SSR-SYS-0058, SSR-SYS-0059, SSR-SYS-0060 | Low |
| N-SYS-011 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0061, SSR-SYS-0062, SSR-SYS-0063, SSR-SYS-0064, SSR-SYS-0065, SSR-SYS-0066 | Low |
| N-SYS-012 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0067, SSR-SYS-0068, SSR-SYS-0069, SSR-SYS-0070, SSR-SYS-0071, SSR-SYS-0072 | Low |
| N-SYS-013 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0073, SSR-SYS-0074, SSR-SYS-0075, SSR-SYS-0076, SSR-SYS-0077, SSR-SYS-0078 | Low |
| N-SYS-014 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0079, SSR-SYS-0080, SSR-SYS-0081, SSR-SYS-0082, SSR-SYS-0083, SSR-SYS-0084 | Low |
| N-SYS-015 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0085, SSR-SYS-0086, SSR-SYS-0087, SSR-SYS-0088, SSR-SYS-0089, SSR-SYS-0090 | Low |
| N-SYS-016 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0091, SSR-SYS-0092, SSR-SYS-0093, SSR-SYS-0094, SSR-SYS-0095, SSR-SYS-0096 | Low |
| N-SYS-017 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0097, SSR-SYS-0098, SSR-SYS-0099, SSR-SYS-0100, SSR-SYS-0101, SSR-SYS-0102, SSR-SYS-0099-2 | Low |
| N-SYS-018 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0103, SSR-SYS-0104, SSR-SYS-0105, SSR-SYS-0106, SSR-SYS-0107, SSR-SYS-0108 | Low |
| N-SYS-019 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0109, SSR-SYS-0110, SSR-SYS-0111, SSR-SYS-0112, SSR-SYS-0113, SSR-SYS-0114 | Low |
| N-SYS-020 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0115, SSR-SYS-0116, SSR-SYS-0117, SSR-SYS-0118, SSR-SYS-0119, SSR-SYS-0120 | Low |
| N-SYS-021 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0121, SSR-SYS-0122, SSR-SYS-0123, SSR-SYS-0124, SSR-SYS-0125, SSR-SYS-0126 | Low |
| N-SYS-022 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0127, SSR-SYS-0128, SSR-SYS-0129, SSR-SYS-0130, SSR-SYS-0131, SSR-SYS-0132, SSR-SYS-0128-2, SSR-SYS-0129-2 | Low |
| N-SYS-023 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0133, SSR-SYS-0134, SSR-SYS-0135, SSR-SYS-0136, SSR-SYS-0137, SSR-SYS-0138 | Low |
| N-SYS-024 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0139, SSR-SYS-0140, SSR-SYS-0141, SSR-SYS-0142, SSR-SYS-0143, SSR-SYS-0144 | Low |
| N-SYS-025 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0145, SSR-SYS-0146, SSR-SYS-0147, SSR-SYS-0148, SSR-SYS-0149, SSR-SYS-0150 | Low |
| N-SYS-026 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0151, SSR-SYS-0152, SSR-SYS-0153, SSR-SYS-0154, SSR-SYS-0155, SSR-SYS-0156 | Low |
| N-SYS-027 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0157, SSR-SYS-0158, SSR-SYS-0159, SSR-SYS-0160, SSR-SYS-0161, SSR-SYS-0162 | Low |
| N-SYS-028 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0163, SSR-SYS-0164, SSR-SYS-0165, SSR-SYS-0166, SSR-SYS-0167, SSR-SYS-0168, SSR-SYS-0165-2 | Low |
| N-SYS-029 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0169, SSR-SYS-0170, SSR-SYS-0171, SSR-SYS-0172, SSR-SYS-0173, SSR-SYS-0174 | Low |
| N-SYS-030 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0175, SSR-SYS-0176, SSR-SYS-0177, SSR-SYS-0178, SSR-SYS-0179, SSR-SYS-0180 | Low |
| N-SYS-031 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0181, SSR-SYS-0182, SSR-SYS-0183, SSR-SYS-0184, SSR-SYS-0185, SSR-SYS-0186 | Low |
| N-SYS-032 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0187, SSR-SYS-0188, SSR-SYS-0189, SSR-SYS-0190, SSR-SYS-0191, SSR-SYS-0192 | Low |
| N-SYS-033 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0193, SSR-SYS-0194, SSR-SYS-0195, SSR-SYS-0196, SSR-SYS-0197, SSR-SYS-0198, SSR-SYS-0197-2 | Low |
| N-SYS-034 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0199, SSR-SYS-0200, SSR-SYS-0201, SSR-SYS-0202, SSR-SYS-0203, SSR-SYS-0204 | Low |
| N-SYS-035 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0205, SSR-SYS-0206, SSR-SYS-0207, SSR-SYS-0208, SSR-SYS-0209, SSR-SYS-0210 | Low |
| N-SYS-036 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0211, SSR-SYS-0212, SSR-SYS-0213, SSR-SYS-0214, SSR-SYS-0215, SSR-SYS-0216, SSR-SYS-0214-2, SSR-SYS-0215-2 | Low |
| N-SYS-037 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0217, SSR-SYS-0218, SSR-SYS-0219, SSR-SYS-0220, SSR-SYS-0221, SSR-SYS-0222, SSR-SYS-0218-2, SSR-SYS-0220-2 | Low |
| N-SYS-038 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0223, SSR-SYS-0224, SSR-SYS-0225, SSR-SYS-0226, SSR-SYS-0227, SSR-SYS-0228, SSR-SYS-0228-2, SSR-SYS-0228-3 | Low |
| N-SYS-039 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0229, SSR-SYS-0230, SSR-SYS-0231, SSR-SYS-0232, SSR-SYS-0233, SSR-SYS-0234 | Low |
| N-SYS-040 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0235, SSR-SYS-0236, SSR-SYS-0237, SSR-SYS-0238 | Low |
| N-HW-001 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to provide the bill of materials. | SSR-HW-0001 | Low |
| N-CYBER-008 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities. | SSR-CYBER-0030 | Medium |
| N-CYBER-009 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-CYBER-0031, SSR-CYBER-0032, SSR-CYBER-0033, SSR-CYBER-0034, SSR-CYBER-0035, SSR-CYBER-0036, SSR-CYBER-0035-2 | High |
| N-CYBER-010 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-CYBER-0037, SSR-CYBER-0038 | Medium |
| N-MECH-001 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce the defined network-boundary controls. | SSR-MECH-0001 | Low |
| N-SYS-041 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce the defined network-boundary controls. | SSR-SYS-0239 | Low |
| N-HW-002 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements. | SSR-HW-0002, SSR-HW-0003, SSR-HW-0004, SSR-HW-0005, SSR-HW-0006, SSR-HW-0007 | Low |
| N-HW-003 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements. | SSR-HW-0008, SSR-HW-0009, SSR-HW-0010, SSR-HW-0011, SSR-HW-0012, SSR-HW-0013, SSR-HW-0009-2, SSR-HW-0013-2 | Low |
| N-HW-004 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements. | SSR-HW-0014, SSR-HW-0015, SSR-HW-0016, SSR-HW-0017, SSR-HW-0018, SSR-HW-0019, SSR-HW-0015-2 | Low |
| N-HW-005 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the hardware obligation defined in the traced customer requirements. | SSR-HW-0020, SSR-HW-0021, SSR-HW-0022, SSR-HW-0023, SSR-HW-0024, SSR-HW-0025, SSR-HW-0023-2 | Low |
| N-CYBER-011 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to control cryptographic key handling. | SSR-CYBER-0039, SSR-CYBER-0040, SSR-CYBER-0041, SSR-CYBER-0042, SSR-CYBER-0043, SSR-CYBER-0044 | Highest |
| N-CYBER-012 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to control cryptographic key handling. | SSR-CYBER-0045, SSR-CYBER-0046, SSR-CYBER-0047, SSR-CYBER-0048, SSR-CYBER-0049, SSR-CYBER-0050, SSR-CYBER-0050-2 | Highest |
| N-CYBER-013 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to control cryptographic key handling. | SSR-CYBER-0051, SSR-CYBER-0052, SSR-CYBER-0053, SSR-CYBER-0054, SSR-CYBER-0055, SSR-CYBER-0056, SSR-CYBER-0051-2, SSR-CYBER-0054-2 | Highest |
| N-SYS-042 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to control cryptographic key handling. | SSR-SYS-0240, SSR-SYS-0241 | Low |
| N-CYBER-014 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-CYBER-0057, SSR-CYBER-0058, SSR-CYBER-0059, SSR-CYBER-0060 | Medium |
| N-CYBER-015 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to support vulnerability response. | SSR-CYBER-0061, SSR-CYBER-0062, SSR-CYBER-0063, SSR-CYBER-0064, SSR-CYBER-0065 | Low |
| N-CYBER-016 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to support cybersecurity incident monitoring. | SSR-CYBER-0066, SSR-CYBER-0067, SSR-CYBER-0068, SSR-CYBER-0069, SSR-CYBER-0070 | Medium |
| N-VAL-002 | VAL | KA project organization | The KA project organization needs the ECA to meet the validation obligation defined in the traced customer requirements. | SSR-VAL-0005, SSR-VAL-0006, SSR-VAL-0007, SSR-VAL-0008, SSR-VAL-0009, SSR-VAL-0010, SSR-VAL-0007-2, SSR-VAL-0009-2 | Low |
| N-VAL-003 | VAL | KA project organization | The KA project organization needs the ECA to meet the validation obligation defined in the traced customer requirements. | SSR-VAL-0011, SSR-VAL-0012, SSR-VAL-0013, SSR-VAL-0014, SSR-VAL-0014-2 | Low |
| N-VAL-004 | VAL | KA project organization | The KA project organization needs the ECA to support the specified approval gate. | SSR-VAL-0015 | Medium |
| N-SYS-043 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to support vulnerability response. | SSR-SYS-0242 | Low |
| N-HW-006 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to control cryptographic key handling. | SSR-HW-0026 | Low |
| N-CYBER-017 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to record the specified security events. | SSR-CYBER-0071, SSR-CYBER-0072, SSR-CYBER-0071-2 | High |
| N-SYS-044 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SYS-0243, SSR-SYS-0243-2 | High |
| N-SYS-045 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SYS-0244, SSR-SYS-0245, SSR-SYS-0246, SSR-SYS-0247, SSR-SYS-0248, SSR-SYS-0249, SSR-SYS-0248-2, SSR-SYS-0249-2 | Medium |
| N-SYS-046 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SYS-0250, SSR-SYS-0251, SSR-SYS-0252, SSR-SYS-0253, SSR-SYS-0254, SSR-SYS-0255, SSR-SYS-0250-2, SSR-SYS-0250-3 | Low |
| N-SYS-047 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SYS-0256, SSR-SYS-0257, SSR-SYS-0258, SSR-SYS-0259, SSR-SYS-0260, SSR-SYS-0261, SSR-SYS-0261-2, SSR-SYS-0261-3 | Low |
| N-SYS-048 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SYS-0262, SSR-SYS-0263, SSR-SYS-0264, SSR-SYS-0265, SSR-SYS-0266, SSR-SYS-0267, SSR-SYS-0263-2, SSR-SYS-0263-3 | Low |
| N-SYS-049 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SYS-0268, SSR-SYS-0269, SSR-SYS-0270, SSR-SYS-0271, SSR-SYS-0272, SSR-SYS-0273, SSR-SYS-0268-2 | Low |
| N-SYS-050 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SYS-0274 | Low |
| N-MECH-002 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-MECH-0002, SSR-MECH-0003, SSR-MECH-0004, SSR-MECH-0005, SSR-MECH-0006, SSR-MECH-0007, SSR-MECH-0002-2, SSR-MECH-0002-3 | Medium |
| N-MECH-003 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-MECH-0008, SSR-MECH-0009, SSR-MECH-0010, SSR-MECH-0011, SSR-MECH-0012, SSR-MECH-0013, SSR-MECH-0008-2, SSR-MECH-0009-2 | Low |
| N-MECH-004 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-MECH-0014, SSR-MECH-0015, SSR-MECH-0016, SSR-MECH-0017, SSR-MECH-0014-2, SSR-MECH-0014-3, SSR-MECH-0016-2 | Medium |
| N-MECH-005 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the mechanical obligation defined in the traced customer requirements. | SSR-MECH-0018, SSR-MECH-0019, SSR-MECH-0020, SSR-MECH-0021, SSR-MECH-0022, SSR-MECH-0023, SSR-MECH-0018-2, SSR-MECH-0018-3 | Medium |
| N-MECH-006 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the mechanical obligation defined in the traced customer requirements. | SSR-MECH-0024, SSR-MECH-0025, SSR-MECH-0026, SSR-MECH-0027, SSR-MECH-0028, SSR-MECH-0029, SSR-MECH-0027-2, SSR-MECH-0028-2 | Low |
| N-MECH-007 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the mechanical obligation defined in the traced customer requirements. | SSR-MECH-0030, SSR-MECH-0031, SSR-MECH-0032, SSR-MECH-0033, SSR-MECH-0034, SSR-MECH-0035, SSR-MECH-0030-2, SSR-MECH-0030-3 | Medium |
| N-SYS-051 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to operate within the specified electrical-supply limits. | SSR-SYS-0275, SSR-SYS-0276 | Low |
| N-HW-007 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to acquire the specified sensor measurements. | SSR-HW-0027 | Low |
| N-CYBER-018 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-CYBER-0073, SSR-CYBER-0074, SSR-CYBER-0075, SSR-CYBER-0076, SSR-CYBER-0073-2, SSR-CYBER-0075-2 | Medium |
| N-SYS-052 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SYS-0277, SSR-SYS-0278, SSR-SYS-0279, SSR-SYS-0280, SSR-SYS-0281, SSR-SYS-0282, SSR-SYS-0278-2, SSR-SYS-0278-3 | Low |
| N-SYS-053 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SYS-0283, SSR-SYS-0284, SSR-SYS-0285, SSR-SYS-0286, SSR-SYS-0287, SSR-SYS-0288, SSR-SYS-0286-2, SSR-SYS-0287-2 | Low |
| N-SYS-054 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SYS-0289, SSR-SYS-0290, SSR-SYS-0291, SSR-SYS-0292, SSR-SYS-0293, SSR-SYS-0294, SSR-SYS-0294-2 | Low |
| N-SYS-055 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SYS-0295, SSR-SYS-0296, SSR-SYS-0297, SSR-SYS-0298, SSR-SYS-0299, SSR-SYS-0300, SSR-SYS-0299-2, SSR-SYS-0300-2 | Low |
| N-SYS-056 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SYS-0301, SSR-SYS-0301-2 | Low |
| N-MECH-008 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to operate within the specified thermal limits. | SSR-MECH-0036, SSR-MECH-0037, SSR-MECH-0036-2, SSR-MECH-0036-3 | Low |
| N-SYS-057 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0302, SSR-SYS-0303, SSR-SYS-0304, SSR-SYS-0305, SSR-SYS-0306, SSR-SYS-0307 | Low |
| N-SYS-058 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0308, SSR-SYS-0309, SSR-SYS-0310, SSR-SYS-0311, SSR-SYS-0312, SSR-SYS-0313 | Low |
| N-SYS-059 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the system obligation defined in the traced customer requirements. | SSR-SYS-0314 | Low |
| N-SYS-060 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to regulate clutch torque. | SSR-SYS-0315, SSR-SYS-0316, SSR-SYS-0317, SSR-SYS-0317-2 | Highest |
| N-MECH-009 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to regulate actuator position. | SSR-MECH-0038, SSR-MECH-0039 | Low |
| N-CYBER-019 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-CYBER-0077 | Low |
| N-SYS-061 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to operate within the specified thermal limits. | SSR-SYS-0318 | Low |
| N-SW-001 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to regulate actuator position. | SSR-SW-0001, SSR-SW-0002, SSR-SW-0001-2, SSR-SW-0001-3, SSR-SW-0002-2, SSR-SW-0002-3 | Low |
| N-SYS-062 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to regulate actuator position. | SSR-SYS-0319, SSR-SYS-0320, SSR-SYS-0321 | Low |
| N-SW-002 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to regulate clutch torque. | SSR-SW-0003 | High |
| N-SW-003 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-SW-0004, SSR-SW-0005 | Low |
| N-VAL-005 | VAL | KA project organization | The KA project organization needs the ECA to exchange the specified network signals. | SSR-VAL-0016, SSR-VAL-0017 | Low |
| N-SYS-063 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SYS-0322, SSR-SYS-0322-2 | Low |
| N-SW-004 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SW-0006, SSR-SW-0007, SSR-SW-0008, SSR-SW-0009, SSR-SW-0010, SSR-SW-0011 | Medium |
| N-SW-005 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SW-0012 | Low |
| N-SW-006 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0013, SSR-SW-0014, SSR-SW-0015, SSR-SW-0016, SSR-SW-0017, SSR-SW-0018, SSR-SW-0016-2 | Low |
| N-SW-007 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0019, SSR-SW-0020, SSR-SW-0021, SSR-SW-0022, SSR-SW-0023, SSR-SW-0024 | Low |
| N-SW-008 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0025, SSR-SW-0026, SSR-SW-0027, SSR-SW-0028, SSR-SW-0029, SSR-SW-0030, SSR-SW-0029-2 | Low |
| N-SW-009 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0031, SSR-SW-0032, SSR-SW-0033, SSR-SW-0034, SSR-SW-0035, SSR-SW-0036 | Low |
| N-SW-010 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0037, SSR-SW-0038, SSR-SW-0039, SSR-SW-0040, SSR-SW-0041, SSR-SW-0042, SSR-SW-0041-2 | Low |
| N-SW-011 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0043, SSR-SW-0044, SSR-SW-0045, SSR-SW-0046, SSR-SW-0047, SSR-SW-0048 | Low |
| N-SW-012 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0049, SSR-SW-0050, SSR-SW-0051, SSR-SW-0052, SSR-SW-0053, SSR-SW-0054 | Low |
| N-SW-013 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the software obligation defined in the traced customer requirements. | SSR-SW-0055, SSR-SW-0056, SSR-SW-0057, SSR-SW-0058, SSR-SW-0058-2 | Low |
| N-HW-008 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to operate within the specified thermal limits. | SSR-HW-0028, SSR-HW-0029, SSR-HW-0029-2 | Low |
| N-HW-009 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to operate within the specified electrical-supply limits. | SSR-HW-0030, SSR-HW-0031, SSR-HW-0032, SSR-HW-0033, SSR-HW-0034, SSR-HW-0031-2, SSR-HW-0033-2 | Low |
| N-SW-014 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to provide a verified secure-boot start-up sequence. | SSR-SW-0059, SSR-SW-0059-2, SSR-SW-0059-3, SSR-SW-0059-4, SSR-SW-0059-5 | Medium |
| N-SYS-064 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-SYS-0323, SSR-SYS-0324, SSR-SYS-0325, SSR-SYS-0326, SSR-SYS-0327, SSR-SYS-0328 | Low |
| N-SYS-065 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-SYS-0329, SSR-SYS-0330, SSR-SYS-0331, SSR-SYS-0332, SSR-SYS-0333, SSR-SYS-0334 | Low |
| N-SW-015 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage diagnostic trouble codes. | SSR-SW-0060, SSR-SW-0061, SSR-SW-0062, SSR-SW-0063, SSR-SW-0064, SSR-SW-0065, SSR-SW-0060-2, SSR-SW-0063-2 | High |
| N-SW-016 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage diagnostic trouble codes. | SSR-SW-0066, SSR-SW-0067, SSR-SW-0068, SSR-SW-0069, SSR-SW-0070, SSR-SW-0071 | Low |
| N-SW-017 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage diagnostic trouble codes. | SSR-SW-0072, SSR-SW-0073, SSR-SW-0074, SSR-SW-0075, SSR-SW-0076, SSR-SW-0077 | Low |
| N-SW-018 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage diagnostic trouble codes. | SSR-SW-0078, SSR-SW-0079, SSR-SW-0080, SSR-SW-0081, SSR-SW-0082, SSR-SW-0083 | Low |
| N-SW-019 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage diagnostic trouble codes. | SSR-SW-0084, SSR-SW-0085, SSR-SW-0086, SSR-SW-0087 | Low |
| N-SYS-066 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to record the specified security events. | SSR-SYS-0335, SSR-SYS-0336, SSR-SYS-0337, SSR-SYS-0338, SSR-SYS-0336-2, SSR-SYS-0336-3, SSR-SYS-0336-4 | Low |
| N-HW-010 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-HW-0035, SSR-HW-0036, SSR-HW-0037, SSR-HW-0035-2 | Low |
| N-SYS-067 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-SYS-0339, SSR-SYS-0340, SSR-SYS-0341, SSR-SYS-0342, SSR-SYS-0343, SSR-SYS-0344, SSR-SYS-0339-2 | Low |
| N-SYS-068 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-SYS-0345, SSR-SYS-0346, SSR-SYS-0347, SSR-SYS-0348, SSR-SYS-0349, SSR-SYS-0350 | Low |
| N-SYS-069 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-SYS-0351, SSR-SYS-0352, SSR-SYS-0353, SSR-SYS-0354 | Low |
| N-FUSA-001 | FUSA | vehicle manufacturer | The vehicle manufacturer needs the ECA to satisfy the allocated functional-safety objectives. | SSR-FUSA-0001, SSR-FUSA-0002, SSR-FUSA-0003, SSR-FUSA-0004, SSR-FUSA-0001-2 | High |
| N-FUSA-002 | FUSA | vehicle manufacturer | The vehicle manufacturer needs the ECA to actuate the clutch across the specified drivetrains. | SSR-FUSA-0005 | Medium |
| N-MECH-010 | MECH | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-MECH-0040 | Low |
| N-SW-020 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-SW-0088, SSR-SW-0089, SSR-SW-0090, SSR-SW-0091, SSR-SW-0092, SSR-SW-0093, SSR-SW-0088-2, SSR-SW-0088-3 | Medium |
| N-SW-021 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-SW-0094, SSR-SW-0095, SSR-SW-0096, SSR-SW-0097, SSR-SW-0098, SSR-SW-0099 | Low |
| N-SW-022 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-SW-0100, SSR-SW-0101, SSR-SW-0102, SSR-SW-0103, SSR-SW-0104, SSR-SW-0105 | Low |
| N-HW-011 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-HW-0038, SSR-HW-0039, SSR-HW-0040, SSR-HW-0041, SSR-HW-0042, SSR-HW-0043 | Low |
| N-HW-012 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-HW-0044, SSR-HW-0045 | Low |
| N-SYS-070 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities. | SSR-SYS-0355, SSR-SYS-0356, SSR-SYS-0357, SSR-SYS-0358, SSR-SYS-0359, SSR-SYS-0360, SSR-SYS-0356-2, SSR-SYS-0356-3 | Low |
| N-SYS-071 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities. | SSR-SYS-0361 | Low |
| N-SW-023 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities. | SSR-SW-0106, SSR-SW-0107, SSR-SW-0108, SSR-SW-0109, SSR-SW-0110, SSR-SW-0111, SSR-SW-0109-2, SSR-SW-0109-3 | High |
| N-SW-024 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities. | SSR-SW-0112, SSR-SW-0113, SSR-SW-0114 | High |
| N-SYS-072 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-SYS-0362, SSR-SYS-0363, SSR-SYS-0364, SSR-SYS-0365, SSR-SYS-0366, SSR-SYS-0367, SSR-SYS-0362-2 | Low |
| N-SYS-073 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-SYS-0368, SSR-SYS-0369, SSR-SYS-0370 | Low |
| N-SW-025 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service. | SSR-SW-0115, SSR-SW-0116, SSR-SW-0117, SSR-SW-0118, SSR-SW-0119, SSR-SW-0120 | High |
| N-SW-026 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service. | SSR-SW-0121, SSR-SW-0122, SSR-SW-0123, SSR-SW-0124, SSR-SW-0125, SSR-SW-0126 | Medium |
| N-SW-027 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service. | SSR-SW-0127, SSR-SW-0128, SSR-SW-0129, SSR-SW-0130, SSR-SW-0131, SSR-SW-0132 | Medium |
| N-SW-028 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service. | SSR-SW-0133, SSR-SW-0134, SSR-SW-0135 | Medium |
| N-HW-013 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-HW-0046 | Low |
| N-CYBER-020 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm. | SSR-CYBER-0078, SSR-CYBER-0079, SSR-CYBER-0080, SSR-CYBER-0081, SSR-CYBER-0082, SSR-CYBER-0083 | Low |
| N-CYBER-021 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm. | SSR-CYBER-0084, SSR-CYBER-0085, SSR-CYBER-0086, SSR-CYBER-0087, SSR-CYBER-0088, SSR-CYBER-0089 | Low |
| N-CYBER-022 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm. | SSR-CYBER-0090, SSR-CYBER-0091, SSR-CYBER-0092, SSR-CYBER-0093, SSR-CYBER-0094, SSR-CYBER-0095, SSR-CYBER-0092-2 | High |
| N-CYBER-023 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm. | SSR-CYBER-0096, SSR-CYBER-0097, SSR-CYBER-0098, SSR-CYBER-0099, SSR-CYBER-0100, SSR-CYBER-0101 | High |
| N-CYBER-024 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm. | SSR-CYBER-0102, SSR-CYBER-0103, SSR-CYBER-0104, SSR-CYBER-0105, SSR-CYBER-0106, SSR-CYBER-0107, SSR-CYBER-0102-2, SSR-CYBER-0103-2 | Medium |
| N-CYBER-025 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm. | SSR-CYBER-0108, SSR-CYBER-0109, SSR-CYBER-0110, SSR-CYBER-0111, SSR-CYBER-0112 | Medium |
| N-SW-029 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SW-0136, SSR-SW-0137, SSR-SW-0138, SSR-SW-0139, SSR-SW-0140, SSR-SW-0141 | Low |
| N-SW-030 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SW-0142, SSR-SW-0143, SSR-SW-0144, SSR-SW-0145, SSR-SW-0146, SSR-SW-0147 | Low |
| N-SW-031 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SW-0148, SSR-SW-0149, SSR-SW-0150, SSR-SW-0151, SSR-SW-0152, SSR-SW-0153 | Low |
| N-SW-032 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SW-0154, SSR-SW-0155, SSR-SW-0156, SSR-SW-0157, SSR-SW-0158, SSR-SW-0159 | Medium |
| N-SW-033 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SW-0160, SSR-SW-0161, SSR-SW-0162 | Low |
| N-CYBER-026 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage device certificates. | SSR-CYBER-0113, SSR-CYBER-0114, SSR-CYBER-0115, SSR-CYBER-0116, SSR-CYBER-0117, SSR-CYBER-0118 | Highest |
| N-CYBER-027 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage device certificates. | SSR-CYBER-0119, SSR-CYBER-0120, SSR-CYBER-0121, SSR-CYBER-0122, SSR-CYBER-0123, SSR-CYBER-0124 | Highest |
| N-CYBER-028 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage device certificates. | SSR-CYBER-0125, SSR-CYBER-0126, SSR-CYBER-0127, SSR-CYBER-0128, SSR-CYBER-0129, SSR-CYBER-0130 | High |
| N-CYBER-029 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce role-based access control. | SSR-CYBER-0131, SSR-CYBER-0132, SSR-CYBER-0133, SSR-CYBER-0134, SSR-CYBER-0135, SSR-CYBER-0136 | Medium |
| N-CYBER-030 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce role-based access control. | SSR-CYBER-0137, SSR-CYBER-0138, SSR-CYBER-0139, SSR-CYBER-0140, SSR-CYBER-0141, SSR-CYBER-0142 | Medium |
| N-CYBER-031 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce role-based access control. | SSR-CYBER-0143, SSR-CYBER-0144, SSR-CYBER-0145 | Medium |
| N-SW-034 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to establish a secured diagnostic session. | SSR-SW-0163, SSR-SW-0164, SSR-SW-0165, SSR-SW-0166, SSR-SW-0167, SSR-SW-0168, SSR-SW-0165-2 | Medium |
| N-SW-035 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to establish a secured diagnostic session. | SSR-SW-0169, SSR-SW-0170, SSR-SW-0171, SSR-SW-0172, SSR-SW-0173, SSR-SW-0174 | High |
| N-SW-036 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to establish a secured diagnostic session. | SSR-SW-0175, SSR-SW-0176, SSR-SW-0177, SSR-SW-0178, SSR-SW-0179, SSR-SW-0180, SSR-SW-0175-2 | Low |
| N-SW-037 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to establish a secured diagnostic session. | SSR-SW-0181, SSR-SW-0182 | Medium |
| N-SW-038 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-SW-0183, SSR-SW-0184, SSR-SW-0185, SSR-SW-0186, SSR-SW-0187, SSR-SW-0188, SSR-SW-0185-2, SSR-SW-0185-3 | High |
| N-SW-039 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect memory integrity. | SSR-SW-0189, SSR-SW-0190, SSR-SW-0191, SSR-SW-0192, SSR-SW-0193, SSR-SW-0194, SSR-SW-0194-2 | Low |
| N-HW-014 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage diagnostic trouble codes. | SSR-HW-0047, SSR-HW-0047-2, SSR-HW-0047-3 | Low |
| N-HW-015 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-HW-0048 | Low |
| N-SYS-074 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to establish a secured diagnostic session. | SSR-SYS-0371, SSR-SYS-0372, SSR-SYS-0373, SSR-SYS-0374, SSR-SYS-0375, SSR-SYS-0376, SSR-SYS-0371-2 | Low |
| N-SW-040 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to perform authenticated software update. | SSR-SW-0195, SSR-SW-0196, SSR-SW-0197, SSR-SW-0198, SSR-SW-0199, SSR-SW-0196-2 | Low |
| N-SW-041 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-SW-0200, SSR-SW-0201, SSR-SW-0202, SSR-SW-0203, SSR-SW-0204, SSR-SW-0205, SSR-SW-0200-2 | Low |
| N-SW-042 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-SW-0206, SSR-SW-0207, SSR-SW-0208, SSR-SW-0209, SSR-SW-0210, SSR-SW-0211 | Low |
| N-SW-043 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-SW-0212, SSR-SW-0213, SSR-SW-0214, SSR-SW-0215, SSR-SW-0216 | Low |
| N-SW-044 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to exchange the specified network signals. | SSR-SW-0217 | Low |
| N-SW-045 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to operate within the specified electrical-supply limits. | SSR-SW-0218, SSR-SW-0219, SSR-SW-0218-2, SSR-SW-0218-3 | Low |
| N-SW-046 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce role-based access control. | SSR-SW-0220, SSR-SW-0221, SSR-SW-0222, SSR-SW-0223, SSR-SW-0224, SSR-SW-0225 | Highest |
| N-SW-047 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce role-based access control. | SSR-SW-0226, SSR-SW-0227, SSR-SW-0228, SSR-SW-0229, SSR-SW-0230, SSR-SW-0231, SSR-SW-0230-2 | Medium |
| N-SW-048 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce role-based access control. | SSR-SW-0232 | Low |
| N-SW-049 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to enter the defined safe state on detected faults. | SSR-SW-0233, SSR-SW-0233-2 | Low |
| N-SW-050 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to enforce the defined network-boundary controls. | SSR-SW-0234 | High |
| N-FUSA-003 | FUSA | vehicle manufacturer | The vehicle manufacturer needs the ECA to meet the functional-safety obligation defined in the traced customer requirements. | SSR-FUSA-0006 | Medium |
| N-SYS-075 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SYS-0377, SSR-SYS-0378, SSR-SYS-0379, SSR-SYS-0380, SSR-SYS-0381, SSR-SYS-0382 | Low |
| N-SYS-076 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SYS-0383, SSR-SYS-0384, SSR-SYS-0385, SSR-SYS-0386, SSR-SYS-0387, SSR-SYS-0388 | Low |
| N-SYS-077 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SYS-0389, SSR-SYS-0390, SSR-SYS-0391, SSR-SYS-0392, SSR-SYS-0393, SSR-SYS-0394 | Low |
| N-SYS-078 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-SYS-0395, SSR-SYS-0396, SSR-SYS-0397 | Low |
| N-FUSA-004 | FUSA | vehicle manufacturer | The vehicle manufacturer needs the ECA to agree the distributed cybersecurity responsibilities. | SSR-FUSA-0007 | Low |
| N-CYBER-032 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage calibration parameters. | SSR-CYBER-0146, SSR-CYBER-0147, SSR-CYBER-0148 | Low |
| N-SW-051 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage device certificates. | SSR-SW-0235, SSR-SW-0236, SSR-SW-0237, SSR-SW-0238, SSR-SW-0239, SSR-SW-0240 | High |
| N-SW-052 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to manage device certificates. | SSR-SW-0241, SSR-SW-0242, SSR-SW-0243, SSR-SW-0244, SSR-SW-0245, SSR-SW-0241-2 | High |
| N-SW-053 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to protect data confidentiality with the specified cryptographic algorithm. | SSR-SW-0246, SSR-SW-0247, SSR-SW-0248, SSR-SW-0249 | Low |
| N-CYBER-033 | CYBER | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-CYBER-0149, SSR-CYBER-0150, SSR-CYBER-0151, SSR-CYBER-0152, SSR-CYBER-0153 | Low |
| N-SYS-079 | SYS | vehicle manufacturer | The vehicle manufacturer needs the ECA to implement the specified UDS diagnostic service. | SSR-SYS-0398 | Low |
| N-SW-054 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to implement the defined cybersecurity concept. | SSR-SW-0250, SSR-SW-0250-2, SSR-SW-0250-3, SSR-SW-0250-4 | Low |
| N-HW-016 | HW | vehicle manufacturer | The vehicle manufacturer needs the ECA to authenticate the requesting client before privileged access. | SSR-HW-0049, SSR-HW-0050, SSR-HW-0051 | Low |
| N-SW-055 | SW | vehicle manufacturer | The vehicle manufacturer needs the ECA to control cryptographic key handling. | SSR-SW-0251, SSR-SW-0252 | Low |
System requirements — SSR (1077)
Each SSR refines a customer requirement into a self-contained ECA obligation, authored and independently checked by writer and verifier sub-agents (INCOSE GtWR v4). 688/1077 (64%) pass the automated GtWR rule engine; 66 are marked needs-clarification where the source is truncated or non-normative, each with a specific question. Complete Jira summaries are in the export.
| SSR ID | Status | Area | Category | ASIL | Prio | V-method | Requirement statement | Parent need | Traces to customer | Managed unknowns / clarification |
|---|---|---|---|---|---|---|---|---|---|---|
| SSR-CYBER-0001 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall document in the cybersecurity concept the scope of the risk analysis, the risks identified during the risk analysis, the cybersecurity goals, the cybersecurity requirements, the mitigation strategies, and the validation and verification strategies. | N-CYBER-001 | CR-CYBER-0001 | ||
| SSR-CYBER-0002 | split | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall describe the cybersecurity concept. | N-CYBER-001 | REQ_SEC_0003 | |
| SSR-CYBER-0002-2 | split | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall describe how the cybersecurity concept is implemented in the ECA hardware and in the ECA software. | N-CYBER-001 | REQ_SEC_0003 | |
| SSR-CYBER-0003 | split | CYBER | Design constraint | QM | High | Review | The ECA supplier shall document the accepted residual risk in the cybersecurity concept. | N-CYBER-001 | REQ_SEC_0024 | |
| SSR-CYBER-0003-2 | split | CYBER | Design constraint | QM | High | Review | The ECA supplier shall agree the cybersecurity concept with the vehicle manufacturer. | N-CYBER-001 | REQ_SEC_0024 | |
| SSR-CYBER-0004 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall provide documentation describing the strategies and methods used for embedded systems cybersecurity. | N-CYBER-002 | REQ_SEC_0001 | ||
| SSR-CYBER-0005 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall provide documentation of the verification and validation methods for the cybersecurity features. | N-CYBER-002 | REQ_SEC_0004 | ||
| SSR-CYBER-0006 | CYBER | Design constraint | QM | Medium | Review | For each release, the ECA supplier shall perform a risk assessment based on a threat and vulnerability analysis that covers each vehicle manufacturer-specific adaptation. | N-CYBER-003 | REQ_SEC_0002 | ||
| SSR-CYBER-0007 | CYBER | Design constraint | QM | Low | Review | For each risk identified in the cybersecurity risk analyses, the ECA supplier shall make a risk treatment decision to avoid, reduce, share, or retain the risk. | N-CYBER-003 | CR-CYBER-0006 | ||
| SSR-CYBER-0008 | needs clarification | CYBER | Design constraint | QM | Low | Review | The ECA shall verify the data chunks identified by each Range item in the dataRanges sequence. | N-CYBER-003 | CR-CYBER-0089 | CLARIFY: Should this CVS154 data-dictionary entry be captured as a verification requirement (the ECA verifies the data chunks identified by each Range in dataRanges), or is it purely a data-structure definition to be referenced rather than a standalone requirement?; Source is a CVS154 data-dictionary definition of 'dataRanges' (sequence of Range items); the concrete data chunks are defined per DSC instance, not in this item. |
| SSR-CYBER-0009 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall state, for the DSC instance, whether the ECA supports the specified dataRanges in the VerificationEntry. | N-CYBER-003 | CR-CYBER-0091 | ||
| SSR-CYBER-0010 | CYBER | Design constraint | QM | Low | Test | The ECA supplier shall state, for the DSC instance, whether the ECA supports the specified dataRanges in the EncryptionEntry. | N-CYBER-003 | CR-CYBER-0094 | ||
| SSR-SYS-0001 | SYS | Design constraint | QM | Medium | Test | The ECA supplier shall propose the method and the scope to the vehicle manufacturer for approval. | N-SYS-001 | CR-SYS-0001 | ||
| SSR-SYS-0002 | SYS | Design constraint | QM | Medium | Test | The ECA supplier shall propose the methods to the vehicle manufacturer for approval. | N-SYS-001 | CR-SYS-0003 | ||
| SSR-SYS-0003 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall propose the methods to the vehicle manufacturer for approval. | N-SYS-001 | CR-SYS-0008 | ||
| SSR-SYS-0004 | SYS | Design constraint | QM | Medium | Test | The ECA supplier shall propose the methods, including a stipulated notification time of TBD, to the vehicle manufacturer for approval. | N-SYS-001 | CR-SYS-0015 | Notification time is not quantified by the customer ('reasonable notification time'); the value (TBD) must be agreed with the vehicle manufacturer. | |
| SSR-SYS-0005 | split | SYS | Design constraint | QM | Medium | Test | Each part included in the ECA shall fulfil the applicable sections of Part 9 in Annex B to the latest ADR applicable at the time of type approval. | N-SYS-001 | 9.2 | |
| SSR-SYS-0005-2 | split | SYS | Design constraint | QM | Medium | Test | The ECA shall comply with ECE Regulation No. 105 as amended at the time of type approval. | N-SYS-001 | 9.2 | |
| SSR-SYS-0005-3 | split | SYS | Design constraint | QM | Medium | Test | The ECA shall comply with European Directive 2008/68/EC as amended at the time of type approval. | N-SYS-001 | 9.2 | |
| SSR-SYS-0006 | needs clarification | SYS | Design constraint | QM | Low | Test | Where type approval is required, the ECA shall comply with ECE Regulation No. TBD. | N-SYS-001 | CR-SYS-0123 | CLARIFY: Which ECE Regulation number(s) must the ECA and its components comply with for type approval? The source statement is truncated at 'ECE Regulation No.'.; The applicable ECE Regulation number is missing; the customer statement is truncated at 'ECE Regulation No.'. |
| SSR-VAL-0001 | VAL | Design constraint | QM | Low | Review | The ECA supplier shall provide documentation of the method and the results to the vehicle manufacturer. | N-VAL-001 | CR-VAL-0001 | ||
| SSR-VAL-0002 | split | VAL | Design constraint | QM | Medium | Review | When the vehicle manufacturer requests documentation or evidence, the ECA supplier shall provide the requested documentation and evidence. | N-VAL-001 | REQ_SEC_0041 | |
| SSR-VAL-0002-2 | split | VAL | Design constraint | QM | Medium | Review | When the vehicle manufacturer performs or orders a compliance audit, the ECA supplier shall support the compliance audit. | N-VAL-001 | REQ_SEC_0041 | |
| SSR-VAL-0003 | needs clarification | VAL | Design constraint | QM | Low | Review | The ECA supplier shall provide documentation of the ECA product. | N-VAL-001 | CR-VAL-0005 | CLARIFY: What specific product documentation does Traton require? The source statement (clause 2.12) is truncated after 'Documentation of the product, i.e.'.; The specific product documentation items are missing; the source is truncated after 'Documentation of the product, i.e.'. |
| SSR-VAL-0004 | VAL | Design constraint | QM | Low | Review | The ECA supplier shall provide documentation for the ESD bits and the related faults. | N-VAL-001 | CR-VAL-0009 | ||
| SSR-CYBER-0011 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall evaluate each risk identified in the cybersecurity risk analyses. | N-CYBER-004 | REQ_SEC_0022 | ||
| SSR-CYBER-0012 | CYBER | Design constraint | QM | Low | Review | The ECA shall implement cybersecurity controls that reduce each identified risk to the acceptable residual risk level of TBD. | N-CYBER-004 | REQ_SEC_0023 | The acceptable residual risk level is not quantified by the customer ('sufficiently'); the target level (TBD) must be agreed with the vehicle manufacturer. | |
| SSR-CYBER-0013 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall maintain traceability between each cybersecurity control and the requirement from which it was derived. | N-CYBER-004 | CR-CYBER-0008 | ||
| SSR-CYBER-0014 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall provide test reports detailing the results of the verification and validation of the cybersecurity features. | N-CYBER-004 | REQ_SEC_0005 | ||
| SSR-CYBER-0015 | CYBER | Design constraint | QM | Low | Review | The ECA shall isolate the software components, the hardware components, and the data to reduce the effect of a cybersecurity breach. | N-CYBER-004 | REQ_SEC_0009 | ||
| SSR-CYBER-0016 | CYBER | Design constraint | QM | Low | Review | The ECA shall support secure injection of data by the vehicle manufacturer in accordance with the specification provided by the vehicle manufacturer. | N-CYBER-004 | REQ_SEC_0027 | ||
| SSR-CYBER-0017 | CYBER | Design constraint | QM | Low | Review | The ECA shall conform to the harmonized Security Access specification provided by the vehicle manufacturer. | N-CYBER-005 | REQ_SEC_0015 | ||
| SSR-CYBER-0018 | CYBER | Design constraint | QM | Low | Review | When the ECA is decommissioned, the ECA shall keep the risk to the road user and to the vehicle manufacturer within the acceptable level. | N-CYBER-005 | CR-CYBER-0031 | ||
| SSR-CYBER-0019 | CYBER | Design constraint | QM | Low | Review | The ECA shall support the ECU identification data in accordance with CVS124. | N-CYBER-005 | CR-CYBER-0044 | ||
| SSR-CYBER-0020 | CYBER | Design constraint | QM | Low | Test | The ECA shall use ED25519 as the signature algorithm. | N-CYBER-005 | CR-CYBER-0051 | ||
| SSR-CYBER-0021 | CYBER | Design constraint | QM | Low | Test | If the authenticity verification is valid, the ECA shall initiate installation of the received file. | N-CYBER-005 | REQ_UDS_0170 | ||
| SSR-CYBER-0022 | CYBER | Design constraint | QM | Low | Test | Until the authenticity verification completes, the ECA shall keep the AuthenticityStatus field in bits 7-6 of AuthenticityVerificationStatus set to 0x0, indicating Software Authenticity Invalid. | N-CYBER-005 | REQ_UDS_0177 | ||
| SSR-CYBER-0023 | needs clarification | CYBER | Design constraint | QM | Low | Review | The ECA shall conform to the Data Security Container base definition specified in CVS154. | N-CYBER-006 | CR-CYBER-0084 | CLARIFY: CR-CYBER-0084 is the CVS154 foreword (Data Security Container base definition scope), not a testable obligation. Should it be captured as a general conformance requirement to CVS154 or dropped as non-normative boilerplate?; Source is the CVS154 foreword/scope text, not a specific obligation; the applicable normative clauses of CVS154 are elsewhere in the standard. |
| SSR-CYBER-0024 | CYBER | Design constraint | QM | Low | Test | The ECA shall generate the proof or the signature according to the specified pseudo code. | N-CYBER-006 | CR-CYBER-0101 | The referenced pseudo code ('below') is not included in this item and must be taken from the source document. | |
| SSR-CYBER-0025 | CYBER | Design constraint | QM | Low | Test | The ECA shall generate the signature according to the specified pseudo code. | N-CYBER-006 | CR-CYBER-0105 | The referenced pseudo code ('below') is not included in this item and must be taken from the source document. | |
| SSR-CYBER-0026 | CYBER | Design constraint | QM | Low | Test | The ECA shall represent each access role as a single bit within a 32-bit role field, where role number N corresponds to bit number N minus one, expressed as a four-byte value. | N-CYBER-006 | CR-CYBER-0114 | ||
| SSR-CYBER-0027 | CYBER | Design constraint | QM | Low | Test | The ECA shall set the SignatureAlgorithm extension to ED25519 with the object identifier 1.3.101.112. | N-CYBER-006 | CR-CYBER-0121 | ||
| SSR-CYBER-0028 | needs clarification | CYBER | Design constraint | QM | High | Review | The ECA supplier shall interpret the requirement-level keywords used in this document in accordance with Key words for use in RFCs to Indicate Requirement Levels. | N-CYBER-006 | CR-CYBER-0126 | CLARIFY: CR-CYBER-0126 is a keyword-interpretation convention (shall/should/must per RFC 2119), not a system requirement. Should it be retained as a documentation convention note or dropped from the requirement set? |
| SSR-CYBER-0029 | CYBER | Design constraint | QM | High | Review | The ECA supplier shall allow the vehicle manufacturer to perform penetration testing on the ECA. | N-CYBER-007 | REQ_SEC_0040 | ||
| SSR-SYS-0007 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall provide an inventory of the software and the protocols, including the version of each. | N-SYS-002 | REQ_SEC_0007 | ||
| SSR-SYS-0008 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall agree the selection of the cryptographic methods and their use with the vehicle manufacturer. | N-SYS-002 | REQ_SEC_0020 | ||
| SSR-SYS-0009 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall harden each network service implemented in the ECA. | N-SYS-002 | REQ_SEC_0010 | The hardening baseline/standard is not specified by the customer; the applicable hardening measures should be agreed with the vehicle manufacturer. | |
| SSR-SYS-0010 | SYS | Design constraint | QM | Low | Test | The ECA shall expose only the network and communication services that have been agreed with the vehicle manufacturer. | N-SYS-002 | REQ_SEC_0011 | ||
| SSR-SYS-0011 | SYS | Design constraint | QM | Low | Test | For the series-production ECA, the ECA supplier shall remove or disable each interface used for development purposes. | N-SYS-002 | REQ_SEC_0014 | ||
| SSR-SYS-0012 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall agree the details with the vehicle manufacturer. | N-SYS-002 | CR-SYS-0010 | ||
| SSR-SYS-0013 | SYS | Design constraint | QM | Low | Test | The ECA shall protect the data specified by the vehicle manufacturer from manipulation. | N-SYS-003 | REQ_SEC_0028 | ||
| SSR-SYS-0014 | SYS | Design constraint | QM | Low | Test | The ECA shall protect the data specified by the vehicle manufacturer from disclosure. | N-SYS-003 | REQ_SEC_0029 | ||
| SSR-SYS-0015 | SYS | Design constraint | QM | Low | Test | The ECA shall protect the intellectual property of the vehicle manufacturer from disclosure. | N-SYS-003 | REQ_SEC_0006 | ||
| SSR-SYS-0016 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall address end-of-life and decommissioning of the ECA in the ECA design. | N-SYS-003 | CR-SYS-0018 | ||
| SSR-SYS-0017 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall determine the ECA variant type based on the delivery agreement and the brand involved. | N-SYS-003 | CR-SYS-0022 | ||
| SSR-SYS-0018 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall verify the ECA mechanics in an overall durability test as stated in Appendix B. | N-SYS-003 | 2.11 | Appendix B durability test content is referenced but not provided in the source. | |
| SSR-SYS-0019 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall perform testing to verify each requirement stated in the requirement specification. | N-SYS-004 | CR-SYS-0025 | ||
| SSR-SYS-0020 | SYS | Design constraint | QM | Low | Test | The surface roughness of the ECA opposite to surface B shall be equal to or finer than Ra 3.2 µm. | N-SYS-004 | CR-SYS-0027 | ||
| SSR-SYS-0021 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall test the ECA step response in accordance with the description and Figure 10 - Step response test cycle of the referenced specification. | N-SYS-004 | CR-SYS-0046 | ||
| SSR-SYS-0022 | SYS | Design constraint | QM | Low | Test | The ECA shall run the 4-second release frequency test cycle defined in Figure 11 continuously for 5 hours while remaining free of degradation and failure. | N-SYS-004 | CR-SYS-0047 | ||
| SSR-SYS-0023 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree the strategy with Traton. | N-SYS-004 | CR-SYS-0050 | The specific strategy referred to by 'the strategy' is defined in surrounding context not included in the source. | |
| SSR-SYS-0024 | SYS | Design constraint | QM | Low | Test | The ECA shall comply with TB4684. | N-SYS-004 | CR-SYS-0053 | ||
| SSR-SYS-0025 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA supplier shall comply fully with the referenced specification. | N-SYS-005 | CR-SYS-0054 | CLARIFY: What does 'It' refer to - which document, standard, or specification shall be followed to its full extent?; The referent of 'It' is not identified in the source. |
| SSR-SYS-0026 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA supplier shall obtain approval from Traton for each specific case. | N-SYS-005 | CR-SYS-0056 | CLARIFY: Which specific cases require Traton approval in CR-SYS-0056? The source statement 'Specific cases shall be approved with Traton' does not identify the configurations, deviations, or conditions it applies to.; The 'specific cases' requiring Traton approval are not defined in the item and cannot be resolved from the context neighbours. |
| SSR-SYS-0027 | SYS | Design constraint | QM | Low | Test | The ECA shall report the FCCP value via CAN in accordance with reference 14.14. | N-SYS-005 | CR-SYS-0063 | ||
| SSR-SYS-0028 | SYS | Design constraint | QM | Low | Review | The ECA shall report supplier code 5 via CAN. | N-SYS-005 | 6.10 | ||
| SSR-SYS-0029 | SYS | Design constraint | QM | Low | Test | When the ECA performs a self-adjustment procedure that is independent of an RPC request or a TC request, the ECA shall send 0x5 as the actuator control state. | N-SYS-005 | 6.14.5 | ||
| SSR-SYS-0030 | SYS | Design constraint | QM | Low | Test | When the ECA performs its shut-down routine, the ECA shall send 0xA as the actuator control state. | N-SYS-005 | CR-SYS-0073 | ||
| SSR-SYS-0031 | SYS | Design constraint | QM | Low | Test | The ECA shall comply with CVS120 as defined in reference 14.12. | N-SYS-006 | 6.20 | ||
| SSR-SYS-0032 | SYS | Design constraint | QM | Low | Test | The ECA shall calculate the current value for each actuator phase using a moving mean filter. | N-SYS-006 | CR-SYS-0077 | ||
| SSR-SYS-0033 | SYS | Design constraint | QM | Low | Test | The ECA shall handle data corruption while preserving stored data and function. | N-SYS-006 | CR-SYS-0083 | ||
| SSR-SYS-0034 | SYS | Design constraint | QM | Low | Test | If a single failure occurs, the ECA shall maintain electrical isolation between the Wake-up line and terminal 30. | N-SYS-006 | CR-SYS-0087 | ||
| SSR-SYS-0035 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree the redundancies related to improper shutdown with Traton. | N-SYS-006 | CR-SYS-0091 | The specific redundancies for improper shutdown are defined in surrounding context not included in the source. | |
| SSR-SYS-0036 | SYS | Design constraint | QM | Low | Inspection | By default, the ECA shall leave the components unpopulated. | N-SYS-006 | CR-SYS-0099 | The specific components are defined in surrounding context not included in the source. | |
| SSR-SYS-0037 | SYS | Design constraint | QM | Low | Inspection | The conformal coating or lacquer of the ECA shall cover the entire PCB and each solder joint. | N-SYS-007 | CR-SYS-0104 | ||
| SSR-SYS-0038 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA supplier shall specify the type of conformal coating or lacquer in the initial offer. | N-SYS-007 | CR-SYS-0106 | CLARIFY: In CR-SYS-0106, what must be specified in the initial offer? The source fragment 'shall be specified in the initial offer' lacks a subject; the surrounding context concerns conformal coating and lacquer, so please confirm whether the coating or lacquer type is the item to be specified.; The subject of 'shall be specified in the initial offer' (what must be specified) is not stated in the item; inferred as the conformal coating or lacquer type from the coating context. |
| SSR-SYS-0039 | split | SYS | Design constraint | QM | Low | Inspection | The visual appearance of the ECA final coating shall be consistent with the latest version of IPC-A-610. | N-SYS-007 | CR-SYS-0107 | Source is a merged fragment; identifiers 'HDBK-001' and 'HDBK-830' are likely 'IPC-HDBK-001' and 'IPC-HDBK-830' but the prefix is not confirmed in the source. |
| SSR-SYS-0039-2 | split | SYS | Design constraint | QM | Low | Inspection | The ECA conformal coating shall be applied in accordance with HDBK-001, IPC-CC-830 and HDBK-830. | N-SYS-007 | CR-SYS-0107 | |
| SSR-SYS-0040 | SYS | Design constraint | QM | Low | Inspection | The ECA shall be free of water-based and silicone lacquers. | N-SYS-007 | CR-SYS-0108 | ||
| SSR-SYS-0041 | SYS | Design constraint | QM | Low | Review | The ECA shall position the membrane so that the membrane is protected against blunt force, falling dust and dripping salt-water. | N-SYS-007 | CR-SYS-0110 | ||
| SSR-SYS-0042 | SYS | Design constraint | QM | Low | Test | The ECA shall keep the top of the membrane and the membrane cavity free of accumulated water. | N-SYS-007 | CR-SYS-0111 | ||
| SSR-SYS-0043 | SYS | Design constraint | QM | Low | Inspection | The ECA shall be free of BGA capsules. | N-SYS-008 | CR-SYS-0112 | ||
| SSR-SYS-0044 | SYS | Design constraint | QM | Low | Test | The ECA shall be maintenance-free throughout its service life. | N-SYS-008 | 8.5 | ||
| SSR-SYS-0045 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall provide the maintenance window cover as a spare part. | N-SYS-008 | 8.8 | ||
| SSR-SYS-0046 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall define the spare parts or repair kits in agreement with Traton. | N-SYS-008 | CR-SYS-0119 | ||
| SSR-SYS-0047 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA supplier shall provide the item defined in section 4.17 of the referenced specification as a spare part. | N-SYS-008 | CR-SYS-0120 | CLARIFY: In CR-SYS-0120, which item (referenced as '4.17') must be provided as a spare part? The source fragment lacks the subject; please identify the component defined in section 4.17.; The component to be provided as a spare part (referenced as '4.17') is not identified in the item and cannot be resolved from the context neighbours. |
| SSR-SYS-0048 | SYS | Design constraint | QM | Low | Test | The ECA shall be lead-free. | N-SYS-008 | CR-SYS-0122 | ||
| SSR-SYS-0049 | SYS | Design constraint | QM | Low | Test | The ECA shall fulfil the general requirements for Electronic Control Units stated in CVS40 and CVS41. | N-SYS-009 | 10.1 | ||
| SSR-SYS-0050 | SYS | Design constraint | QM | Low | Test | The ECA shall achieve the protection required by CVS40 and CVS41 independently of software. | N-SYS-009 | 10.2 | ||
| SSR-SYS-0051 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree the accepted behaviour for this case with Traton. | N-SYS-009 | CR-SYS-0127 | The specific case/scenario referred to by 'this case' is defined in surrounding context not included in the source. | |
| SSR-SYS-0052 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall perform the test before and after exposure. | N-SYS-009 | CR-SYS-0128 | The specific test and exposure referred to are defined in surrounding context not included in the source. | |
| SSR-SYS-0053 | SYS | Design constraint | QM | Low | Test | The ECA shall allow the test to be performed during exposure. | N-SYS-009 | CR-SYS-0129 | The specific test and exposure referred to are defined in surrounding context not included in the source. | |
| SSR-SYS-0054 | SYS | Design constraint | QM | Low | Review | Where reduced versions of test procedure II are agreed with Traton, the ECA supplier shall use the reduced versions during the applicable tests. | N-SYS-009 | CR-SYS-0130 | ||
| SSR-SYS-0055 | SYS | Design constraint | QM | Low | Test | Each plastic material of the ECA shall be a self-extinguishing material rated to UL94. | N-SYS-010 | 10.5.33 | ||
| SSR-SYS-0056 | needs clarification | SYS | Design constraint | QM | Low | Test | Each tab header of the ECA shall be a self-extinguishing material. | N-SYS-010 | CR-SYS-0132 | CLARIFY: This appears to be a truncated duplicate of the flammability requirement (10.5.33). Which standard was intended after '(i.e.' - is it UL94, and does this requirement duplicate CR-SYS-0055?; The material/flammability standard is truncated in the source (text ends at '(i.e.'). |
| SSR-SYS-0057 | SYS | Design constraint | QM | Low | Review | When Traton requests support during the vehicle ESD test, the ECA supplier shall support Traton in resolving each issue originating from the ECA. | N-SYS-010 | 10.7.27 | ||
| SSR-SYS-0058 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA supplier shall systematically identify each possible cause. | N-SYS-010 | CR-SYS-0135 | CLARIFY: In CR-SYS-0135, what is 'this purpose' for which possible causes must be systematically identified? The dangling opener references a preceding objective that was not included; please confirm the activity (for example, fault or issue root-cause analysis) this applies to.; The antecedent of 'For this purpose' (the objective or event whose causes must be identified) is not present in the item or context neighbours. |
| SSR-SYS-0059 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall provide software that enables testing of the ECA during development, during production and on each claimed ECA. | N-SYS-010 | 12.3 | ||
| SSR-SYS-0060 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall perform a conformance test of each external and internal I/O of the ECA. | N-SYS-010 | CR-SYS-0137 | ||
| SSR-SYS-0061 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall verify that each internal and external I/O of the ECA fulfils the requirements in this specification. | N-SYS-011 | CR-SYS-0138 | ||
| SSR-SYS-0062 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall carry out two full test rounds according to the Traton test requirements. | N-SYS-011 | CR-SYS-0139 | ||
| SSR-SYS-0063 | SYS | Design constraint | QM | Low | Review | Where the ECA supplier initiates and performs additional tests, the ECA supplier shall discuss the additional tests with Traton. | N-SYS-011 | CR-SYS-0140 | ||
| SSR-SYS-0064 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall perform EMC tests on the ECA alone. | N-SYS-011 | CR-SYS-0141 | ||
| SSR-SYS-0065 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall certify the ECA according to the latest revision of UN ECE R10, including each amendment. | N-SYS-011 | CR-SYS-0142 | ||
| SSR-SYS-0066 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall check that the prototype and serial ECAs fulfil the dimension requirements in each applicable Traton-supplied drawing. | N-SYS-011 | CR-SYS-0143 | ||
| SSR-SYS-0067 | SYS | Design constraint | QM | Low | Inspection | Each prototype and serial ECA shall fulfil the requirements of TB1822, IPC/EIA J-STD-001 class 3 and IPC-A-610 class 3. | N-SYS-012 | CR-SYS-0144 | ||
| SSR-SYS-0068 | SYS | Design constraint | QM | Low | Review | Where sample phases are divided into several generations, the ECA supplier shall agree the division with Traton. | N-SYS-012 | CR-SYS-0145 | ||
| SSR-SYS-0069 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall functionally test each sample before sending the sample to Traton. | N-SYS-012 | CR-SYS-0146 | ||
| SSR-SYS-0070 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall report each deviation as part of the sample delivery. | N-SYS-012 | CR-SYS-0147 | ||
| SSR-SYS-0071 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall perform dimensional checks on each B-sample and each C-sample prior to delivery to Traton. | N-SYS-012 | CR-SYS-0148 | ||
| SSR-SYS-0072 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall use the sample denominations requested by Traton. | N-SYS-012 | CR-SYS-0149 | ||
| SSR-SYS-0073 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall apply, for each referenced document without a stated version, the latest version available as of 1 May 2026. | N-SYS-013 | CR-SYS-0150 | ||
| SSR-SYS-0074 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall apply the latest released version of the CVS123-2 specification. | N-SYS-013 | CR-SYS-0155 | ||
| SSR-SYS-0075 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA shall expose its two physical servers to the diagnostic client. | N-SYS-013 | CR-SYS-0156 | CLARIFY: CR-SYS-0156 is phrased as an explanatory note ('a single server view is not completely achievable and clients still need to be aware of two physical servers'). What is the binding obligation on the ECA? Please confirm whether the ECA must expose two physical servers, or whether this is context for a client-side requirement.; The binding obligation on the ECA is unclear; the source is a note stating that a single-server view is not fully achievable and that clients must be aware of two physical servers. |
| SSR-SYS-0076 | SYS | Design constraint | QM | Low | Review | The ECA shall support the programming sequence specified in CVS123-2. | N-SYS-013 | CR-SYS-0158 | ||
| SSR-SYS-0077 | SYS | Design constraint | QM | Low | Test | The ECA shall keep the boot loader separated from the application software. | N-SYS-013 | CR-SYS-0159 | Antecedent 'It' is not stated in the source; interpreted as the boot loader from the surrounding programming/boot-loader context. | |
| SSR-SYS-0078 | needs clarification | SYS | Design constraint | QM | Low | Test | The ECA shall implement the specified boot-software function in the boot software code. | N-SYS-013 | CR-SYS-0161 | CLARIFY: In CR-SYS-0161, what must be implemented in the boot software code? The source fragment 'shall be implemented in the boot software code' lacks a subject; please identify the function or feature (the antecedent 'it' in the surrounding boot-loader text).; The subject of 'shall be implemented in the boot software code' is not stated; it is the antecedent of 'it' in the surrounding boot-loader description, which is not included. |
| SSR-SYS-0079 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree each deviation from the specification with the applicable vehicle manufacturer. | N-SYS-014 | CR-SYS-0163 | ||
| SSR-SYS-0080 | SYS | Design constraint | QM | Low | Review | Where the specification does not state otherwise, the ECA supplier shall apply the programming requirements of the specification to the programming of each software module, including the application software, the application data, and the boot loader. | N-SYS-014 | CR-SYS-0164 | ||
| SSR-SYS-0081 | SYS | Design constraint | QM | Low | Test | The ECA shall protect the stored software against accidental erasure and overwriting by means of a software or hardware protection mechanism. | N-SYS-014 | CR-SYS-0165 | ||
| SSR-SYS-0082 | SYS | Design constraint | QM | Low | Test | If the microcontroller supports hardware protection, the ECA shall use that hardware protection. | N-SYS-014 | CR-SYS-0166 | ||
| SSR-SYS-0083 | SYS | Design constraint | QM | Low | Test | The ECA shall support boot loader updating in accordance with the specification during development from the A-sample stage onwards. | N-SYS-014 | CR-SYS-0168 | ||
| SSR-SYS-0084 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall provide, for each committed software delivery, a document that describes the programming procedure, the requirement exceptions, and the ECA-specific behaviours. | N-SYS-014 | CR-SYS-0169 | ||
| SSR-SYS-0085 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall document the versioning concept for the supplier-specific DIDs. | N-SYS-015 | CR-SYS-0171 | ||
| SSR-SYS-0086 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree the partitioning of the ECA software into modules with the vehicle manufacturer. | N-SYS-015 | CR-SYS-0174 | ||
| SSR-SYS-0087 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree with the vehicle manufacturer whether the ECA is delivered with a pre-programmed application and pre-programmed application data. | N-SYS-015 | CR-SYS-0176 | ||
| SSR-SYS-0088 | SYS | Design constraint | QM | Low | Review | Where the ECA is a programmable server, the ECA shall support the complete programming sequence described in the specification. | N-SYS-015 | CR-SYS-0178 | ||
| SSR-SYS-0089 | SYS | Design constraint | QM | Low | Review | Where the ECA is a non-programmable server, the ECA shall support the phase 1 pre-programming step and the phase 2 post-programming step of the programming sequence described in the specification. | N-SYS-015 | CR-SYS-0179 | ||
| SSR-SYS-0090 | SYS | Design constraint | QM | Low | Review | The ECA shall support the programming sequence described in the specification regardless of whether a valid application is present in the ECA. | N-SYS-015 | CR-SYS-0180 | ||
| SSR-SYS-0091 | SYS | Design constraint | QM | Low | Test | If the application has been started, the ECA shall check whether application initialization is required. | N-SYS-016 | CR-SYS-0183 | ||
| SSR-SYS-0092 | SYS | Design constraint | QM | Low | Test | The ECA shall allow the application software module and the application data module to be programmed in any order. | N-SYS-016 | CR-SYS-0185 | ||
| SSR-SYS-0093 | needs clarification | SYS | Design constraint | QM | Low | Test | If the applicable precondition cannot be met, the ECA shall implement a compression method. | N-SYS-016 | CR-SYS-0187 | CLARIFY: The source is truncated ('cannot be met, a compression method shall be implemented'). What is the precondition that, when it cannot be met, requires a compression method to be implemented (for example a memory-size or download-time limit)?; The condition that 'cannot be met' is truncated in the source; likely a memory-size or download-time constraint but not stated. |
| SSR-SYS-0094 | SYS | Design constraint | QM | Low | Test | The ECA shall use, as the compression and decompression algorithm, the LZSS algorithm with a dictionary size of 1023 bytes or a newer compression and decompression method with a higher compression ratio. | N-SYS-016 | CR-SYS-0188 | ||
| SSR-SYS-0095 | SYS | Design constraint | QM | Low | Review | Where an alternative compression and decompression algorithm is used, the ECA supplier shall agree its use with the vehicle manufacturer. | N-SYS-016 | CR-SYS-0189 | ||
| SSR-SYS-0096 | SYS | Design constraint | QM | Low | Test | The ECA shall allow the same software version to be programmed repeatedly. | N-SYS-016 | CR-SYS-0190 | ||
| SSR-SYS-0097 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree the technical implementation of the programming preconditions with the vehicle manufacturer. | N-SYS-017 | CR-SYS-0194 | ||
| SSR-SYS-0098 | SYS | Design constraint | QM | Low | Test | The ECA shall be re-programmable both standalone and in the vehicle regardless of whether the application and the application data are valid or corrupted. | N-SYS-017 | CR-SYS-0196 | ||
| SSR-SYS-0099 | needs clarification | SYS | Design constraint | QM | Low | Test | When a non-permitted service is requested during programming, the ECA shall resume programming from the state at which it was executing before that non-permitted service was requested. | N-SYS-017 | CR-SYS-0199 | CLARIFY: The source is truncated, starting with '(requestSequenceError) and shall accept programming to proceed ...'. Please confirm the full requirement: on which non-permitted service request shall the ECA return the requestSequenceError NRC, and confirm it shall then continue programming from the pre-request state.; The clause preceding '(requestSequenceError)' is truncated; the exact trigger and full wording of the negative-response behaviour are not stated. |
| SSR-SYS-0099-2 | split | SYS | Design constraint | QM | Low | Test | The ECA shall respond to the non-permitted service request with the requestSequenceError negative response code. | N-SYS-017 | CR-SYS-0199 | |
| SSR-SYS-0100 | SYS | Design constraint | QM | Low | Test | If the software is compressed, the ECA shall decompress the software before performing the software hash comparison verification. | N-SYS-017 | CR-SYS-0201 | ||
| SSR-SYS-0101 | SYS | Design constraint | QM | Low | Test | The ECA shall verify the software hash after decryption, decompression, or both have been performed. | N-SYS-017 | CR-SYS-0202 | ||
| SSR-SYS-0102 | SYS | Design constraint | QM | Low | Review | The ECA shall support the negative response codes defined in CVS32. | N-SYS-017 | CR-SYS-0205 | ||
| SSR-SYS-0103 | SYS | Design constraint | QM | Low | Review | The ECA shall check whether the software modules are complete and mutually compatible. | N-SYS-018 | CR-SYS-0210 | ||
| SSR-SYS-0104 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall determine the method used to check compatibility and consistency in consultation with the vehicle manufacturer. | N-SYS-018 | CR-SYS-0212 | ||
| SSR-SYS-0105 | SYS | Design constraint | QM | Low | Review | The ECA shall be solely responsible for carrying out the consistency check. | N-SYS-018 | CR-SYS-0213 | ||
| SSR-SYS-0106 | SYS | Design constraint | QM | Low | Test | The ECA shall use SHA512 as the hash algorithm. | N-SYS-018 | CR-SYS-0214 | ||
| SSR-SYS-0107 | SYS | Design constraint | QM | Low | Review | The ECA shall sign the hashed output using the receipt-keys. | N-SYS-018 | CR-SYS-0215 | ||
| SSR-SYS-0108 | SYS | Design constraint | QM | Low | Review | The ECA shall implement the SDSC structure as defined in CVS154. | N-SYS-018 | CR-SYS-0218 | ||
| SSR-SYS-0109 | SYS | Design constraint | QM | Low | Test | The ECA shall set the range length field to the number of bytes to be verified. | N-SYS-019 | CR-SYS-0219 | ||
| SSR-SYS-0110 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall propose, for each software module, an identification to be used in the dataLocator field in the SDSC. | N-SYS-019 | CR-SYS-0220 | ||
| SSR-SYS-0111 | SYS | Design constraint | QM | Low | Review | Before accepting the received SDSC as valid, the ECA shall perform the sanity check of the received SDSC as defined in CVS154. | N-SYS-019 | CR-SYS-0222 | ||
| SSR-SYS-0112 | SYS | Design constraint | QM | Low | Review | If the sanity check returns fail or invalid, the ECA shall reject the SDSC as described in CVS34. | N-SYS-019 | CR-SYS-0223 | ||
| SSR-SYS-0113 | SYS | Design constraint | QM | Low | Test | The ECA shall validate each VerificationEntry found in the SDSC. | N-SYS-019 | CR-SYS-0224 | ||
| SSR-SYS-0114 | SYS | Design constraint | QM | Low | Test | The ECA shall verify each software hash in the SDSC considering the ranges stated in the SDSC. | N-SYS-019 | CR-SYS-0225 | ||
| SSR-SYS-0115 | SYS | Design constraint | QM | Low | Review | When the ECA has verified each verificationEntry, the ECA shall return a result of OK or NOT_OK. | N-SYS-020 | CR-SYS-0228 | ||
| SSR-SYS-0116 | SYS | Design constraint | QM | Low | Test | If a NOT_OK result is returned, the ECA shall prevent the new software from being executed. | N-SYS-020 | CR-SYS-0229 | ||
| SSR-SYS-0117 | SYS | Design constraint | QM | Low | Test | Where additional software verification checks are implemented, the ECA shall execute them before determining whether the installed software is accepted. | N-SYS-020 | CR-SYS-0230 | ||
| SSR-SYS-0118 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree each method other than the methods specified in CVS123-2 with the vehicle manufacturer. | N-SYS-020 | CR-SYS-0232 | ||
| SSR-SYS-0119 | SYS | Design constraint | QM | Low | Test | The ECA shall decrypt the received data according to the defined range, where the received data may comprise only part of a software module. | N-SYS-020 | CR-SYS-0233 | ||
| SSR-SYS-0120 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall apply the latest released version of the CVS124 specification. | N-SYS-020 | CR-SYS-0234 | ||
| SSR-SYS-0121 | needs clarification | SYS | Design constraint | QM | Low | Review | Where the CVS124 specification is applicable to the ECA, the ECA supplier shall apply it. | N-SYS-021 | CR-SYS-0235 | CLARIFY: This item is the CVS124 foreword ('contains requirement specification for TRATON GROUP ... may be used by all within TRATON Group, if applicable') and carries no obligation on the ECA. Should it be dropped as informative, or is a specific applicability requirement intended?; Source is a foreword; no measurable ECA obligation is stated. |
| SSR-SYS-0122 | needs clarification | SYS | Design constraint | QM | Low | Review | TBD - the source is a definition of 'Affiliate' and states no obligation on the ECA or the supplier. | N-SYS-021 | CR-SYS-0236 | CLARIFY: This item is a contractual definition of 'Affiliate' (including 'control shall mean ownership of at least 50% ...'). Please confirm it is a glossary/definition entry to be excluded from the system requirements rather than a requirement.; Definitional 'shall' is not an obligation; no ECA or supplier requirement is present in the source. |
| SSR-SYS-0123 | SYS | Design constraint | QM | Low | Test | Where a particular option is absent from the ECA, the ECA shall interoperate with an implementation that includes that option. | N-SYS-021 | CR-SYS-0237 | ||
| SSR-SYS-0124 | SYS | Design constraint | QM | Low | Test | Where the ECA includes a particular option, the ECA shall interoperate with an implementation that lacks that option, except for the feature that the option provides. | N-SYS-021 | CR-SYS-0238 | ||
| SSR-SYS-0125 | SYS | Design constraint | QM | Low | Test | If valid data is not required for the applicable use case and system, the ECA shall use the default values. | N-SYS-021 | CR-SYS-0239 | ||
| SSR-SYS-0126 | needs clarification | SYS | Design constraint | QM | Low | Review | Where the ECA is required to comply with worldwide OBD legislation, the ECA shall support each service classified as mandatory. | N-SYS-021 | CR-SYS-0240 | CLARIFY: This text is a legend defining classification codes (E = mandatory, C = conditional, U = user optional) rather than one requirement. Does the ECA fall under worldwide OBD legislation, and which specific services/DIDs are classified E, C and U for this ECA? |
| SSR-SYS-0127 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree the data value with the vehicle manufacturer. | N-SYS-022 | CR-SYS-0241 | CLARIFY: In CR-SYS-0241, what must be agreed between the supplier and the vehicle manufacturer? The source fragment has no subject; the surrounding CVS124 text concerns data values and defaults, so please identify the specific item.; The subject of 'Shall be agreed between the supplier and the vehicle manufacturer' (what must be agreed) is not stated in the item; the surrounding CVS124 context concerns data values and defaults. |
| SSR-SYS-0128 | split | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree each deviation and each extension with the applicable vehicle manufacturer. | N-SYS-022 | REQ_UDS_0002 | |
| SSR-SYS-0128-2 | split | SYS | Design constraint | QM | Low | Review | The ECA supplier shall document each deviation and each extension. | N-SYS-022 | REQ_UDS_0002 | |
| SSR-SYS-0129 | split | SYS | Design constraint | QM | Low | Test | The ECA assigned value shall have a minimum length of 8 bytes. | N-SYS-022 | CR-SYS-0243 | The 'assigned value' is the customer's term for a per-unit identifier defined in CVS124; the exact identifier name is not specified in the item. |
| SSR-SYS-0129-2 | split | SYS | Design constraint | QM | Low | Test | The ECA supplier shall assign a unique value to each unit provided within one project. | N-SYS-022 | CR-SYS-0243 | |
| SSR-SYS-0130 | SYS | Design constraint | QM | Low | Test | The ECA shall execute the ECU reset only after it has sent a positive response to the ECU reset service request. | N-SYS-022 | REQ_UDS_0063 | ||
| SSR-SYS-0131 | split | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree with the vehicle manufacturer the maximum time from the ECA sending a positive response until the ECA responds to new requests. | N-SYS-022 | REQ_UDS_0067 | The maximum time value is not stated in the source; it is to be agreed with the vehicle manufacturer (TBD). |
| SSR-SYS-0131-2 | split | SYS | Design constraint | QM | Low | Review | The ECA supplier shall document the agreed maximum time from the ECA sending a positive response until the ECA responds to new requests. | N-SYS-022 | REQ_UDS_0067 | |
| SSR-SYS-0132 | SYS | Design constraint | QM | Low | Test | The ECA shall perform an actual disconnect from the battery. | N-SYS-022 | CR-SYS-0251 | ||
| SSR-SYS-0133 | SYS | Design constraint | QM | Low | Test | When executing a hardReset, the ECA shall preserve data integrity. | N-SYS-023 | CR-SYS-0252 | ||
| SSR-SYS-0134 | SYS | Design constraint | QM | Low | Test | When a functionally addressed TesterPresent is received during another request, the ECA shall accept it. | N-SYS-023 | CR-SYS-0254 | ||
| SSR-SYS-0135 | SYS | Design constraint | QM | Low | Test | The ECA shall switch the baud rate within one second. | N-SYS-023 | REQ_UDS_0082 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0136 | SYS | Design constraint | QM | Low | Test | If the LinkControl service request was received while the ECA was executing in the application, the ECA shall inherit the selected baud rate in the boot loader. | N-SYS-023 | REQ_UDS_0083 | ||
| SSR-SYS-0137 | SYS | Design constraint | QM | Low | Test | The ECA shall send the positive response before switching the baud rate. | N-SYS-023 | REQ_UDS_0084 | ||
| SSR-SYS-0138 | SYS | Design constraint | QM | Low | Review | The ECA shall use SPNs and FMIs in accordance with SAE J1939. | N-SYS-023 | REQ_UDS_0097 | ||
| SSR-SYS-0139 | SYS | Design constraint | QM | Low | Test | When transmitting data in a secured mode, the ECA shall use the service specified in CVS32. | N-SYS-024 | REQ_UDS_0125 | ||
| SSR-SYS-0140 | SYS | Design constraint | QM | Low | Test | The ECA shall provide the positive response in accordance with CVS32. | N-SYS-024 | REQ_UDS_0127 | ||
| SSR-SYS-0141 | SYS | Design constraint | QM | Low | Test | The ECA shall provide the negative response in accordance with the supported negative response codes defined in CVS32 section 5.5.17.3.1. | N-SYS-024 | REQ_UDS_0128 | ||
| SSR-SYS-0142 | SYS | Design constraint | QM | Low | Test | If the file is not stored at the location, the ECA shall add the file. | N-SYS-024 | CR-SYS-0265 | ||
| SSR-SYS-0143 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree each programming precondition with the vehicle manufacturer. | N-SYS-024 | REQ_UDS_0147 | The set of programming preconditions is not stated in the source; it is to be agreed with the vehicle manufacturer (TBD). | |
| SSR-SYS-0144 | SYS | Design constraint | QM | Low | Test | The ECA shall base the decision on the conditions of a programming precondition on a minimum of two independent sources of information. | N-SYS-024 | REQ_UDS_0148 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0145 | SYS | Design constraint | QM | Low | Test | If information for checking a programming precondition is unavailable, the ECA shall consider the programming precondition fulfilled. | N-SYS-025 | REQ_UDS_0149 | ||
| SSR-SYS-0146 | SYS | Design constraint | QM | Low | Test | While the software installation is on-going, the ECA shall set the InstallationStatus in bits 7 to 6 of SoftwareInstallationStatus to 0x0. | N-SYS-025 | REQ_UDS_0180 | ||
| SSR-SYS-0147 | SYS | Design constraint | QM | Low | Test | The ECA shall provide the information as a percentage. | N-SYS-025 | CR-SYS-0271 | ||
| SSR-SYS-0148 | SYS | Design constraint | QM | Low | Test | The ECA shall report the estimated time to complete the installation of the file in the TimeRemaningEstimative parameter. | N-SYS-025 | REQ_UDS_0182 | ||
| SSR-SYS-0149 | SYS | Design constraint | QM | Low | Test | The ECA shall provide the information in seconds. | N-SYS-025 | CR-SYS-0273 | ||
| SSR-SYS-0150 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA shall check whether each module is complete and compatible. | N-SYS-025 | REQ_UDS_0183 | CLARIFY: The source sentence is truncated at 'compatible with' - compatible/consistent with what (e.g., the other modules, the target hardware, or the vehicle configuration)? |
| SSR-SYS-0151 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall determine the method used to check compatibility or consistency in consultation with the vehicle manufacturer. | N-SYS-026 | REQ_UDS_0184 | The compatibility or consistency check method is not stated in the source; it is to be determined by the ECA supplier with the vehicle manufacturer (TBD). | |
| SSR-SYS-0152 | SYS | Design constraint | QM | Low | Review | The ECA shall carry out the consistency check by itself. | N-SYS-026 | REQ_UDS_0185 | ||
| SSR-SYS-0153 | SYS | Design constraint | QM | Low | Test | The ECA shall limit the occurrence counter to a minimum value of 0. | N-SYS-026 | REQ_UDS_0198 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0154 | SYS | Design constraint | QM | Low | Test | The ECA shall limit the occurrence counter to a maximum value of 126. | N-SYS-026 | REQ_UDS_0199 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0155 | SYS | Design constraint | QM | Low | Test | The ECA shall use a default occurrence counter value of 0. | N-SYS-026 | REQ_UDS_0200 | ||
| SSR-SYS-0156 | SYS | Design constraint | QM | Low | Test | The ECA shall increment the occurrence counter by 1 only. | N-SYS-026 | REQ_UDS_0201 | ||
| SSR-SYS-0157 | SYS | Design constraint | QM | Low | Review | If the occurrence counter value is below the maximum value, the ECA shall increment the occurrence counter. | N-SYS-027 | REQ_UDS_0202 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0158 | SYS | Design constraint | QM | Low | Test | The ECA shall define the occurrence counter value 127 as indicating errors with the counter. | N-SYS-027 | REQ_UDS_0206 | ||
| SSR-SYS-0159 | SYS | Design constraint | QM | Low | Test | The ECA P2Server time shall be within the range of 0 ms to 50 ms. | N-SYS-027 | REQ_UDS_0225 | ||
| SSR-SYS-0160 | SYS | Design constraint | QM | Low | Test | The ECA shall use a value of 150 ms for P2Client. | N-SYS-027 | REQ_UDS_0226 | ||
| SSR-SYS-0161 | SYS | Design constraint | QM | Low | Test | The ECA P2*Server time shall be within the range of 0 ms to 4000 ms. | N-SYS-027 | REQ_UDS_0227 | ||
| SSR-SYS-0162 | SYS | Design constraint | QM | Low | Test | The ECA shall limit the P4_Server_max timing parameter to a maximum value of 30 s. | N-SYS-027 | REQ_UDS_0229 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0163 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall document the implemented value for P4_Server_max. | N-SYS-028 | REQ_UDS_0230 | The implemented value for P4_Server_max is not stated in the source; it is to be documented by the ECA supplier (TBD). | |
| SSR-SYS-0164 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall apply the latest version of CVS151. | N-SYS-028 | CR-SYS-0290 | ||
| SSR-SYS-0165 | split | SYS | Design constraint | QM | Low | Review | If a matching allow rule is found and each rule setting is fulfilled, the ECA shall accept the request. | N-SYS-028 | CR-SYS-0291 | |
| SSR-SYS-0165-2 | split | SYS | Design constraint | QM | Low | Review | If a matching deny rule is found and each rule setting is fulfilled, the ECA shall deny the request. | N-SYS-028 | CR-SYS-0291 | |
| SSR-SYS-0166 | SYS | Design constraint | QM | Low | Review | If a matching rule is found and one or more of the rule settings are unfulfilled, the ECA shall consider the request rejected for that rule. | N-SYS-028 | CR-SYS-0292 | ||
| SSR-SYS-0167 | SYS | Design constraint | QM | Low | Review | The ECA shall support two octets in the version field. | N-SYS-028 | CR-SYS-0293 | ||
| SSR-SYS-0168 | SYS | Design constraint | QM | Low | Review | The ECA shall support major version value 3 and minor version value 0. | N-SYS-028 | CR-SYS-0294 | ||
| SSR-SYS-0169 | SYS | Design constraint | QM | Low | Review | Where support of a version other than major version 3 and minor version 0 is required, the ECA supplier shall agree the scope of that version support with the relevant Traton project. | N-SYS-029 | CR-SYS-0295 | Which specific versions beyond major version 3 and minor version 0 must be supported is out of scope of the source document and remains TBD pending agreement between the relevant Traton projects. | |
| SSR-SYS-0170 | SYS | Design constraint | QM | Low | Review | If the version number is incompatible with the ECA implementation, the ECA shall reject the request to store the data. | N-SYS-029 | CR-SYS-0296 | ||
| SSR-SYS-0171 | SYS | Design constraint | QM | Low | Review | The ECA shall support, for each entry in the did-rules, one octet representing the did-rule settings followed by two octets representing the DID. | N-SYS-029 | CR-SYS-0297 | ||
| SSR-SYS-0172 | SYS | Design constraint | QM | Low | Review | The ECA shall support, for each entry in the rid-rules, one octet that represents the rid-rule settings followed by two octets that represent the RID. | N-SYS-029 | CR-SYS-0299 | ||
| SSR-SYS-0173 | SYS | Design constraint | QM | Low | Test | The ECA shall permit the request only where the client has read access to each included DID and has access to the service itself. | N-SYS-029 | CR-SYS-0301 | ||
| SSR-SYS-0174 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall apply the latest version of CVS154. | N-SYS-029 | CR-SYS-0304 | ||
| SSR-SYS-0175 | SYS | Design constraint | QM | Low | Review | The ECA shall support a DSC Metadata block containing version and id fields. | N-SYS-030 | CR-SYS-0305 | ||
| SSR-SYS-0176 | SYS | Design constraint | QM | Low | Review | The ECA shall support the Major and Minor version as specified in section 3.2. | N-SYS-030 | CR-SYS-0306 | ||
| SSR-SYS-0177 | SYS | Design constraint | QM | Low | Review | The ECA shall support a DSC containing verificationEntries. | N-SYS-030 | CR-SYS-0307 | ||
| SSR-SYS-0178 | SYS | Design constraint | QM | Low | Review | The ECA shall support a DSC containing itemEntries. | N-SYS-030 | CR-SYS-0308 | ||
| SSR-SYS-0179 | SYS | Design constraint | QM | Low | Review | When a DSC transmitted by the client contains a verificationEntries field with no VerificationEntry items, the ECA shall expect an ASN.1 SEQUENCE tag with length zero for that field. | N-SYS-030 | CR-SYS-0309 | ||
| SSR-SYS-0180 | SYS | Design constraint | QM | Low | Review | When a DSC transmitted by the client contains an ItemEntries field with no items, the ECA shall expect an ASN.1 SEQUENCE tag with length zero for that field. | N-SYS-030 | CR-SYS-0310 | ||
| SSR-SYS-0181 | SYS | Design constraint | QM | Low | Test | Where the VerificationEntry hashCmp option is selected, the ECA shall verify the data by hash comparison. | N-SYS-031 | CR-SYS-0311 | ||
| SSR-SYS-0182 | SYS | Design constraint | QM | Low | Review | Where the instance specification states specialized actions, the ECA shall process each VerificationEntry one by one. | N-SYS-031 | CR-SYS-0312 | ||
| SSR-SYS-0183 | SYS | Design constraint | QM | Low | Test | The ECA shall use the HashAlgorithm specified by the hashAlgorithm field, as defined in RFC 6234, to hash the data to be verified. | N-SYS-031 | CR-SYS-0313 | ||
| SSR-SYS-0184 | SYS | Design constraint | QM | Low | Review | The ECA shall support the SHA512 HashAlgorithm as defined in the ASN.1 definition in section 3.2. | N-SYS-031 | CR-SYS-0314 | ||
| SSR-SYS-0185 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA shall support both of the specified choices. | N-SYS-031 | CR-SYS-0315 | CLARIFY: The source states 'both of the choices' without identifying them in this excerpt. Which two choices must the ECA support (for example, the two HashAlgorithm options of a specific ASN.1 CHOICE), and where are they defined? |
| SSR-SYS-0186 | SYS | Design constraint | QM | Low | Test | The ECA shall set the initial value of the counter to 0. | N-SYS-031 | CR-SYS-0316 | ||
| SSR-SYS-0187 | SYS | Design constraint | QM | Low | Test | The ECA shall decrypt the data chunks identified by the Range field. | N-SYS-032 | CR-SYS-0317 | ||
| SSR-SYS-0188 | SYS | Design constraint | QM | Low | Review | The ECA shall set the structure version for this document release to Major '04' and Minor '00'. | N-SYS-032 | CR-SYS-0318 | ||
| SSR-SYS-0189 | SYS | Design constraint | QM | Low | Test | The ECA shall verify the length of the version field. | N-SYS-032 | CR-SYS-0320 | ||
| SSR-SYS-0190 | SYS | Design constraint | QM | Low | Test | The ECA shall verify the length of the id field. | N-SYS-032 | CR-SYS-0322 | ||
| SSR-SYS-0191 | SYS | Design constraint | QM | Low | Review | The ECA shall support the hashAlgorithm. | N-SYS-032 | CR-SYS-0323 | ||
| SSR-SYS-0192 | SYS | Design constraint | QM | Low | Test | The ECA shall verify that the length of each referenceHash is consistent with the output size of the hash algorithm specified by the hashAlgorithm field. | N-SYS-032 | CR-SYS-0324 | ||
| SSR-SYS-0193 | SYS | Design constraint | QM | Low | Review | If the ECA rejects a DSC instance that was transmitted with EMP, the ECA shall return an error code to the client. | N-SYS-033 | CR-SYS-0325 | ||
| SSR-SYS-0194 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall apply the latest version of CVS31. | N-SYS-033 | CR-SYS-0326 | ||
| SSR-SYS-0195 | needs clarification | SYS | Design constraint | QM | Low | Test | The ECA supplier shall apply CVS31 as a requirement specification for the ECA. | N-SYS-033 | CR-SYS-0327 | CLARIFY: This text is the CVS31 Foreword describing the document's scope and applicability within the TRATON Group; it states no verifiable ECA obligation. Should it be treated as informative (dropped), or is a specific applicability requirement intended?; quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) |
| SSR-SYS-0196 | needs clarification | SYS | Design constraint | QM | Low | Review | The term 'Affiliate' shall mean any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, where 'control' means ownership of at least 50% of the voting rights or of the interest in the issued share capital, including any branch. | N-SYS-033 | CR-SYS-0328 | CLARIFY: This is a contractual glossary definition of 'Affiliate' and 'control'; it defines terms rather than stating a verifiable ECA obligation. Confirm it should be recorded as a definition rather than a system requirement. |
| SSR-SYS-0197 | split | SYS | Design constraint | QM | Low | Review | The ECA supplier shall document each deviation from the specification. | N-SYS-033 | CR-SYS-0329 | |
| SSR-SYS-0197-2 | split | SYS | Design constraint | QM | Low | Review | The vehicle manufacturer shall review each documented deviation from the specification. | N-SYS-033 | CR-SYS-0329 | |
| SSR-SYS-0198 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree the TBD subject item with the vehicle manufacturer. | N-SYS-033 | CR-SYS-0330 | CLARIFY: In CVS31 page 6 (CR-SYS-0330), what specific item, parameter, value, or scope must be agreed between the ECA supplier and the vehicle manufacturer?; The subject of the agreement (what parameter, scope, deviation, or item must be agreed) is not recoverable from the customer statement or the context neighbours (TBD). |
| SSR-SYS-0199 | SYS | Design constraint | QM | Low | Test | The ECA shall represent the field using 32 octets. | N-SYS-034 | CR-SYS-0332 | ||
| SSR-SYS-0200 | SYS | Design constraint | QM | Low | Test | The client shall generate the proofOfOwnershipClient according to the pseudo code specified in the source specification. | N-SYS-034 | CR-SYS-0337 | ||
| SSR-SYS-0201 | needs clarification | SYS | Design constraint | QM | Low | Test | If the NodeUID extension is not detected, the ECA shall continue the operation as specified for the case in which the NodeUID extension is absent. | N-SYS-034 | CR-SYS-0339 | CLARIFY: The source sentence is truncated ('...continue as in'). Which section or case defines how the operation continues when the NodeUID extension is not detected? |
| SSR-SYS-0202 | SYS | Design constraint | QM | Low | Test | The ECA shall represent the roles as a bit-pattern octet string. | N-SYS-034 | CR-SYS-0340 | ||
| SSR-SYS-0203 | SYS | Design constraint | QM | Low | Test | The ECA shall set the CA field of the basicConstraints extension to False. | N-SYS-034 | CR-SYS-0341 | ||
| SSR-SYS-0204 | SYS | Design constraint | QM | Low | Test | The ECA shall include the clientAuth object identifier 1.3.6.1.5.5.7.3.2 in the ExtendedKeyUsage extension. | N-SYS-034 | CR-SYS-0342 | ||
| SSR-SYS-0205 | SYS | Design constraint | QM | Low | Test | The ECA shall implement the cryptographic random number generator (CRNG) in accordance with CVS150. | N-SYS-035 | CR-SYS-0349 | ||
| SSR-SYS-0206 | SYS | Design constraint | QM | Low | Review | When a valid proofOfOwnership has been received, the ECA shall start the A3 timer. | N-SYS-035 | CR-SYS-0351 | ||
| SSR-SYS-0207 | SYS | Design constraint | QM | Low | Review | When a request is received from the same client, the ECA shall restart the A3 timer. | N-SYS-035 | CR-SYS-0352 | ||
| SSR-SYS-0208 | SYS | Design constraint | QM | Low | Test | The ECA shall implement the A3 timer separately from the S3 timer. | N-SYS-035 | CR-SYS-0355 | ||
| SSR-SYS-0209 | SYS | Design constraint | QM | Low | Test | The ECA shall set the delay timer to 1 second. | N-SYS-035 | CR-SYS-0356 | ||
| SSR-SYS-0210 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall apply the latest version of CVS32. | N-SYS-035 | CR-SYS-0360 | ||
| SSR-SYS-0211 | needs clarification | SYS | Design constraint | QM | Low | Test | The ECA supplier shall apply CVS32 as a requirement specification for the ECA. | N-SYS-036 | CR-SYS-0361 | CLARIFY: This text is the CVS32 Foreword describing the document's scope and applicability within the TRATON Group; it states no verifiable ECA obligation. Should it be treated as informative (dropped), or is a specific applicability requirement intended?; quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) |
| SSR-SYS-0212 | needs clarification | SYS | Design constraint | QM | Low | Review | The term 'Affiliate' shall mean any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, where 'control' means ownership of at least 50% of the voting rights or of the interest in the issued share capital, including any branch. | N-SYS-036 | CR-SYS-0362 | CLARIFY: This is a contractual glossary definition of 'Affiliate' and 'control'; it defines terms rather than stating a verifiable ECA obligation. Confirm it should be recorded as a definition rather than a system requirement. |
| SSR-SYS-0213 | needs clarification | SYS | Design constraint | QM | Low | Test | The ECA shall implement Secured Data Transmission (SDT) in accordance with the referenced specification. | N-SYS-036 | CR-SYS-0363 | CLARIFY: The source sentence is truncated ('...follow the information provided in'). Which document or section governs the SDT implementation? |
| SSR-SYS-0214 | split | SYS | Design constraint | QM | Low | Review | The ECA shall maintain instances of the state variables PREQARC and PRESARC. | N-SYS-036 | CR-SYS-0366 | |
| SSR-SYS-0214-2 | split | SYS | Design constraint | QM | Low | Review | The client shall maintain instances of the state variables PREQARC and PRESARC. | N-SYS-036 | CR-SYS-0366 | |
| SSR-SYS-0215 | split | SYS | Design constraint | QM | Low | Test | When constructing an SDT request, the client shall increment PREQARC by one. | N-SYS-036 | CR-SYS-0367 | |
| SSR-SYS-0215-2 | split | SYS | Design constraint | QM | Low | Test | When constructing an SDT request, the client shall populate the ANTIREPLAYCNT protocol element with the resulting PREQARC value. | N-SYS-036 | CR-SYS-0367 | |
| SSR-SYS-0216 | split | SYS | Design constraint | QM | Low | Review | When constructing an SDT response, the ECA shall increment PRESARC by one. | N-SYS-036 | CR-SYS-0369 | |
| SSR-SYS-0216-2 | split | SYS | Design constraint | QM | Low | Review | When constructing an SDT response, the ECA shall populate the ANTIREPLAYCNT protocol element with the resulting PRESARC value. | N-SYS-036 | CR-SYS-0369 | |
| SSR-SYS-0217 | needs clarification | SYS | Design constraint | QM | Low | Test | When constructing the first request of an SDT sequence, the client shall populate the ANTIREPLAYCNT protocol element with TBD. | N-SYS-037 | CR-SYS-0371 | CLARIFY: The source sentence is truncated ('...first request of an'). What value shall the ANTIREPLAYCNT protocol element of the first request of an SDT sequence be populated with (for example, zero, by analogy with the first response)?; TBD: value for the ANTIREPLAYCNT protocol element of the first request of an SDT sequence - not stated in the truncated source (likely zero, by analogy with the first response in SSR-SYS-0218). |
| SSR-SYS-0218 | split | SYS | Design constraint | QM | Low | Review | When constructing the first response of an SDT sequence, the ECA shall populate the ANTIREPLAYCNT protocol element with the value zero. | N-SYS-037 | CR-SYS-0372 | |
| SSR-SYS-0218-2 | split | SYS | Design constraint | QM | Low | Review | When constructing the first response of an SDT sequence, the ECA shall set PRESARC to zero. | N-SYS-037 | CR-SYS-0372 | |
| SSR-SYS-0219 | SYS | Design constraint | QM | Low | Test | The client shall maintain the state variable PREQTAG. | N-SYS-037 | CR-SYS-0373 | ||
| SSR-SYS-0220 | split | SYS | Design constraint | QM | Low | Test | The ECA shall construct the N argument as an octet string of length 12 octets. | N-SYS-037 | CR-SYS-0374 | |
| SSR-SYS-0220-2 | split | SYS | Design constraint | QM | Low | Test | The ECA shall set the first 10 octets of the N argument to 6E6F6E73656E73652121. | N-SYS-037 | CR-SYS-0374 | |
| SSR-SYS-0220-3 | split | SYS | Design constraint | QM | Low | Test | The ECA shall set the remaining 2 octets of the N argument to the ANTIREPLAYCNT value. | N-SYS-037 | CR-SYS-0374 | |
| SSR-SYS-0221 | SYS | Design constraint | QM | Low | Test | The ECA shall set the plaintext argument P to the octet string formed by concatenating the INTMSGREQID and the SRVSPECPARAM. | N-SYS-037 | CR-SYS-0375 | ||
| SSR-SYS-0222 | SYS | Design constraint | QM | Low | Test | The client shall populate the APAR protocol element in the request with bits 0, 4, 5, and 6 set to true. | N-SYS-037 | CR-SYS-0377 | ||
| SSR-SYS-0223 | SYS | Design constraint | QM | Low | Test | The client shall populate the SIGMACBYTE protocol element in the request with TAG. | N-SYS-038 | CR-SYS-0378 | ||
| SSR-SYS-0224 | SYS | Design constraint | QM | Low | Test | The client shall store TAG in its state variable PREQTAG. | N-SYS-038 | CR-SYS-0379 | ||
| SSR-SYS-0225 | SYS | Design constraint | QM | Low | Review | The ECA shall populate the APAR protocol element in the response with bits 4 and 5 set to true. | N-SYS-038 | CR-SYS-0380 | ||
| SSR-SYS-0226 | SYS | Design constraint | QM | Low | Review | The ECA shall populate the SIGMACBYTE protocol element in the request with TAG. | N-SYS-038 | CR-SYS-0381 | ||
| SSR-SYS-0227 | needs clarification | SYS | Design constraint | QM | Low | Test | The ECA shall place the remaining octets in the SRVSPECPARAM protocol element. | N-SYS-038 | CR-SYS-0382 | CLARIFY: The source is a sentence fragment ('one octet, and the rest should go in the SRVSPECPARAM protocol element'): which data field is split, what element receives the first octet, and which entity (the ECA/server or the off-board client) places the remaining octets into the SRVSPECPARAM protocol element?; Which data field is being split into 'one octet' plus a remainder; What element receives the first octet; Whether the actor is the ECA (server) or the off-board client |
| SSR-SYS-0228 | split | SYS | Design constraint | QM | Low | Test | The ECA shall construct the N argument as an octet string of length 12 octets. | N-SYS-038 | CR-SYS-0383 | |
| SSR-SYS-0228-2 | split | SYS | Design constraint | QM | Low | Test | The ECA shall set the first 10 octets of the N argument to 6E6F6E73656E73652121. | N-SYS-038 | CR-SYS-0383 | |
| SSR-SYS-0228-3 | split | SYS | Design constraint | QM | Low | Test | The ECA shall set the remaining 2 octets of the N argument to the ANTIREPLAYCNT value. | N-SYS-038 | CR-SYS-0383 | |
| SSR-SYS-0229 | SYS | Design constraint | QM | Low | Test | The client shall populate the APAR protocol element of the request with bits 0, 5 and 6 set to true. | N-SYS-039 | CR-SYS-0385 | ||
| SSR-SYS-0230 | SYS | Design constraint | QM | Low | Test | The client shall populate the SIGMACBYTE protocol element of the request with TAG. | N-SYS-039 | CR-SYS-0386 | ||
| SSR-SYS-0231 | SYS | Design constraint | QM | Low | Test | The client shall store TAG in the state variable PREQTAG. | N-SYS-039 | CR-SYS-0387 | ||
| SSR-SYS-0232 | SYS | Design constraint | QM | Low | Test | The client shall verify the SDT response with the A argument set to the octet string comprising the protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string stored in the state variable PREQTAG. | N-SYS-039 | CR-SYS-0388 | ||
| SSR-SYS-0233 | SYS | Design constraint | QM | Low | Review | The ECA shall verify the SDT request with the A argument set to the octet string comprising the protocol elements of the SDT response, excluding the SIGMACBYTE protocol element. | N-SYS-039 | CR-SYS-0389 | ||
| SSR-SYS-0234 | SYS | Design constraint | QM | Low | Review | The ECA shall populate the APAR protocol element of the response with bit 5 set to true. | N-SYS-039 | CR-SYS-0391 | ||
| SSR-SYS-0235 | SYS | Design constraint | QM | Low | Test | The client shall populate the SIGMACBYTE protocol element of the response with TAG. | N-SYS-040 | CR-SYS-0392 | ||
| SSR-SYS-0236 | SYS | Design constraint | QM | Low | Test | When the client receives an SDT response, if the request is too short or malformed, the client shall discard the response. | N-SYS-040 | CR-SYS-0395 | Definition of 'too short' (protocol minimum length is qualitative in the source) | |
| SSR-SYS-0237 | SYS | Design constraint | QM | Low | Test | When the client receives an SDT response, if ANTIREPLAYCNT is less than or equal to PRESARC, the client shall discard the response. | N-SYS-040 | CR-SYS-0396 | Source sentence was truncated at 'discard the'; object 'response' inferred from sibling requirements CR-SYS-0395/0397 | |
| SSR-SYS-0238 | SYS | Design constraint | QM | Low | Test | When the client receives an SDT response, if the client fails to verify or decrypt the response, the client shall discard the response. | N-SYS-040 | CR-SYS-0397 | ||
| SSR-HW-0001 | HW | Design constraint | QM | Low | Inspection | The ECA supplier shall provide a hardware bill of materials that lists the part number and version of each hardware component used in the product. | N-HW-001 | REQ_SEC_0025 | ||
| SSR-CYBER-0030 | CYBER | Design constraint | QM | Medium | Review | The ECA supplier shall establish, together with the vehicle manufacturer, a cybersecurity Development Interface Agreement that assigns the responsibilities for the distributed cybersecurity activities. | N-CYBER-008 | REQ_SEC_0042 | ||
| SSR-CYBER-0031 | CYBER | Design constraint | QM | Medium | Test | The ECA shall verify the integrity and authenticity of the vehicle-manufacturer-specified set of data stored within the ECA. | N-CYBER-009 | REQ_SEC_0008 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-CYBER-0032 | CYBER | Design constraint | QM | High | Test | The ECA shall verify the integrity according to the information supplied in the SDSC, including memory regions that are not programmed. | N-CYBER-009 | CR-CYBER-0042 | ||
| SSR-CYBER-0033 | CYBER | Design constraint | QM | Medium | Test | The ECA shall verify the integrity of the software as part of the consistency check. | N-CYBER-009 | CR-CYBER-0048 | ||
| SSR-CYBER-0034 | CYBER | Design constraint | QM | Medium | Test | The ECA shall be the only entity that carries out the integrity check. | N-CYBER-009 | CR-CYBER-0050 | ||
| SSR-CYBER-0035 | split | CYBER | Design constraint | QM | Medium | Review | The ECA shall obtain the information required to verify software integrity from the Software Data Security Container provided by the trusted source. | N-CYBER-009 | CR-CYBER-0052 | |
| SSR-CYBER-0035-2 | split | CYBER | Design constraint | QM | Medium | Review | Where decryption is enabled, the ECA shall obtain the information required to decrypt the transported data from the Software Data Security Container provided by the trusted source. | N-CYBER-009 | CR-CYBER-0052 | |
| SSR-CYBER-0036 | CYBER | Design constraint | QM | Medium | Test | If OK is returned, the ECA shall accept the installed software as valid in terms of integrity. | N-CYBER-009 | CR-CYBER-0053 | ||
| SSR-CYBER-0037 | CYBER | Design constraint | QM | Medium | Test | The ECA shall verify the authenticity and integrity of the software as part of the consistency check. | N-CYBER-010 | REQ_UDS_0186 | ||
| SSR-CYBER-0038 | CYBER | Design constraint | QM | Medium | Test | The ECA shall be the only entity that carries out the authenticity and integrity check. | N-CYBER-010 | REQ_UDS_0188 | ||
| SSR-MECH-0001 | MECH | Design constraint | QM | Low | Inspection | The ECA shall apply ingress and egress filtering as boundary controls on each communication interface. | N-MECH-001 | REQ_SEC_0012 | ||
| SSR-SYS-0239 | SYS | Design constraint | QM | Low | Test | The ECA shall make the communication boundary controls configurable by the vehicle manufacturer. | N-SYS-041 | REQ_SEC_0013 | ||
| SSR-HW-0002 | HW | Design constraint | QM | Low | Test | While in series production, the ECA shall provide only the hardware interfaces and protocols specified by the vehicle manufacturer. | N-HW-002 | REQ_SEC_0026 | ||
| SSR-HW-0003 | HW | Design constraint | QM | Low | Test | Where the ECA is returned from the field, the ECA shall support field-return analysis. | N-HW-002 | REQ_SEC_0047 | ||
| SSR-HW-0004 | HW | Design constraint | QM | Low | Test | Where the ECA is enabled for field-return analysis, the ECA shall prevent its use as a spare part. | N-HW-002 | REQ_SEC_0049 | ||
| SSR-HW-0005 | HW | Design constraint | QM | Low | Test | The ECA shall permit reuse by a third party only where system support from the vehicle manufacturer is provided. | N-HW-002 | CR-HW-0006 | ||
| SSR-HW-0006 | HW | Design constraint | QM | Low | Test | The ECA shall report the current system state. | N-HW-002 | 6.14 | ||
| SSR-HW-0007 | HW | Design constraint | QM | Low | Test | The ECA shall execute a safe boot sequence that prevents unwanted or undefined behaviour during and after a loss of power or a corruption of stored data. | N-HW-002 | 7.3 | Precise, testable definition of 'unwanted or undefined behaviour' (source is qualitative) | |
| SSR-HW-0008 | HW | Design constraint | QM | Low | Test | The ECA shall implement short-circuit protection in hardware. | N-HW-003 | CR-HW-0014 | ||
| SSR-HW-0009 | split | HW | Design constraint | QM | Low | Inspection | The ECA tab headers shall comply with TB1787. | N-HW-003 | CR-HW-0016 | The self-extinguishing material class or example given after 'i.e.' in clause 7.9 is truncated in the source and is not available (TBD). |
| SSR-HW-0009-2 | split | HW | Design constraint | QM | Low | Inspection | The ECA tab headers shall be made of a self-extinguishing material. | N-HW-003 | CR-HW-0016 | |
| SSR-HW-0010 | HW | Design constraint | QM | Low | Test | The ECA shall draw all power it uses from the battery connection. | N-HW-003 | CR-HW-0018 | ||
| SSR-HW-0011 | HW | Design constraint | QM | Low | Test | The ECA shall meet the quiescent-current limit specified in CVS41 independent of the input and output conditions. | N-HW-003 | CR-HW-0019 | ||
| SSR-HW-0012 | HW | Design constraint | QM | Low | Test | The ECA shall control the power-up sequence to the µP. | N-HW-003 | CR-HW-0020 | ||
| SSR-HW-0013 | split | HW | Design constraint | QM | Low | Test | The ECA shall exhibit a failure rate of no more than 0 ppm at 0 km, 200 ppm/year during years 1 to 5, 400 ppm/year during years 6 to 10, and 1000 ppm/year during years 11 to 15. | N-HW-003 | CR-HW-0023 | CLARIFY: Source section 8.7 ('External vulnerable components might need to be replaceable') was concatenated into this failure-rate requirement and is stated tentatively: is replaceability of external vulnerable components mandatory, and which components count as 'vulnerable'?; Whether replaceability of external vulnerable components (source 8.7) is mandatory - source uses 'might need to'; Which external components are classified as 'vulnerable' |
| SSR-HW-0013-2 | split | HW | Design constraint | QM | Low | Test | Where the ECA uses external vulnerable components, the ECA shall make each such component replaceable. | N-HW-003 | CR-HW-0023 | |
| SSR-HW-0014 | HW | Design constraint | QM | Low | DT | The ECA shall comply with STD4158, the Scania Black List of prohibited chemical substances, in addition to CVS55 regarding the recycling and environmental requirements. | N-HW-004 | CR-HW-0024 | The source uses the plural 'the following standards' but lists only STD4158; whether additional standards were intended is TBD (possible source truncation). | |
| SSR-HW-0015 | split | HW | Design constraint | QM | Low | DT | The ECA supplier shall perform the full design-verification environmental test programme at B-sample level according to CVS40 and CVS41. | N-HW-004 | CR-HW-0026 | CLARIFY: The source ends mid-phrase at 'CVS40 and CVS41 (incl.': what additional scope was intended after 'incl.'?; Source truncated at 'CVS40 and CVS41 (incl.'; any additional included scope of the test programmes is unknown |
| SSR-HW-0015-2 | split | HW | Design constraint | QM | Low | DT | The ECA supplier shall perform the full product-validation environmental test programme at C-sample level according to CVS40 and CVS41. | N-HW-004 | CR-HW-0026 | |
| SSR-HW-0016 | HW | Design constraint | QM | Low | Inspection | The ECA supplier shall test the connectors according to TB1787. | N-HW-004 | CR-HW-0027 | ||
| SSR-HW-0017 | HW | Design constraint | QM | Low | Test | The ECA shall be made eligible for programming only after each programming precondition agreed between the ECA supplier and the vehicle manufacturer has been fulfilled. | N-HW-004 | CR-HW-0028 | ||
| SSR-HW-0018 | HW | Design constraint | QM | Low | Review | The ECA supplier shall agree with the vehicle manufacturer whether the ECA supports stand-alone programming at the vehicle manufacturer premises. | N-HW-004 | CR-HW-0031 | ||
| SSR-HW-0019 | HW | Design constraint | QM | Low | Test | If, at startup, the ECA hardware and software are consistent and no programming request is pending, the ECA shall start and execute the application. | N-HW-004 | CR-HW-0033 | ||
| SSR-HW-0020 | HW | Design constraint | QM | Low | Test | The ECA shall populate the DID with a snapshot of the mandatory lifetime ECA-runtime operational data. | N-HW-005 | REQ_UDS_0027 | ||
| SSR-HW-0021 | HW | Design constraint | QM | Low | Test | When the ECA is reset, the ECA shall restart and re-initialise within 2 s. | N-HW-005 | REQ_UDS_0066 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-HW-0022 | HW | Design constraint | QM | Low | Inspection | Where the ECA supports a request containing more than one data identifier, the ECA supplier shall document that support. | N-HW-005 | REQ_UDS_0087 | ||
| SSR-HW-0023 | split | HW | Design constraint | QM | Low | Test | The ECA shall encode the ECU start-up reason in bits 0-3 and the ECU alive reason in bits 4-7 of the start-up and alive reasons data element number 54, in accordance with the value definitions in CVS124, page 49. | N-HW-005 | CR-HW-0043 | |
| SSR-HW-0023-2 | split | HW | Design constraint | QM | Low | Test | At ECU start-up, the ECA shall set the start-up reason and the alive reason to identical values. | N-HW-005 | CR-HW-0043 | |
| SSR-HW-0024 | HW | Design constraint | QM | Low | Test | The file specified by the filePathAndName parameter shall already exist in the ECA file system. | N-HW-005 | CR-HW-0045 | ||
| SSR-HW-0025 | HW | Design constraint | QM | Low | Test | If the ECA received the information related to any of the conditions during the same driving cycle, the ECA shall use the received information. | N-HW-005 | CR-HW-0046 | ||
| SSR-CYBER-0039 | CYBER | Design constraint | QM | High | Test | The ECA shall allow the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECA according to the vehicle manufacturer specification. | N-CYBER-011 | REQ_SEC_0016 | ||
| SSR-CYBER-0040 | CYBER | Design constraint | QM | Medium | Review | In production vehicle systems, the ECA shall use secrets, public keys and other data for cybersecurity controls that differ from those used in the pre-production phases. | N-CYBER-011 | REQ_SEC_0019 | ||
| SSR-CYBER-0041 | CYBER | Design constraint | QM | Highest | Test | The client shall generate the signatures using the private key corresponding to the client certificate. | N-CYBER-011 | CR-CYBER-0107 | ||
| SSR-CYBER-0042 | CYBER | Design constraint | QM | Highest | Test | The ECA shall generate the signatures using the private key corresponding to the server certificate. | N-CYBER-011 | CR-CYBER-0108 | ||
| SSR-CYBER-0043 | CYBER | Design constraint | QM | Highest | Test | The client certificate shall include the Key Usage extension defined in RFC 5280. | N-CYBER-011 | CR-CYBER-0118 | ||
| SSR-CYBER-0044 | CYBER | Design constraint | QM | High | Test | The Key Usage extension shall contain DigitalSignature. | N-CYBER-011 | CR-CYBER-0119 | ||
| SSR-CYBER-0045 | CYBER | Design constraint | QM | Highest | Test | The client certificate shall include the Extended Key Usage extension defined in RFC 5280. | N-CYBER-012 | CR-CYBER-0120 | ||
| SSR-CYBER-0046 | CYBER | Design constraint | QM | Low | Test | Each private key shall be generated using a CRNG. | N-CYBER-012 | CR-CYBER-0123 | ||
| SSR-CYBER-0047 | CYBER | Design constraint | QM | Medium | Test | The ECA shall support the HKDF key derivation function using HMAC-SHA512. | N-CYBER-012 | CR-CYBER-0134 | ||
| SSR-CYBER-0048 | CYBER | Design constraint | QM | Low | Test | The salt argument to the HKDF function shall be set to the zero-length octet string. | N-CYBER-012 | CR-CYBER-0135 | ||
| SSR-CYBER-0049 | CYBER | Design constraint | QM | Low | Test | The L argument to the HKDF function shall be set to 64. | N-CYBER-012 | CR-CYBER-0136 | ||
| SSR-CYBER-0050 | split | CYBER | Design constraint | QM | Highest | Test | The ECA shall decrypt the request using octets 0-31 of the okm as the key. | N-CYBER-012 | CR-CYBER-0137 | |
| SSR-CYBER-0050-2 | split | CYBER | Design constraint | QM | Highest | Test | The client shall encrypt the request using octets 0-31 of the okm as the key. | N-CYBER-012 | CR-CYBER-0137 | |
| SSR-CYBER-0051 | split | CYBER | Design constraint | QM | Highest | Test | The ECA shall encrypt the response using octets 32-63 of the okm as the key. | N-CYBER-013 | CR-CYBER-0138 | |
| SSR-CYBER-0051-2 | split | CYBER | Design constraint | QM | Highest | Test | The client shall decrypt the response using octets 32-63 of the okm as the key. | N-CYBER-013 | CR-CYBER-0138 | |
| SSR-CYBER-0052 | CYBER | Design constraint | QM | Highest | Test | Where SDT_CHACHA20_POLY1305 is used, the ECA shall set the K argument to a key octet string of 32 octets. | N-CYBER-013 | CR-CYBER-0139 | ||
| SSR-CYBER-0053 | CYBER | Design constraint | QM | Low | Test | The L argument to the HKDF function shall be set to 64. | N-CYBER-013 | CR-CYBER-0144 | ||
| SSR-CYBER-0054 | split | CYBER | Design constraint | QM | Medium | Test | The ECA shall verify the request using octets 0-31 of the okm as the key. | N-CYBER-013 | CR-CYBER-0145 | |
| SSR-CYBER-0054-2 | split | CYBER | Design constraint | QM | Medium | Test | The client shall authenticate the request using octets 0-31 of the okm as the key. | N-CYBER-013 | CR-CYBER-0145 | |
| SSR-CYBER-0055 | split | CYBER | Design constraint | QM | Medium | Test | The ECA shall authenticate the response using octets 32-63 of the okm as the key. | N-CYBER-013 | CR-CYBER-0146 | |
| SSR-CYBER-0055-2 | split | CYBER | Design constraint | QM | Medium | Test | The client shall verify the response using octets 32-63 of the okm as the key. | N-CYBER-013 | CR-CYBER-0146 | |
| SSR-CYBER-0056 | CYBER | Design constraint | QM | Highest | Test | Where SDT_POLY1305 is used, the ECA shall set the K argument to a key octet string of 32 octets. | N-CYBER-013 | CR-CYBER-0147 | ||
| SSR-SYS-0240 | SYS | Design constraint | QM | Low | Test | The ECA shall contain only the secrets agreed between the vehicle manufacturer and the ECA supplier. | N-SYS-042 | REQ_SEC_0021 | ||
| SSR-SYS-0241 | SYS | Design constraint | QM | Low | Test | While in field operation, the ECA shall keep the field-return analysis secrets disabled. | N-SYS-042 | REQ_SEC_0048 | ||
| SSR-CYBER-0057 | CYBER | Design constraint | QM | Low | Review | The ECA shall provide the capability to update its software. | N-CYBER-014 | REQ_SEC_0043 | ||
| SSR-CYBER-0058 | CYBER | Design constraint | QM | Medium | Review | The ECA supplier shall deliver the information required to verify the integrity of the flash files. | N-CYBER-014 | CR-CYBER-0037 | ||
| SSR-CYBER-0059 | CYBER | Design constraint | QM | Medium | Test | The ECA shall update its software only after the integrity information has been supplied to it. | N-CYBER-014 | CR-CYBER-0049 | ||
| SSR-CYBER-0060 | CYBER | Design constraint | QM | Medium | Test | The ECA shall update its software only after the authenticity and integrity information has been supplied to it. | N-CYBER-014 | REQ_UDS_0187 | ||
| SSR-CYBER-0061 | CYBER | Design constraint | QM | Low | Review | When a cybersecurity patch becomes available, the ECA supplier shall inform the vehicle manufacturer of the patch. | N-CYBER-015 | REQ_SEC_0030 | ||
| SSR-CYBER-0062 | CYBER | Design constraint | QM | Low | Review | When a vulnerability is identified during the product lifecycle, the ECA supplier shall communicate the vulnerability to the vehicle manufacturer within TBD. | N-CYBER-015 | REQ_SEC_0033 | Reporting timeframe is unspecified: 'promptly' has no stated value and is to be agreed with the vehicle manufacturer (see CR-VAL-0004). | |
| SSR-CYBER-0063 | CYBER | Design constraint | QM | Low | Review | When a vulnerability has been identified and reported, the ECA supplier shall agree with the vehicle manufacturer on the initial response to the vulnerability. | N-CYBER-015 | REQ_SEC_0034 | ||
| SSR-CYBER-0064 | CYBER | Design constraint | QM | Low | Review | After the initial vulnerability report, the ECA supplier shall provide additional information about the identified vulnerability within TBD. | N-CYBER-015 | REQ_SEC_0035 | 'Adequate time' has no stated value; the follow-up timeframe is to be agreed with the vehicle manufacturer. | |
| SSR-CYBER-0065 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall include in the vulnerability information the affected hardware or software component versions, the nature of the vulnerability, the description of the affected cybersecurity goal, the technical conditions to exploit the vulnerability, the impact of the exploitation, and the means to remove the vulnerability. | N-CYBER-015 | CR-CYBER-0029 | ||
| SSR-CYBER-0066 | CYBER | Design constraint | QM | Medium | Review | The ECA supplier shall obtain the vehicle manufacturer's approval of the incident response process. | N-CYBER-016 | REQ_SEC_0044 | ||
| SSR-CYBER-0067 | CYBER | Design constraint | QM | Low | Review | When a cybersecurity incident occurs, the ECA supplier shall follow the incident response process. | N-CYBER-016 | REQ_SEC_0045 | ||
| SSR-CYBER-0068 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall maintain the incident response process for the entire product lifetime. | N-CYBER-016 | REQ_SEC_0046 | ||
| SSR-CYBER-0069 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall manage the cybersecurity risk in coordination with the vehicle manufacturer using the incident response process. | N-CYBER-016 | REQ_SEC_0032 | ||
| SSR-CYBER-0070 | CYBER | Design constraint | QM | Low | Review | The ECA supplier shall consider each identified vulnerability in each current development project and in each project under field monitoring. | N-CYBER-016 | REQ_SEC_0037 | ||
| SSR-VAL-0005 | VAL | Design constraint | QM | Low | Review | The ECA supplier shall include in the report the information needed to identify the affected vehicles or products. | N-VAL-002 | CR-VAL-0003 | ||
| SSR-VAL-0006 | VAL | Design constraint | QM | Low | Review | The ECA shall report its unique individual identification number. | N-VAL-002 | 6.9 | ||
| SSR-VAL-0007 | split | VAL | Design constraint | QM | Low | Review | The ECA shall store its accumulated operational hours. | N-VAL-002 | 6.19.1 | |
| SSR-VAL-0007-2 | split | VAL | Design constraint | QM | Low | Review | The ECA shall report its accumulated operational hours. | N-VAL-002 | 6.19.1 | |
| SSR-VAL-0008 | VAL | Design constraint | QM | Low | Review | The ECA shall report its accumulated lifetime travel length. | N-VAL-002 | 6.19.2 | ||
| SSR-VAL-0009 | split | VAL | Design constraint | QM | Low | Review | The ECA shall support validation of the reported ESD. | N-VAL-002 | 6.23 | The acronym 'ESD' is not expanded in the source; its exact meaning is undefined in the provided text. |
| SSR-VAL-0009-2 | split | VAL | Design constraint | QM | Low | Review | The ECA shall support invalidation of the reported ESD. | N-VAL-002 | 6.23 | |
| SSR-VAL-0010 | split | VAL | Design constraint | QM | Low | Review | The ECA supplier shall support the PCB during the process. | N-VAL-002 | CR-VAL-0013 | 'The process' is not identified in the extracted text (conformal coating / PCB handling per doc 3299216_1, p.36). |
| SSR-VAL-0010-2 | split | VAL | Design constraint | QM | Low | Review | The ECA supplier shall prevent the PCB from bending in any direction during the process. | N-VAL-002 | CR-VAL-0013 | |
| SSR-VAL-0011 | needs clarification | VAL | Design constraint | QM | Low | Review | The conformal coating process and materials shall comply with the latest version of IPC/EIA J-STD-001. | N-VAL-003 | CR-VAL-0014 | CLARIFY: The source text is truncated after 'with applicable standards as e.g.' - which additional standards apply to the conformal coating process and materials, and to which specific revision of IPC/EIA J-STD-001 shall compliance be pinned?; Additional applicable standards are truncated in the source ('with applicable standards as e.g.' is cut off).; 'Latest version' is an open, time-varying reference; the specific IPC/EIA J-STD-001 revision is unspecified (R8). |
| SSR-VAL-0012 | VAL | Design constraint | QM | Low | Review | If an error condition occurs during the programming process, the ECA shall remain re-programmable. | N-VAL-003 | CR-VAL-0015 | ||
| SSR-VAL-0013 | VAL | Design constraint | QM | Low | Review | The ECA supplier shall obtain the vehicle manufacturer's review and acceptance of the proposal for each dataLocator. | N-VAL-003 | CR-VAL-0016 | ||
| SSR-VAL-0014 | split | VAL | Design constraint | QM | Low | Review | While a mechanic is working on the vehicle, the driveline shall report Not Ready. | N-VAL-003 | CR-VAL-0017 | |
| SSR-VAL-0014-2 | split | VAL | Design constraint | QM | Low | Review | While a mechanic is working on the vehicle, the driveline shall place the vehicle in the PropulsionNotReady state. | N-VAL-003 | CR-VAL-0017 | |
| SSR-VAL-0015 | VAL | Design constraint | QM | Medium | Review | The ECA supplier shall obtain the vehicle manufacturer's approval of the reporting methods, including the stipulated reporting time. | N-VAL-004 | CR-VAL-0004 | The reporting time value is unspecified ('reasonable'); it is to be stipulated and agreed with the vehicle manufacturer. | |
| SSR-SYS-0242 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall maintain a method for monitoring the available vulnerability databases for vulnerabilities that can affect the delivered product. | N-SYS-043 | REQ_SEC_0036 | ||
| SSR-HW-0026 | HW | Design constraint | QM | Low | Test | The ECA shall protect each secret specified by the vehicle manufacturer throughout the ECA lifecycle. | N-HW-006 | REQ_SEC_0050 | ||
| SSR-CYBER-0071 | split | CYBER | Design constraint | QM | Low | Review | The ECA shall identify security-related events. | N-CYBER-017 | REQ_SEC_0051 | |
| SSR-CYBER-0071-2 | split | CYBER | Design constraint | QM | Low | Review | The ECA shall log the identified security-related events. | N-CYBER-017 | REQ_SEC_0051 | |
| SSR-CYBER-0072 | CYBER | Design constraint | QM | High | Review | The ECA supplier shall analyse the risks of each individual hardware component, software component, mechanical component, and other technology used in the product, independently of the scope of ISO 26262. | N-CYBER-017 | CR-CYBER-0035 | ||
| SSR-SYS-0243 | split | SYS | Design constraint | QM | High | Test | The ECA shall be a common unit across each drivetrain. | N-SYS-044 | CR-SYS-0019 | |
| SSR-SYS-0243-2 | split | SYS | Design constraint | QM | High | Test | The ECA shall be compatible with each driveline setup. | N-SYS-044 | CR-SYS-0019 | |
| SSR-SYS-0244 | SYS | Functional | QM | Low | Test | The ECA shall be electrically driven. | N-SYS-045 | 2.1 | ||
| SSR-SYS-0245 | SYS | Functional | QM | Medium | Test | The ECA shall incorporate its own internal ECU for manoeuvring and error handling. | N-SYS-045 | 2.3 | ||
| SSR-SYS-0246 | SYS | Functional | QM | Low | Test | The ECA shall reach the extreme pushrod positions A and B, measured at the center of the pushrod end. | N-SYS-045 | 4.3 | The dimensional values for positions A and B are defined in Figure 3 (Pushrod positions), which is not available in the provided text. | |
| SSR-SYS-0247 | SYS | Functional | QM | Low | Test | When the ECA is powered up with the PP in the utmost forward position, the ECA shall move the AP to its utmost reversed position. | N-SYS-045 | 4.21 | ||
| SSR-SYS-0248 | split | SYS | Functional | QM | Low | Test | The ECA shall apply a preload force to the release bearing. | N-SYS-045 | 4.23 | |
| SSR-SYS-0248-2 | split | SYS | Functional | QM | Low | Test | While the clutch is in any position, the ECA shall maintain the preload force measured at the push rod between 150 N and 250 N. | N-SYS-045 | 4.23 | |
| SSR-SYS-0249 | split | SYS | Functional | QM | Medium | Test | When clutch disengagement is requested, the ECA shall disengage the clutch within 180 ms. | N-SYS-045 | CR-SYS-0033 | Disengagement position accuracy is stated as 'according to' a requirement whose reference is blank in the source; accuracy target is TBD. |
| SSR-SYS-0249-2 | split | SYS | Functional | QM | Medium | Test | During clutch disengagement, the ECA shall limit the push rod speed to a maximum of 125 mm/s. | N-SYS-045 | CR-SYS-0033 | |
| SSR-SYS-0250 | split | SYS | Functional | QM | Low | Test | When clutch engagement is requested, the ECA shall engage the clutch within 180 ms. | N-SYS-046 | CR-SYS-0035 | |
| SSR-SYS-0250-2 | split | SYS | Functional | QM | Low | Test | During clutch engagement, the ECA shall limit the push rod speed to a maximum of 125 mm/s. | N-SYS-046 | CR-SYS-0035 | |
| SSR-SYS-0250-3 | split | SYS | Functional | QM | Low | Test | The ECA shall engage the clutch with the position accuracy specified in requirement 5.10. | N-SYS-046 | CR-SYS-0035 | |
| SSR-SYS-0251 | SYS | Functional | QM | Low | Test | The ECA shall include a displacement sensor that measures the movement of the push rod. | N-SYS-046 | 5.5 | ||
| SSR-SYS-0252 | split | SYS | Functional | QM | Low | Test | The ECA shall determine the push rod position with an accuracy of +/-1.6 mm. | N-SYS-046 | 5.6 | |
| SSR-SYS-0252-2 | split | SYS | Functional | QM | Low | Test | The ECA shall determine the push rod position with a resolution of 0.0125 mm. | N-SYS-046 | 5.6 | |
| SSR-SYS-0252-3 | split | SYS | Functional | QM | Low | Test | The ECA shall determine the push rod position with a repeatability of +/-0.1 mm. | N-SYS-046 | 5.6 | |
| SSR-SYS-0252-4 | split | SYS | Functional | QM | Low | Test | The ECA shall determine the push rod position over a range of 85 mm. | N-SYS-046 | 5.6 | |
| SSR-SYS-0253 | SYS | Functional | QM | Low | Test | The ECA shall achieve a maximum push-rod speed of at least 125 mm/s. | N-SYS-046 | CR-SYS-0040 | ||
| SSR-SYS-0254 | SYS | Functional | QM | Low | Test | The ECA shall move the push rod at the highest speed that exceeds neither its maximum achievable speed nor the maximum requested speed. | N-SYS-046 | CR-SYS-0041 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0255 | SYS | Functional | QM | Low | Test | The ECA supplier shall perform the release frequency test at the highest operating temperature and at the maximum clutch force. | N-SYS-046 | CR-SYS-0048 | Highest operating temperature value is a blank cross-reference in the source (see ...); value is TBD. | |
| SSR-SYS-0256 | SYS | Functional | QM | Low | Test | While the maximum allowed speed signal is received on CAN, the ECA shall limit the push rod speed to that maximum allowed speed. | N-SYS-047 | 6.4 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0257 | SYS | Functional | QM | Low | Test | When Test Mode is requested, the ECA shall perform tests to detect latent faults. | N-SYS-047 | CR-SYS-0059 | ||
| SSR-SYS-0258 | SYS | Functional | QM | Low | Test | While a maximum allowed speed limit is defined, the ECA shall limit the push rod speed to that limit. | N-SYS-047 | CR-SYS-0061 | Source uses 'this value' and 'this limit' with no antecedent in this item; assumed to be the maximum allowed speed limit as in req 6.4; exact source and value are TBD. | |
| SSR-SYS-0259 | SYS | Functional | QM | Low | Test | While the ECA is in the debug or test control state, the ECA shall send the control-state value 0xC. | N-SYS-047 | 6.14.8 | ||
| SSR-SYS-0260 | SYS | Functional | QM | Low | Test | While the ECA is performing a motor brake simulation, the ECA shall send the control-state value 0xD. | N-SYS-047 | 6.14.9 | ||
| SSR-SYS-0261 | split | SYS | Functional | QM | Low | Review | The ECA shall report the current for each phase of the actuator. | N-SYS-047 | 6.17 | 'The filter time shall equal the update frequency' mixes a time and a frequency; the intended relationship (filter window equal to the update period versus equal to the update rate) is unclear and needs confirmation (TBD). |
| SSR-SYS-0261-2 | split | SYS | Functional | QM | Low | Review | The ECA shall calculate each reported phase current using a moving-mean filter. | N-SYS-047 | 6.17 | |
| SSR-SYS-0261-3 | split | SYS | Functional | QM | Low | Review | The ECA shall set the moving-mean filter time equal to the update frequency. | N-SYS-047 | 6.17 | |
| SSR-SYS-0262 | needs clarification | SYS | Functional | QM | Low | Test | Where the CVS41 voltage limits apply, the ECA shall maintain the ECU and communication function while the supply voltage is below TBD. | N-SYS-048 | 7.18 | CLARIFY: For SSR-SYS-0262, what supply-voltage value may the CVS41 limits go below, and what exact behaviour is required of the ECU and communication function while the voltage is in that lower range? (Clutch actuation is covered by req 5.13.); The voltage value that CVS41 limits may go below is not given (TBD).; The required behaviour of the ECU and communication function in that voltage range is not stated (TBD). |
| SSR-SYS-0263 | split | SYS | Functional | QM | Low | Test | When the wake-up line transitions to the high state during a normal start-up, the ECA shall communicate on the CAN line within 250 ms. | N-SYS-048 | CR-SYS-0088 | The abnormal-start-up readiness limit is stated only as 'as soon as possible after necessary movements' with no quantified value (TBD). |
| SSR-SYS-0263-2 | split | SYS | Functional | QM | Low | Test | When the wake-up line transitions to the high state during a normal start-up, the ECA shall be ready to open the clutch within 350 ms. | N-SYS-048 | CR-SYS-0088 | |
| SSR-SYS-0263-3 | split | SYS | Functional | QM | Low | Test | When the wake-up line transitions to the high state during an abnormal start-up, the ECA shall be ready to open the clutch within TBD ms after completing the necessary movements. | N-SYS-048 | CR-SYS-0088 | |
| SSR-SYS-0264 | split | SYS | Functional | QM | Low | Test | When the ECA has completed movement and reset, the ECA shall communicate on the CAN line within 250 ms. | N-SYS-048 | CR-SYS-0089 | The third clause (ready to open clutch within 3 s when wake-up coincides with U30) uses 'should' in the source, so it may be a goal rather than a hard requirement; confirmation needed. |
| SSR-SYS-0264-2 | split | SYS | Functional | QM | Low | Test | When the ECA has completed movement and reset, the ECA shall be ready to open the clutch within 400 ms. | N-SYS-048 | CR-SYS-0089 | |
| SSR-SYS-0264-3 | split | SYS | Functional | QM | Low | Test | When the wake-up line goes high simultaneously with the U30 signal, the ECA shall be ready to open the clutch within 3 s. | N-SYS-048 | CR-SYS-0089 | |
| SSR-SYS-0265 | split | SYS | Functional | QM | Low | Test | While in the ready-to-open-clutch state, the ECA shall keep the actuator position between FCCP and FCCP minus 3 mm. | N-SYS-048 | CR-SYS-0090 | |
| SSR-SYS-0265-2 | split | SYS | Functional | QM | Low | Test | While in the ready-to-open-clutch state, the ECA shall be able to move directly to the disengaged clutch position when disengagement is requested. | N-SYS-048 | CR-SYS-0090 | |
| SSR-SYS-0266 | SYS | Functional | QM | Low | Test | When a clutch-disengagement signal is received, the ECA shall actuate the disengagement request independently of the CAN request. | N-SYS-048 | CR-SYS-0092 | ||
| SSR-SYS-0267 | SYS | Functional | QM | Low | Review | The ECA shall withstand 6 500 000 actuations when subjected to the test cycle described in Appendix B. | N-SYS-048 | 8.3 | ||
| SSR-SYS-0268 | split | SYS | Functional | QM | Low | Review | While the ECA is jammed and holding the clutch open, the ECA shall allow the clutch force to be removed by following an instruction documented on the ECA drawing. | N-SYS-049 | 8.9 | |
| SSR-SYS-0268-2 | split | SYS | Functional | QM | Low | Review | The ECA supplier shall document the clutch-force-removal instruction on the ECA drawing. | N-SYS-049 | 8.9 | |
| SSR-SYS-0269 | SYS | Functional | QM | Low | Test | The ECA supplier shall run six consecutive ECA units past 6 500 000 actuations and continue each unit to its end of life. | N-SYS-049 | CR-SYS-0117 | ||
| SSR-SYS-0270 | SYS | Functional | QM | Low | Test | Each of three consecutive ECA units shall run past 6 500 000 actuations at Scania and continue to its end of life. | N-SYS-049 | CR-SYS-0118 | ||
| SSR-SYS-0271 | SYS | Functional | QM | Low | Test | Between the two movements, the ECA shall remain in the fully disengaged position. | N-SYS-049 | CR-SYS-0152 | ||
| SSR-SYS-0272 | SYS | Functional | QM | Low | Test | After complete engagement, the ECA shall remain in the engaged position until the next disengagement is requested. | N-SYS-049 | CR-SYS-0153 | ||
| SSR-SYS-0273 | SYS | Functional | QM | Low | Test | The ECA shall check whether the software is compatible with the hardware version and with the other data structures. | N-SYS-049 | CR-SYS-0211 | ||
| SSR-SYS-0274 | SYS | Functional | QM | Low | Test | The ECA shall check whether the software is compatible with the hardware version and with the other data structures. | N-SYS-050 | CR-SYS-0275 | ||
| SSR-MECH-0002 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall mark each ECA unit in accordance with Scania STD19, using the wordmark and part-number variant defined for the involved Traton brand. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-2 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall select the marking variant based on the delivery agreement and the involved brand. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-3 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall apply marking method MA1 to each ECA unit. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-4 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall apply a marking height of 3 mm to each ECA unit. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-5 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall mark the manufacturing date on each ECA unit in the YYMMDD format. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-6 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall mark each ECA unit with a unique serial number. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-7 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall mark each ECA unit with a Data Matrix Code that contains the part number and the serial number in accordance with Scania STD4562. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-8 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall position the marking so that it is concealed when the ECA unit is mounted on a gearbox. | N-MECH-002 | 2.6 | |
| SSR-MECH-0002-9 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall deliver each ECA unit to the required Traton brand production in a pallet position where the marking is visible. | N-MECH-002 | 2.6 | |
| SSR-MECH-0003 | MECH | Design constraint | QM | Low | Inspection | While the ECA is mounted on a gearbox, the ECA shall keep the marking concealed. | N-MECH-002 | CR-MECH-0004 | ||
| SSR-MECH-0004 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall mark the rubber cover defined in requirement 4.16 in accordance with Scania STD19, using Tentik wordmark variant W and the 9-digit part number in the format 12 345 6789. | N-MECH-002 | 2.7 | |
| SSR-MECH-0004-2 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall apply marking method CAS to the rubber cover. | N-MECH-002 | 2.7 | |
| SSR-MECH-0004-3 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall apply a marking height of 2 mm to 6 mm to the rubber cover. | N-MECH-002 | 2.7 | |
| SSR-MECH-0004-4 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall apply date dial CVM to the rubber cover. | N-MECH-002 | 2.7 | |
| SSR-MECH-0004-5 | split | MECH | Design constraint | QM | Low | Inspection | As an alternative design, the ECA supplier shall apply date dial CXM or an equivalent combination of a date dial and a date field to the rubber cover. | N-MECH-002 | 2.7 | |
| SSR-MECH-0004-6 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall position the rubber-cover marking so that it is concealed when the ECA is mounted on a gearbox. | N-MECH-002 | 2.7 | |
| SSR-MECH-0005 | MECH | Design constraint | QM | Low | Inspection | The total stroke of the ECA shall be 85 mm. | N-MECH-002 | 4.2 | ||
| SSR-MECH-0006 | split | MECH | Design constraint | QM | Low | Inspection | When the ECA is assembled, the ECA shall prevent an object larger than Ø0,2 mm from being inserted between the ECA and the gearbox flange into the space behind the ECA. | N-MECH-002 | 4.6 | |
| SSR-MECH-0006-2 | split | MECH | Design constraint | QM | Low | Inspection | The rubber grommet at the lower part of the flange is permitted to have the same interface as the surrounding aluminium flange. | N-MECH-002 | 4.6 | |
| SSR-MECH-0007 | MECH | Design constraint | QM | Low | Inspection | The ECA shall be adapted for two 10 mm guide pins. | N-MECH-002 | 4.9 | ||
| SSR-MECH-0008 | split | MECH | Design constraint | QM | Low | Inspection | The guide pin holes in the ECA shall have a diameter of 10.1 ±0.05 mm and a depth of at least 12 mm, with the depth measured from the centre of the oval hole in the Gearbox/ECA flange. | N-MECH-003 | 4.10 | |
| SSR-MECH-0008-2 | split | MECH | Design constraint | QM | Low | Inspection | The guide pin holes shall limit the guide pin protrusion from the gearbox housing to a maximum of 14 mm, measured from the centre of the oval hole in the Gearbox/ECA flange. | N-MECH-003 | 4.10 | |
| SSR-MECH-0009 | split | MECH | Design constraint | QM | Low | DT | The ECA shall be capable of being held by the guide pins alone while exposed to the maximum clutch load for up to 50 load occasions. | N-MECH-003 | 4.11 | Maximum clutch load value is referenced as req. 4.22 and is not restated here. |
| SSR-MECH-0009-2 | split | MECH | Design constraint | QM | Low | DT | Surface indents in the contacts are permitted where the structural integrity remains unaffected. | N-MECH-003 | 4.11 | |
| SSR-MECH-0010 | MECH | Design constraint | QM | Low | Inspection | The push rod end that contacts the clutch lever shall be a Ø15,93±0,07 mm steel sphere. | N-MECH-003 | 4.12 | ||
| SSR-MECH-0011 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall provide support for a clutch snap-in tool on the surface marked in Figure 4, withstanding a maximum force of 1 kN. | N-MECH-003 | 4.16 | |
| SSR-MECH-0011-2 | split | MECH | Design constraint | QM | Low | Inspection | Surface indents are permitted where they do not affect other requirements or the structural integrity of the ECA. | N-MECH-003 | 4.16 | |
| SSR-MECH-0012 | MECH | Design constraint | QM | Low | Inspection | The guide pin holes shall limit the guide pin protrusion to a maximum of 14 mm from the gearbox housing. | N-MECH-003 | CR-MECH-0021 | ||
| SSR-MECH-0013 | MECH | Design constraint | QM | Low | Inspection | When the cover is assembled, the ECA shall prevent an object larger than Ø0,2 mm from being inserted into the gearbox housing between the cover and the ECA. | N-MECH-003 | 4.18 | ||
| SSR-MECH-0014 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall provide a loop or similar feature where the cable can be fixated with a cable tie. | N-MECH-004 | 4.19 | |
| SSR-MECH-0014-2 | split | MECH | Design constraint | QM | Low | Inspection | The loop or the Scania-assembled bracket shall be located within ±20 mm of the centre of the cable section between the connector and the last cable fixation point on the gearbox. | N-MECH-004 | 4.19 | |
| SSR-MECH-0014-3 | split | MECH | Design constraint | QM | Low | Inspection | The ECA may provide an M8 screw thread and a rotation stop for a sheet metal bracket in accordance with Figure 4 - ISO view of 3D envelope. | N-MECH-004 | 4.19 | |
| SSR-MECH-0015 | MECH | Design constraint | QM | Low | Inspection | While no power is connected to the ECA, the ECA shall allow its push rod to be moved by hand with a force of at most 300 N, independent of the lever position. | N-MECH-004 | 4.25 | ||
| SSR-MECH-0016 | split | MECH | Design constraint | QM | Low | DT | For each stroke that the ECA performs, the ECA shall adjust to the current wear of the clutch. | N-MECH-004 | 5.7 | |
| SSR-MECH-0016-2 | split | MECH | Design constraint | QM | Low | DT | When a relative stroke is requested from the fully closed clutch position, the ECA shall achieve the step accuracy defined in requirement 5.10. | N-MECH-004 | 5.7 | |
| SSR-MECH-0017 | MECH | Design constraint | QM | Medium | Inspection | After a clutch engagement, the ECA shall update the FCCP to 90% of the step within 0,2 s per mm that the FCCP changed during the stroke. | N-MECH-004 | CR-MECH-0031 | ||
| SSR-MECH-0018 | split | MECH | Design constraint | QM | Medium | Inspection | For each marking variant, the ECA marking shall use marking method MA1. | N-MECH-005 | CR-MECH-0003 | |
| SSR-MECH-0018-2 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA marking shall have a marking height of 3 mm. | N-MECH-005 | CR-MECH-0003 | |
| SSR-MECH-0018-3 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA marking shall use the date format YYMMDD. | N-MECH-005 | CR-MECH-0003 | |
| SSR-MECH-0018-4 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA marking shall include a unique serial number. | N-MECH-005 | CR-MECH-0003 | |
| SSR-MECH-0018-5 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA marking shall include a DMC according to Scania STD 4562 that contains the part number and serial number information. | N-MECH-005 | CR-MECH-0003 | |
| SSR-MECH-0019 | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall deliver each ECA unit to the required Traton brand's production positioned in the pallet so that the marking is visible. | N-MECH-005 | CR-MECH-0005 | ||
| SSR-MECH-0020 | MECH | Design constraint | QM | Low | Inspection | The ECA shall be designed to support remanufacturing and refurbishment, allowing larger electronic assemblies and components to be replaced. | N-MECH-005 | 2.8 | Remanufacturing and refurbishment details are to be agreed with Traton (TBD). | |
| SSR-MECH-0021 | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall mark the ECA rubber cover in accordance with Scania STD19, reference 14.17, using the Tentik wordmark variant W, a 9-digit part number in the format 12 345 6789, the CAS marking method, and a marking height between 2 mm and 6 mm. | N-MECH-005 | CR-MECH-0008 | ||
| SSR-MECH-0022 | split | MECH | Design constraint | QM | Low | Inspection | When the ECA is assembled, the ECA shall provide a gap of 3.5 mm towards surface B, with a profile tolerance of ±1 mm to the nominal dimensions. | N-MECH-005 | 4.7 | |
| SSR-MECH-0022-2 | split | MECH | Design constraint | QM | Low | Inspection | The surface roughness of the ECA surface opposite to surface B shall be equal to or finer than Ra 3.2 µm. | N-MECH-005 | 4.7 | |
| SSR-MECH-0023 | MECH | Design constraint | QM | Low | Inspection | The ECA shall be adapted for 6 M8 flange screws described by Scania STD4435. | N-MECH-005 | 4.8 | ||
| SSR-MECH-0024 | MECH | Design constraint | QM | Low | Inspection | The ECA shall maintain clearance from the geometry defined in the 3D envelope 11_RFQ2030.stp, except at locations where interference fits or functional contacts are required. | N-MECH-006 | CR-MECH-0013 | ||
| SSR-MECH-0025 | MECH | Design constraint | QM | Low | Inspection | The ECA shall provide space for external tools according to the cylinders defined in the attached 3D envelope. | N-MECH-006 | 4.14 | ||
| SSR-MECH-0026 | MECH | Design constraint | QM | Low | Inspection | The ECA shall have a window through which the snap-in tool space volume shown in Figure 6 can pass. | N-MECH-006 | 4.15 | ||
| SSR-MECH-0027 | split | MECH | Design constraint | QM | Low | Inspection | When connected, the ECA shall position the connector for communication and power as indicated in Figure 4 - ISO view of 3D envelope. | N-MECH-006 | 4.20 | Actual length and positioning tolerances of the communication and power connector are TBD, to be agreed with Traton during the design phase. |
| SSR-MECH-0027-2 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall agree the actual length and positioning tolerances of the communication and power connector with Traton during the design phase. | N-MECH-006 | 4.20 | |
| SSR-MECH-0028 | split | MECH | Design constraint | QM | Low | Inspection | When a new position is requested and the stroke is too short to reach the requested speed, the ECA shall complete the stroke in minimum time with dynamics compliant with requirement 5.2 and this section. | N-MECH-006 | CR-MECH-0032 | A dynamics reference preceding '5.2' is blank in the source; only requirement 5.2 and 'this section' are named. |
| SSR-MECH-0028-2 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall limit the position overshoot to a maximum of 0,2 mm. | N-MECH-006 | CR-MECH-0032 | |
| SSR-MECH-0029 | MECH | Design constraint | QM | Low | Inspection | The ECA housing shall be DC-isolated from the ground. | N-MECH-006 | CR-MECH-0034 | ||
| SSR-MECH-0030 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall fulfil the requirements stated in Scania STD3868. | N-MECH-007 | 9.1 | |
| SSR-MECH-0030-2 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall comply with CVS55 reference 14.32, the Scania STD4158 Black list of prohibited chemical substances, and the Scania STD4159 Grey list of chemical substances with limited use. | N-MECH-007 | 9.1 | |
| SSR-MECH-0030-3 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall provide a material declaration in accordance with CVS 83 using the Scania IMDS reporting standard. | N-MECH-007 | 9.1 | |
| SSR-MECH-0030-4 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall mark each part of the housing according to its material content. | N-MECH-007 | 9.1 | |
| SSR-MECH-0030-5 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall be lead free. | N-MECH-007 | 9.1 | |
| SSR-MECH-0031 | MECH | Design constraint | QM | Low | Inspection | Each part of the housing shall be marked according to its material content. | N-MECH-007 | CR-MECH-0036 | ||
| SSR-MECH-0032 | split | MECH | Design constraint | QM | Low | Inspection | The ECA supplier shall verify the ECA using test procedure I and test procedure II. | N-MECH-007 | 10.4 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) |
| SSR-MECH-0032-2 | split | MECH | Design constraint | QM | Low | Inspection | Test procedure I shall be a comprehensive test that verifies each functional requirement and that is performed before and after exposure. | N-MECH-007 | 10.4 | |
| SSR-MECH-0032-3 | split | MECH | Design constraint | QM | Low | Inspection | Test procedure I shall contain at least a full stroke to evaluate speed, a staircase to evaluate accuracy, and a power loss to evaluate safety, in accordance with Figure 17 - Test procedure I. | N-MECH-007 | 10.4 | |
| SSR-MECH-0032-4 | split | MECH | Design constraint | QM | Low | Inspection | Test procedure II shall be a reduced function test that verifies the fundamental requirements and that can be performed during exposure. | N-MECH-007 | 10.4 | |
| SSR-MECH-0032-5 | split | MECH | Design constraint | QM | Low | Inspection | Test procedure II shall be performed either as a test cycle according to Appendix B at a frequency of 10 strokes per minute to 30 strokes per minute, or as a release frequency test according to requirement 5.12. | N-MECH-007 | 10.4 | |
| SSR-MECH-0033 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall include a full-stroke test to evaluate speed in Test procedure I. | N-MECH-007 | CR-MECH-0038 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) |
| SSR-MECH-0033-2 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall include a staircase test to evaluate accuracy in Test procedure I. | N-MECH-007 | CR-MECH-0038 | |
| SSR-MECH-0033-3 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall include a power-loss test to evaluate safety in Test procedure I. | N-MECH-007 | CR-MECH-0038 | |
| SSR-MECH-0033-4 | split | MECH | Design constraint | QM | Medium | Inspection | The ECA supplier shall define Test procedure II as a reduced function test that verifies the fundamental requirements. | N-MECH-007 | CR-MECH-0038 | |
| SSR-MECH-0034 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall fulfil IP54 without mounted connectors. | N-MECH-007 | 10.5.16 | |
| SSR-MECH-0034-2 | split | MECH | Design constraint | QM | Low | Inspection | The ECA shall fulfil ingress protection classes IP6K6K, IP6K7, and IP6K9K. | N-MECH-007 | 10.5.16 | |
| SSR-MECH-0035 | MECH | Design constraint | QM | Low | Inspection | Where the RoutineIdentifier is invoked, the ECA shall verify the authenticity of the received file package. | N-MECH-007 | REQ_UDS_0169 | Cross-reference is truncated ('See CVS123 and ...'); the second reference is missing. | |
| SSR-SYS-0275 | SYS | Design constraint | QM | Low | Test | The ECA supplier shall invite Traton to participate in the electrical and mechanical design reviews. | N-SYS-051 | CR-SYS-0024 | ||
| SSR-SYS-0276 | SYS | Design constraint | QM | Low | Test | The ECA shall prevent a shoot-through internal short circuit in each H-bridge. | N-SYS-051 | 7.1 | ||
| SSR-HW-0027 | HW | Design constraint | QM | Low | Test | Where the PP is fully calculated from the AP-sensor, the ECA shall apply no offset to the PP. | N-HW-007 | CR-HW-0007 | 'This offset' refers to a PP-to-AP offset defined earlier in the source and is not restated here. | |
| SSR-CYBER-0073 | split | CYBER | Design constraint | QM | Low | Test | When the push rod is pulled 50 times with a force of 300 N, the ECA shall retain the push rod. | N-CYBER-018 | 4.13 | |
| SSR-CYBER-0073-2 | split | CYBER | Design constraint | QM | Low | Test | Where the push rod has a loose fit in the ECA, the ECA shall allow the push rod to be reconnected by pushing it back by hand. | N-CYBER-018 | 4.13 | |
| SSR-CYBER-0074 | CYBER | Design constraint | QM | Medium | Test | The ECA supplier shall hash each software version released for integration test, production, or service market. | N-CYBER-018 | CR-CYBER-0036 | ||
| SSR-CYBER-0075 | split | CYBER | Design constraint | QM | Low | Test | Where a message-definition table marks a field as included in proofOfOwnershipServer, the ECA shall cover the field with the proofOfOwnershipServer signature. | N-CYBER-018 | CR-CYBER-0098 | |
| SSR-CYBER-0075-2 | split | CYBER | Design constraint | QM | Low | Test | The ECA shall include the proofOfOwnershipServer signature in the ECA response. | N-CYBER-018 | CR-CYBER-0098 | |
| SSR-CYBER-0076 | needs clarification | CYBER | Design constraint | QM | Low | Review | When the ECA receives an SDT request while the security sub-layer is busy, the ECA shall respond with TBD. | N-CYBER-018 | CR-CYBER-0148 | CLARIFY: The source sentence is truncated at 'shall respond with'. What exact response (for example a negative response code such as busyRepeatRequest 0x21, or a specific message) must the ECA return when an SDT request arrives while the security sub-layer is busy?; Response code or message the ECA must return when the security sub-layer is busy |
| SSR-SYS-0277 | needs clarification | SYS | Design constraint | QM | Low | Review | Where the mating component has a loose fit in the ECA, the ECA shall allow the mating component to be reconnected by pushing it back into position by hand. | N-SYS-052 | CR-SYS-0028 | CLARIFY: The customer statement uses 'it' with no antecedent. Which component has the loose fit and must be manually reconnectable (for example the pushrod, a pin, or an electrical connector)? |
| SSR-SYS-0278 | split | SYS | Design constraint | QM | Low | Test | The ECA shall comply with the CAN communication messages specified in PD2497100 to the full extent. | N-SYS-052 | 6.2 | Criteria for when additional checksums and message counters are required ('if needed' is unspecified in the source) |
| SSR-SYS-0278-2 | split | SYS | Design constraint | QM | Low | Test | The ECA shall be controlled by messages on the CAN bus and by the PWM signal specified in requirements 7.24 to 7.33. | N-SYS-052 | 6.2 | |
| SSR-SYS-0278-3 | split | SYS | Design constraint | QM | Low | Test | Where messages require additional integrity protection, the ECA shall complement the messages with checksums and message counters. | N-SYS-052 | 6.2 | |
| SSR-SYS-0279 | SYS | Design constraint | QM | Low | Test | The ECA shall keep CAN communication active. | N-SYS-052 | CR-SYS-0060 | Operating condition or state during which CAN communication must remain active ('still' implies a context not included in the extracted sentence) | |
| SSR-SYS-0280 | SYS | Design constraint | QM | Low | Test | The ECA shall identify the FCCP according to the restrictions defined by the self-adjustment signal. | N-SYS-052 | CR-SYS-0062 | ||
| SSR-SYS-0281 | SYS | Design constraint | QM | Low | Test | The ECA shall connect the wake-up signal to a digital input on the microprocessor. | N-SYS-052 | CR-SYS-0086 | ||
| SSR-SYS-0282 | split | SYS | Design constraint | QM | Low | Test | The ECA CAN front end shall be designed to comply with TB1905 reference 14.3. | N-SYS-052 | 7.34 | |
| SSR-SYS-0282-2 | split | SYS | Design constraint | QM | Low | Test | Each watchdog circuit in the ECA shall operate independently of the CAN bus. | N-SYS-052 | 7.34 | |
| SSR-SYS-0283 | SYS | Design constraint | QM | Low | Test | The ECA shall provide a CAN controller and a CAN transceiver that are CAN FD ready. | N-SYS-053 | 7.35 | ||
| SSR-SYS-0284 | SYS | Design constraint | QM | Low | Test | Each ECA watchdog circuit shall leave the CAN bus unaffected. | N-SYS-053 | CR-SYS-0095 | ||
| SSR-SYS-0285 | SYS | Design constraint | QM | Low | Test | The ECA CAN front end shall comply with TB1905. | N-SYS-053 | CR-SYS-0096 | ||
| SSR-SYS-0286 | split | SYS | Design constraint | QM | Low | Test | The ECA PCB layout shall always include the CAN circuit section. | N-SYS-053 | 7.39 | |
| SSR-SYS-0286-2 | split | SYS | Design constraint | QM | Low | Test | The ECA supplier shall allow the CAN-related components in the CAN circuit section to be changed or removed. | N-SYS-053 | 7.39 | |
| SSR-SYS-0287 | split | SYS | Design constraint | QM | Low | Test | The ECA shall provide a footprint for connecting the CAN shield to system ground 31_ECA through a resistor and a capacitor in series. | N-SYS-053 | 7.40 | |
| SSR-SYS-0287-2 | split | SYS | Design constraint | QM | Low | Test | By default, the ECA shall leave the resistor and the capacitor unpopulated. | N-SYS-053 | 7.40 | |
| SSR-SYS-0287-3 | split | SYS | Design constraint | QM | Low | Test | The ECA CAN front end shall be designed to comply with TB1905 reference 14.3. | N-SYS-053 | 7.40 | |
| SSR-SYS-0288 | SYS | Design constraint | QM | Low | Test | The ECA CAN front end shall comply with TB1905. | N-SYS-053 | CR-SYS-0100 | ||
| SSR-SYS-0289 | SYS | Design constraint | QM | Low | Test | The ECA PCB layout and component placement shall accommodate the application of conformal coating. | N-SYS-054 | CR-SYS-0105 | ||
| SSR-SYS-0290 | SYS | Design constraint | QM | Low | Test | The ECA shall maintain CAN communication. | N-SYS-054 | CR-SYS-0126 | Event or condition during which CAN communication must be unaffected (not included in the extracted sentence) | |
| SSR-SYS-0291 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall perform life-time testing of the ECA consisting of 6,500,000 repetitions of the test cycle described in 'I - Test cycle'. | N-SYS-054 | CR-SYS-0151 | ||
| SSR-SYS-0292 | SYS | Design constraint | QM | Low | Review | Where the ECA is programmed stand-alone at the vehicle manufacturer over DoCAN, the ECA shall support a 1 Mbit/s transfer speed. | N-SYS-054 | CR-SYS-0184 | ||
| SSR-SYS-0293 | SYS | Design constraint | QM | Low | Test | The ECA shall support the parameter EMP message according to CVS33. | N-SYS-054 | CR-SYS-0217 | ||
| SSR-SYS-0294 | split | SYS | Design constraint | QM | Low | Test | The ECA shall use the start address as an offset in the software module. | N-SYS-054 | CR-SYS-0221 | |
| SSR-SYS-0294-2 | split | SYS | Design constraint | QM | Low | Test | The ECA shall use the length to determine which areas of the software module are verified, decrypted, or both. | N-SYS-054 | CR-SYS-0221 | |
| SSR-SYS-0295 | SYS | Design constraint | QM | Low | Test | If the parameter suppressPosRespMsgIndicationBit is true in a functionally addressed request message, the ECA shall preserve each ongoing physically addressed service. | N-SYS-055 | REQ_UDS_0081 | ||
| SSR-SYS-0296 | needs clarification | SYS | Design constraint | QM | Low | Review | The ECA shall allow access rights to be added to or removed from a client or tester independently of the roles assigned to the client or tester. | N-SYS-055 | CR-SYS-0300 | CLARIFY: The source is an explanatory benefit statement ('It can also be useful if you want to...'), not a requirement. Should the ECA support adding or removing individual access rights for a client or tester independently of assigned roles, and if so, what is the exact required behavior? |
| SSR-SYS-0297 | SYS | Design constraint | QM | Low | Test | When evaluating each DID, the ECA shall parse both the pattern-rules and the DID-rules. | N-SYS-055 | CR-SYS-0303 | ||
| SSR-SYS-0298 | SYS | Design constraint | QM | Low | Test | The ECA shall format the response as a valid SDT positive response according to ISO 14299-1:2020. | N-SYS-055 | CR-SYS-0365 | Triggering condition for the positive response (for example upon successful SDT request verification) is not included in the extracted sentence | |
| SSR-SYS-0299 | split | SYS | Design constraint | QM | Low | Test | When the ECA receives an SDT request, the ECA shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PREQARC. | N-SYS-055 | CR-SYS-0368 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) |
| SSR-SYS-0299-2 | split | SYS | Design constraint | QM | Low | Test | When the SDT request is otherwise verified, the ECA shall update PREQARC to the value of the ANTIREPLAYCNT protocol element. | N-SYS-055 | CR-SYS-0368 | |
| SSR-SYS-0300 | split | SYS | Design constraint | QM | Low | Test | When the client receives an SDT response, the client shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PRESARC. | N-SYS-055 | CR-SYS-0370 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) |
| SSR-SYS-0300-2 | split | SYS | Design constraint | QM | Low | Test | When the SDT response is otherwise verified, the client shall update PRESARC to the value of the ANTIREPLAYCNT protocol element. | N-SYS-055 | CR-SYS-0370 | |
| SSR-SYS-0301 | split | SYS | Design constraint | QM | Low | Test | When the ECA injects C into or extracts C from an SDT message, the ECA shall map the first octet of C to INTMSGREQID. | N-SYS-056 | CR-SYS-0376 | |
| SSR-SYS-0301-2 | split | SYS | Design constraint | QM | Low | Test | When the ECA injects C into or extracts C from an SDT message, the ECA shall map the remaining octets of C to SRVSPECPARAM. | N-SYS-056 | CR-SYS-0376 | |
| SSR-MECH-0036 | split | MECH | Design constraint | QM | Low | DT | The ECA shall equip the hole with a cover that can be assembled and disassembled at least 50 times without tools. | N-MECH-008 | 4.17 | |
| SSR-MECH-0036-2 | split | MECH | Design constraint | QM | Low | DT | Where an interference fit is chosen for the cover, the maximum force to assemble or disassemble the cover shall be 50 N at room temperature. | N-MECH-008 | 4.17 | |
| SSR-MECH-0036-3 | split | MECH | Design constraint | QM | Low | DT | The cover shall remain intact and maintain its tightness after the vibration testing defined in requirement 10.5. | N-MECH-008 | 4.17 | |
| SSR-MECH-0037 | MECH | Design constraint | QM | Low | DT | Where an interference fit is chosen, the force to assemble or disassemble the ECA at room temperature shall be at most 50 N. | N-MECH-008 | CR-MECH-0026 | ||
| SSR-SYS-0302 | SYS | Functional | QM | Low | Test | The ECA supplier shall agree the actual length and positioning tolerances with the vehicle manufacturer during the design phase. | N-SYS-057 | CR-SYS-0030 | ||
| SSR-SYS-0303 | SYS | Functional | QM | Low | Test | The ECA shall achieve the maximum disengage time defined in Figure 7 when measured against the maximum disengage force defined in Appendix A. | N-SYS-057 | CR-SYS-0034 | Maximum disengage time value (Figure 7) not provided in the source; Maximum disengage force value (Appendix A) not provided in the source | |
| SSR-SYS-0304 | SYS | Functional | QM | Low | Test | The ECA shall achieve the maximum engage time defined in Figure 8 when measured against the minimum engage force defined in Appendix A. | N-SYS-057 | CR-SYS-0036 | Maximum engage time value (Figure 8) not provided in the source; Minimum engage force value (Appendix A) not provided in the source | |
| SSR-SYS-0305 | SYS | Functional | QM | Low | Test | The ECA shall keep the stationary position error relative to the real FCCP, defined as the sum of the self-adjustment error and the step response error, within +/-0.15 mm. | N-SYS-057 | 5.9 | ||
| SSR-SYS-0306 | SYS | Functional | QM | Low | Test | When a new requested position value is sent, the ECA shall achieve the requested speed, limited to 125 mm/s, within 50 ms. | N-SYS-057 | CR-SYS-0042 | ||
| SSR-SYS-0307 | SYS | Functional | QM | Low | Test | The ECA shall maintain the requested speed until 2 mm from the target position. | N-SYS-057 | CR-SYS-0043 | ||
| SSR-SYS-0308 | SYS | Functional | QM | Low | Test | When 100 ms have elapsed after reaching 2 mm from the target position, the ECA shall keep the position error within +/-0.1 mm. | N-SYS-058 | CR-SYS-0044 | ||
| SSR-SYS-0309 | SYS | Functional | QM | Low | Test | The ECA supplier shall verify the step accuracy defined in requirement 5.10 using the step response test cycle in accordance with Figure 10 - Step response test cycle. | N-SYS-058 | 5.11 | ||
| SSR-SYS-0310 | SYS | Functional | QM | Low | Test | While the supply voltage is between 16 V and loss of power, the ECA shall either hold the current position or move toward the requested position, with no timing constraint. | N-SYS-058 | CR-SYS-0049 | ||
| SSR-SYS-0311 | SYS | Functional | QM | Low | Test | While self-adjustment is disabled, indicated by signal value 0x3, the ECA shall freeze the fully closed clutch position value at the last identified position and use it for Relative Position Control. | N-SYS-058 | 6.5.2 | ||
| SSR-SYS-0312 | SYS | Functional | QM | Low | Test | While self-adjustment is disabled, the ECA shall freeze the fully closed clutch position value at the last identified position and use it for Relative Position Control. | N-SYS-058 | CR-SYS-0064 | The triggering condition (self-adjustment disabled) is inferred from the section 6.5 self-adjustment context and consistency with SSR-SYS-0311; to be confirmed with Traton. | |
| SSR-SYS-0313 | SYS | Functional | QM | Low | Test | The ECA supplier shall analyze the quality and position of the wire bonding. | N-SYS-058 | CR-SYS-0102 | ||
| SSR-SYS-0314 | SYS | Functional | QM | Low | Test | The ECA supplier shall declare the melting point and the composition of the soldering material. | N-SYS-059 | CR-SYS-0103 | ||
| SSR-SYS-0315 | SYS | Functional | QM | Medium | Test | While the clutch is fully engaged, the active control mode is position control or torque control, and there is no active request to extract the pushrod, the ECA shall keep the applied force within the preload force limits. | N-SYS-060 | CR-SYS-0032 | Preload force limit values and the requirement reference are cut off in the source ('defined in req.') | |
| SSR-SYS-0316 | SYS | Functional | QM | Highest | Test | When the ECA is actuating Torque Control, the ECA shall report 0x4 as its active state via CAN. | N-SYS-060 | 6.14.4 | ||
| SSR-SYS-0317 | split | SYS | Functional | QM | Medium | Review | The ECA shall calculate the actuator motor torque. | N-SYS-060 | 6.16 | |
| SSR-SYS-0317-2 | split | SYS | Functional | QM | Medium | Review | The ECA shall report the actuator motor torque. | N-SYS-060 | 6.16 | |
| SSR-MECH-0038 | MECH | Design constraint | QM | Low | Inspection | The ECA shall report the absolute position of the current actuator stroke. | N-MECH-009 | 5.3 | ||
| SSR-MECH-0039 | MECH | Design constraint | QM | Low | Inspection | The ECA shall report the fully closed clutch position as an absolute position of the actuator stroke relative to the absolute zero position. | N-MECH-009 | 5.4 | ||
| SSR-CYBER-0077 | CYBER | Design constraint | QM | Low | Test | While subjected to the maximum disengage force defined in Appendix A and the highest operating temperature defined in requirement 8.1, the ECA shall keep the clutch disengaged continuously for at least 120 minutes while retaining its function. | N-CYBER-019 | 5.14 | ||
| SSR-SYS-0318 | SYS | Functional | QM | Low | Test | The ECA shall achieve the maximum disengage time when measured against the maximum disengage force defined in Appendix A at the highest operating temperature. | N-SYS-061 | CR-SYS-0051 | Maximum disengage time limit value not provided; Highest operating temperature value and its requirement reference are cut off ('see req.'); Maximum disengage force value (Appendix A) not provided | |
| SSR-SW-0001 | split | SW | Functional | QM | Low | Test | When Absolute Position Control is requested using control mode value 0x01, the ECA shall move to the actuator position defined by the requested position. | N-SW-001 | 6.3.1 | The scope of the 'specific cases' requiring Traton approval is interpreted as cases where the ECA controls movement to protect against hardware damage; to be confirmed. |
| SSR-SW-0001-2 | split | SW | Functional | QM | Low | Test | The ECA may control its movement to protect the ECA and the clutch from hardware damage. | N-SW-001 | 6.3.1 | |
| SSR-SW-0001-3 | split | SW | Functional | QM | Low | Test | The ECA supplier shall agree with Traton each specific case in which the ECA controls its movement to protect the ECA or the clutch from hardware damage. | N-SW-001 | 6.3.1 | |
| SSR-SW-0002 | split | SW | Functional | QM | Low | Review | When Relative Position Control is requested, the ECA shall move to an offset from the FCCP that corresponds to the Requested Position. | N-SW-001 | 6.3.2 | |
| SSR-SW-0002-2 | split | SW | Functional | QM | Low | Review | While in Relative Position Control, the ECA shall accept a Requested Position up to the full release travel of 22.4 mm. | N-SW-001 | 6.3.2 | |
| SSR-SW-0002-3 | split | SW | Functional | QM | Low | Review | When the Requested Position is 0 in Relative Position Control, the ECA shall keep the actuator position at or below the FCCP. | N-SW-001 | 6.3.2 | |
| SSR-SYS-0319 | SYS | Functional | QM | Low | Test | When Absolute Position Control is requested, the ECA shall move to the actuator position defined by the Requested Position. | N-SYS-062 | CR-SYS-0055 | ||
| SSR-SYS-0320 | SYS | Functional | QM | Low | Test | When the ECA is actuating Absolute Position Control, the ECA shall report 0x1 as its active state via CAN. | N-SYS-062 | 6.14.2 | ||
| SSR-SYS-0321 | SYS | Functional | QM | Low | Test | When the ECA is actuating Relative Position Control, the ECA shall report 0x2 as its active state via CAN. | N-SYS-062 | 6.14.3 | ||
| SSR-SW-0003 | SW | Functional | QM | High | Test | When Torque Control is requested, the ECA shall actuate the requested motor torque. | N-SW-002 | CR-SW-0003 | ||
| SSR-SW-0004 | SW | Functional | QM | Low | Test | When Test Mode is sent, the ECA shall behave, with respect to actuator control, as if the power supply were cut. | N-SW-003 | CR-SW-0004 | ||
| SSR-SW-0005 | SW | Functional | QM | Low | Review | While the ECA is in boot mode, the ECA shall report 0x00 as the active state. | N-SW-003 | CR-SW-0007 | ||
| SSR-VAL-0016 | VAL | Design constraint | QM | Low | Review | The ECA shall report a complete software version number in the range 0 to 64255. | N-VAL-005 | 6.11 | ||
| SSR-VAL-0017 | VAL | Design constraint | QM | Low | Review | The ECA shall report a complete hardware version number in the range 0 to 64255. | N-VAL-005 | 6.12 | ||
| SSR-SYS-0322 | split | SYS | Functional | QM | Low | Test | When low accuracy mode is requested using accuracy mode value 0x0, the ECA shall limit the push rod position error to a maximum of ±0.5 mm. | N-SYS-063 | CR-SYS-0066 | |
| SSR-SYS-0322-2 | split | SYS | Functional | QM | Low | Test | The ECA shall fulfil the accuracy defined in requirement 5.10. | N-SYS-063 | CR-SYS-0066 | |
| SSR-SW-0006 | SW | Functional | QM | Medium | Test | The ECA shall send, via CAN, a bit field containing the errors that are present. | N-SW-004 | CR-SW-0005 | The CAN bit-field layout (bit-to-error mapping) and the content referenced by the truncated 'Additionally, see,' cross-reference are not provided in the source. | |
| SSR-SW-0007 | SW | Functional | QM | Low | Test | The ECA shall execute the new software only after the new software has been verified using routine 0xFF01. | N-SW-004 | CR-SW-0039 | ||
| SSR-SW-0008 | SW | Functional | QM | Medium | Test | If executing an ECUReset would compromise vehicle safety, the ECA shall reject the ECUReset request. | N-SW-004 | REQ_UDS_0062 | The criteria that define when an ECUReset 'would compromise vehicle safety' are not specified in the source. | |
| SSR-SW-0009 | SW | Functional | QM | Low | Test | After sending a positive response message to an ECUReset request, the ECA shall be available for ECU identification within 1 second. | N-SW-004 | REQ_UDS_0065 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SW-0010 | SW | Functional | QM | Low | Test | The ECA shall send the ECUReset positive response message after completing the preceding reset tasks and before performing the actual resetType. | N-SW-004 | CR-SW-0090 | 'The preceding reset tasks' references tasks listed earlier in the source ('the server tasks above') that are not included in this item. | |
| SSR-SW-0011 | SW | Functional | QM | Low | Test | When an application-layer service 0x29 request is received inside a service 0x84 SDT-protected message, the ECA shall reject the service 0x29 request. | N-SW-004 | CR-SW-0203 | ||
| SSR-SW-0012 | SW | Functional | QM | Low | Test | The ECA shall reject an SDT message that uses service 0x84 as its application-layer service encapsulated inside another service 0x84. | N-SW-005 | CR-SW-0233 | ||
| SSR-SW-0013 | SW | Functional | QM | Low | Test | While the ECA is performing its initiation routine and is unavailable for control, the ECA shall report 0xA as its active state via CAN. | N-SW-006 | 6.14.6 | ||
| SSR-SW-0014 | SW | Functional | QM | Low | Test | When pre-programming the application module, the ECA supplier shall set ECU and software identifiers 0xF187 and 0xF188 to the product-specific values defined by the vehicle manufacturer. | N-SW-006 | CR-SW-0021 | The specific product-specific values for 0xF187 and 0xF188 are defined by the vehicle manufacturer and are not provided in this item. | |
| SSR-SW-0015 | SW | Functional | QM | Low | Test | Where the application module is delivered without supplier pre-programming, the ECA shall set the ECU and software identifiers 0xF187 and 0xF188 to the default values defined in CVS124. | N-SW-006 | CR-SW-0022 | ||
| SSR-SW-0016 | split | SW | Functional | QM | Low | Test | If the ECA hardware or software is inconsistent at startup, the ECA shall start and execute the boot loader. | N-SW-006 | CR-SW-0030 | |
| SSR-SW-0016-2 | split | SW | Functional | QM | Low | Test | If the ECA hardware or software is inconsistent at startup, the ECA shall reset the data identifiers 0xF181, 0xF187, 0xF188, and 0xF1A1 to their default values. | N-SW-006 | CR-SW-0030 | |
| SSR-SW-0017 | SW | Functional | QM | Low | Test | If an error occurs during decryption of data, the ECA shall return NRC 0x10. | N-SW-006 | CR-SW-0043 | ||
| SSR-SW-0018 | SW | Functional | QM | Low | Test | The ECA shall support service 0x84 in accordance with CVS32. | N-SW-006 | CR-SW-0046 | ||
| SSR-SW-0019 | SW | Functional | QM | Low | Test | The ECA shall execute the specified RoutineIdentifier independently of the programming sequence. | N-SW-007 | CR-SW-0054 | The specific RoutineIdentifier value ('This RoutineIdentifier') is defined in preceding source context not included in this item. | |
| SSR-SW-0020 | SW | Functional | QM | Low | Test | Where the client requests execution of the routineIdentifier as a standalone procedure, the ECA shall perform a software consistency check. | N-SW-007 | CR-SW-0055 | ||
| SSR-SW-0021 | SW | Functional | QM | Low | Test | The client shall send the ECA routineStatus and routineResult response to the backend. | N-SW-007 | CR-SW-0059 | ||
| SSR-SW-0022 | SW | Functional | QM | Low | Test | The ECA shall support the routine negative response in accordance with CVS33. | N-SW-007 | CR-SW-0061 | ||
| SSR-SW-0023 | needs clarification | SW | Functional | QM | Low | Test | The ECA implementation shall comply with ISO 14229-1. | N-SW-007 | REQ_UDS_0001 | CLARIFY: The source ends mid-sentence: '...shall be compliant with ISO 14229-1 with the'. What follows 'with the' (for example specific exceptions, additional constraints, or a referenced release/deviation list)?; Source sentence is truncated after 'with the', so any qualification to the ISO 14229-1 compliance is unknown. |
| SSR-SW-0024 | SW | Functional | QM | Low | Test | The ECA shall implement each project-specific DID within the system-supplier-specific data identifier range defined in ISO 14229-1. | N-SW-007 | REQ_UDS_0052 | ||
| SSR-SW-0025 | SW | Functional | QM | Low | Test | The ECA shall support the SPRMIB for the services specified in ISO 14229-1. | N-SW-008 | REQ_UDS_0055 | ||
| SSR-SW-0026 | SW | Functional | QM | Low | Test | The ECA shall limit the supported negative response codes from ISO 14229-1 Annex A.1 to those explicitly specified by this specification or its normative references. | N-SW-008 | REQ_UDS_0056 | ||
| SSR-SW-0027 | SW | Functional | QM | Low | Test | If communication is still switched on, the ECA shall respond with NRC 0x22. | N-SW-008 | CR-SW-0080 | ||
| SSR-SW-0028 | SW | Functional | QM | Low | Test | Where the ECA is involved in engine start, the ECA shall postpone processing of CommunicationControl service requests until 2 seconds after terminal 15 becomes active. | N-SW-008 | REQ_UDS_0075 | ||
| SSR-SW-0029 | split | SW | Functional | QM | Low | Test | If a request is received before the 2-second period has elapsed, the ECA shall respond with either NRC 0x78 or NRC 0x22. | N-SW-008 | CR-SW-0093 | 'This time' is interpreted as the 2-second period referenced in the source (REQ_UDS_0075 / preceding context). |
| SSR-SW-0029-2 | split | SW | Functional | QM | Low | Test | Where the ECA responds with NRC 0x78, the ECA shall process the request and send a final response after the 2-second period has elapsed. | N-SW-008 | CR-SW-0093 | |
| SSR-SW-0030 | SW | Functional | QM | Low | Test | The ECA shall support writing data records with service 0x2E WriteDataByIdentifier in any order. | N-SW-008 | REQ_UDS_0089 | ||
| SSR-SW-0031 | needs clarification | SW | Functional | QM | Low | Test | If the specified action is necessary, the ECA shall integrate the action implicitly into the ECU Reset service 0x11 subfunction 0x02. | N-SW-009 | CR-SW-0103 | CLARIFY: What is 'this action' that must be integrated implicitly into ECU Reset (0x11) subfunction 0x02, and under what condition is it 'necessary'? The referent is defined in preceding source context not included here.; 'This action' references content in the preceding source context not included in this item. |
| SSR-SW-0032 | needs clarification | SW | Functional | QM | Low | Test | Where the ECA is one of the specified ECUs, the ECA shall set each of the specified bytes to the default value 0xFF. | N-SW-009 | CR-SW-0119 | CLARIFY: Which ECUs ('these ECUs') and which bytes ('these bytes') does this apply to? Both reference preceding source context not included in this item.; The set of applicable ECUs and the specific bytes reference preceding source context not included in this item. |
| SSR-SW-0033 | SW | Functional | QM | Low | Test | The ECA shall provide negative response codes in accordance with ISO 14229-1. | N-SW-009 | REQ_UDS_0282 | ||
| SSR-SW-0034 | SW | Functional | QM | Low | Test | The ECA shall conform to the data identifier ranges specified in ISO 14229-1. | N-SW-009 | REQ_UDS_0102 | ||
| SSR-SW-0035 | SW | Functional | QM | Low | Test | The ECA shall provide the negative response format and codes in accordance with ISO 14229-1. | N-SW-009 | REQ_UDS_0294 | ||
| SSR-SW-0036 | SW | Functional | QM | Low | Test | The ECA shall support negative response codes in accordance with ISO 14229-1. | N-SW-009 | REQ_UDS_0146 | ||
| SSR-SW-0037 | SW | Functional | QM | Low | Review | If each precondition is satisfied, the ECA shall omit the routineStatus byte from the response. | N-SW-010 | REQ_UDS_0156 | ||
| SSR-SW-0038 | SW | Functional | QM | Low | Test | The ECA shall send a response to RoutineIdentifier 0x2401 Software Installation without requiring further input from the client. | N-SW-010 | REQ_UDS_0171 | ||
| SSR-SW-0039 | SW | Functional | QM | Low | Test | If authenticity verification fails, the ECA shall send the positive response with AuthenticityVerificationStatus bits 7-6 set to 0x02 and SoftwareInstallationStatus bits 7-6 set to 0x02. | N-SW-010 | REQ_UDS_0172 | ||
| SSR-SW-0040 | SW | Functional | QM | Low | Test | If no authenticity verification takes place as part of the RoutineIdentifier, the ECA shall set AuthenticityVerificationStatus bits 7-6 to 0x01. | N-SW-010 | REQ_UDS_0178 | ||
| SSR-SW-0041 | split | SW | Functional | QM | Low | Test | The ECA shall allow the client to start a consistency check of the ECA using the RoutineIdentifier. | N-SW-010 | CR-SW-0166 | The specific RoutineIdentifier value is defined in preceding source context not included here. |
| SSR-SW-0041-2 | split | SW | Functional | QM | Low | Test | The ECA should execute the RoutineIdentifier independently of the programming sequence. | N-SW-010 | CR-SW-0166 | |
| SSR-SW-0042 | SW | Functional | QM | Low | Test | The ECA shall set the default timestamp value to 0xFF in each byte. | N-SW-010 | REQ_UDS_0207 | Source phrase 'in each data' is ambiguous; interpreted as each byte of the timestamp field. | |
| SSR-SW-0043 | SW | Functional | QM | Low | Test | If the occurrence counter is set to 1, the ECA shall set the timestamp of the latest occurrence to 0xFF. | N-SW-011 | REQ_UDS_0211 | ||
| SSR-SW-0044 | SW | Functional | QM | Low | Test | If no source of vehicle distance information provides current data, the ECA shall set the distance information to 0xFF in each byte. | N-SW-011 | REQ_UDS_0214 | ||
| SSR-SW-0045 | SW | Functional | QM | Low | Test | If no source of operational hours information provides current data, the ECA shall set the operational hours information to 0xFF in each byte. | N-SW-011 | REQ_UDS_0219 | ||
| SSR-SW-0046 | SW | Functional | QM | Low | Test | Where the ECA is a Linux-based system still running in boot, the ECA should indicate via DID 0xF1AD that it is running in boot. | N-SW-011 | CR-SW-0182 | ||
| SSR-SW-0047 | SW | Functional | QM | Low | Test | The client shall use the value estimation for P2*Client given in ISO 14229-2. | N-SW-011 | REQ_UDS_0228 | ||
| SSR-SW-0048 | SW | Functional | QM | Low | Test | If an encapsulated service 0x29 request is detected, the ECA shall return the application-layer NRC 0x39 as a correctly formatted SDT positive response. | N-SW-011 | CR-SW-0204 | ||
| SSR-SW-0049 | needs clarification | SW | Functional | QM | Low | Test | The ECA shall respond with the application-layer NRC 0x39. | N-SW-012 | CR-SW-0234 | CLARIFY: The source is truncated after 'i.e.'. Under what condition shall the ECA respond with application-layer NRC 0x39, and what does the 'i.e.' clause specify (for example delivery as a correctly formatted SDT positive response for a service 0x84 message encapsulated inside another service 0x84, per CVS32/CR-SW-0233)?; Triggering condition for NRC 0x39 and the truncated 'i.e.' clarification are not provided in the source. |
| SSR-SW-0050 | SW | Functional | QM | Low | Test | The client shall populate the SIGLEN protocol element in the request with the value 0x0010. | N-SW-012 | CR-SW-0238 | ||
| SSR-SW-0051 | SW | Functional | QM | Low | Test | The ECA shall populate the SIGLEN protocol element with the value 0x0010. | N-SW-012 | CR-SW-0239 | Source states 'in the request' for the ECA (server); populating SIGLEN in the request rather than the response is atypical, so the message context (request vs response) needs confirmation. | |
| SSR-SW-0052 | SW | Functional | QM | Low | Test | The client shall populate the SIGLEN protocol element in the SDT request with the value 16. | N-SW-012 | CR-SW-0240 | ||
| SSR-SW-0053 | SW | Functional | QM | Low | Test | The ECA shall populate the SIGLEN protocol element in the SDT response with the value 16. | N-SW-012 | CR-SW-0241 | ||
| SSR-SW-0054 | SW | Functional | QM | Low | Test | When the ECA receives an SDT request that has an incorrect length or an invalid format, the ECA shall respond with an SDT negative response using NRC 0x13. | N-SW-012 | CR-SW-0245 | ||
| SSR-SW-0055 | SW | Functional | QM | Low | Test | When the ECA receives an SDT request, if ANTIREPLAYCNT is less than or equal to PREQARC, the ECA shall respond with an SDT negative response using NRC 0x3A. | N-SW-013 | CR-SW-0246 | ||
| SSR-SW-0056 | SW | Functional | QM | Low | Test | When the ECA receives an SDT request, if PRESARC is exhausted, the ECA shall respond with an SDT negative response using NRC 0x3A. | N-SW-013 | CR-SW-0247 | ||
| SSR-SW-0057 | SW | Functional | QM | Low | Test | When the ECA receives an SDT request, if verification or decryption of the request is unsuccessful, the ECA shall respond with an SDT negative response using NRC 0x3A. | N-SW-013 | CR-SW-0251 | ||
| SSR-SW-0058 | split | SW | Functional | QM | Low | Test | If the client determines that an SDT request has been lost in transit, or if the client receives an SDT negative response with NRC 0x21, the client shall repeat the request byte for byte. | N-SW-013 | CR-SW-0252 | |
| SSR-SW-0058-2 | split | SW | Functional | QM | Low | Test | While repeating the request, the client shall preserve its state variables. | N-SW-013 | CR-SW-0252 | |
| SSR-HW-0028 | HW | Design constraint | QM | Low | DT | The ECA shall report the current system temperature. | N-HW-008 | 6.15 | Reporting interface, resolution and accuracy for the temperature value are not specified in the source. | |
| SSR-HW-0029 | split | HW | Design constraint | QM | Low | Inspection | The ECA solder material shall be lead-free. | N-HW-008 | CR-HW-0021 | 'High-temperature solder type' is not quantified (no temperature class or standard cited). |
| SSR-HW-0029-2 | split | HW | Design constraint | QM | Low | Inspection | The ECA solder material shall be of a high-temperature solder type. | N-HW-008 | CR-HW-0021 | |
| SSR-HW-0030 | HW | Design constraint | QM | Low | Test | The ECA shall report the current input voltage. | N-HW-009 | 6.18 | Reporting interface, resolution and accuracy for the voltage value are not specified in the source. | |
| SSR-HW-0031 | split | HW | Design constraint | QM | Low | Inspection | The ECA shall provide geometric coding for each external electrical connector. | N-HW-009 | 7.5 | |
| SSR-HW-0031-2 | split | HW | Design constraint | QM | Low | Inspection | Where internal components are included in repair kits, the ECA shall provide geometric coding for each internal electrical connector. | N-HW-009 | 7.5 | |
| SSR-HW-0032 | HW | Design constraint | QM | Low | Inspection | Where internal components are included in a repair kit, the internal electrical connectors of the ECA shall also be geometrically coded. | N-HW-009 | CR-HW-0015 | ||
| SSR-HW-0033 | split | HW | Design constraint | QM | Low | Inspection | The ECA shall be free of tantalum capacitors. | N-HW-009 | CR-HW-0022 | |
| SSR-HW-0033-2 | split | HW | Design constraint | QM | Low | Inspection | The power supply circuits of the ECA shall be free of serial resistors. | N-HW-009 | CR-HW-0022 | |
| SSR-HW-0034 | HW | Design constraint | QM | Low | Test | The ECA shall remain re-programmable within the normal operating voltage range specified by [11] for 24V systems or by [12] for 12V systems. | N-HW-009 | CR-HW-0034 | Actual voltage-range limits are defined in referenced documents [11] (24V systems) and [12] (12V systems) and are not restated here. | |
| SSR-SW-0059 | split | SW | Functional | QM | Medium | Review | The ECA supplier shall address cybersecurity through a dedicated process that conforms to the applicable Traton cybersecurity workflow. | N-SW-014 | 6.21 | The customer states that additional standards or documents will be made available if applicable; these are not yet identified. |
| SSR-SW-0059-2 | split | SW | Functional | QM | Medium | Review | The ECA supplier shall comply with the mandatory Traton secure update specifications CVS31, CVS32, CVS123-2 and CVS154. | N-SW-014 | 6.21 | |
| SSR-SW-0059-3 | split | SW | Functional | QM | Medium | Review | The ECA supplier shall comply with the mandatory Traton secure diagnostics specifications CVS31, CVS32 and CVS151. | N-SW-014 | 6.21 | |
| SSR-SW-0059-4 | split | SW | Functional | QM | Medium | Review | The ECA supplier shall comply with the mandatory Traton Unified Diagnostic Services specification CVS124. | N-SW-014 | 6.21 | |
| SSR-SW-0059-5 | split | SW | Functional | QM | Medium | Review | Where applicable, the ECA supplier shall apply the supporting specifications CVS30, CVS33, CVS34, CVS121, CVS122, SecureBoot, Vehicle Baseline Requirements and ECU Baseline Requirements. | N-SW-014 | 6.21 | |
| SSR-SYS-0323 | SYS | Design constraint | QM | Low | Test | The ECA shall set the filter time equal to the update frequency. | N-SYS-064 | CR-SYS-0078 | The numeric value of the update frequency (and hence the filter time) is defined elsewhere and not stated here. | |
| SSR-SYS-0324 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall document the normal and worst-case performance values for the total time of the programming sequence comprising the programming steps prefixed P1Pro. | N-SYS-064 | CR-SYS-0170 | ||
| SSR-SYS-0325 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall deliver flash files that the vehicle manufacturer can use as delivered. | N-SYS-064 | CR-SYS-0175 | ||
| SSR-SYS-0326 | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall provide the flash files corresponding to each delivered ECU when the vehicle manufacturer requests them, whether or not the ECU is delivered with a pre-programmed application and application data. | N-SYS-064 | CR-SYS-0177 | ||
| SSR-SYS-0327 | SYS | Design constraint | QM | Low | Test | Before executing the TransferData service, the ECA shall determine whether the data received during the RequestDownload request must be decrypted before being written to non-volatile memory. | N-SYS-064 | CR-SYS-0182 | ||
| SSR-SYS-0328 | SYS | Design constraint | QM | Low | Review | The ECA shall update an individual module independently of the other modules. | N-SYS-064 | CR-SYS-0186 | ||
| SSR-SYS-0329 | SYS | Design constraint | QM | Low | Review | When programmed in the vehicle manufacturer's production facility, the ECA shall complete programming of the complete set of its modules within 90 seconds using the programming sequence covering phase #1 and phase #2. | N-SYS-065 | CR-SYS-0197 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0330 | SYS | Design constraint | QM | Low | Review | When programmed in the workshop, the ECA shall complete programming of the complete set of its modules within 10 minutes using the programming sequence covering phase #1 and phase #2. | N-SYS-065 | CR-SYS-0198 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SYS-0331 | SYS | Design constraint | QM | Low | Review | For each received RequestDownload request, the ECA shall determine whether a VerificationEntry match exists in the SDSC. | N-SYS-065 | CR-SYS-0200 | ||
| SSR-SYS-0332 | SYS | Design constraint | QM | Low | Test | The client shall provide the pre-calculated checksum as part of the data submitted with the TransferData service request. | N-SYS-065 | CR-SYS-0208 | ||
| SSR-SYS-0333 | SYS | Design constraint | QM | Low | Review | The ECA shall set PREQARC to the value received in the ANTIREPLAYCNT protocol element of the SDT request if and only if the ECA successfully verifies or decrypts that SDT request. | N-SYS-065 | CR-SYS-0393 | ||
| SSR-SYS-0334 | SYS | Design constraint | QM | Low | Review | The client shall set PRESARC to the value received in the ANTIREPLAYCNT protocol element of the SDT response if and only if the client successfully verifies or decrypts that SDT response. | N-SYS-065 | CR-SYS-0398 | ||
| SSR-SW-0060 | needs clarification | SW | Functional | QM | Low | Test | Where higher resolution is required to troubleshoot an individual fault occurrence, the ECA shall store the corresponding diagnostic parameters internally. | N-SW-015 | 6.24 | CLARIFY: Which specific diagnostic parameters (for example time-stamps and occurrence counters) must the ECA store internally, and is the ECA required to include these in the ESD fault notifications to the gearbox control unit, or are they generated solely by the TCU when setting DTCs?; The set of 'higher resolution' parameters the ECA must store is not enumerated (source uses 'etc.').; The criterion for when 'higher resolution is required' is not defined. |
| SSR-SW-0060-2 | split | SW | Functional | QM | Low | Test | The ECA shall restrict access to the internally stored diagnostic parameters to supplier-defined tools. | N-SW-015 | 6.24 | |
| SSR-SW-0061 | SW | Functional | QM | Low | Test | The ECA shall be programmable in accordance with this specification using tools other than supplier-specific tools, even when one or more DTCs are active or one or more functions are degraded. | N-SW-015 | CR-SW-0016 | ||
| SSR-SW-0062 | SW | Functional | QM | Low | Test | If the programming preconditions are unmet, the ECA shall reject a ControlDTCSetting service request that requests DTC setting type off by responding with NRC 0x22. | N-SW-015 | REQ_UDS_0343 | ||
| SSR-SW-0063 | split | SW | Functional | QM | High | Test | When the ControlDTCSetting service is executed, the ECA shall limit the effect of the service to the DTC setting. | N-SW-015 | REQ_UDS_0344 | |
| SSR-SW-0063-2 | split | SW | Functional | QM | High | Test | When the ControlDTCSetting service is executed, the ECA shall continue to run the diagnostic tests for safety and degradations as in normal operation. | N-SW-015 | REQ_UDS_0344 | |
| SSR-SW-0064 | SW | Functional | QM | Low | Test | The ECA shall define the groupOfDTC parameter in accordance with ISO 14229-1. | N-SW-015 | REQ_UDS_0262 | ||
| SSR-SW-0065 | SW | Functional | QM | Low | Review | The ECA shall format the ReportNumberOfDTCByStatusMask parameter in accordance with ISO 14229-1. | N-SW-015 | REQ_UDS_0266 | ||
| SSR-SW-0066 | SW | Functional | QM | Low | Test | The ECA shall format the DTCStatusMask parameter in accordance with ISO 14229-1. | N-SW-016 | REQ_UDS_0267 | ||
| SSR-SW-0067 | SW | Functional | QM | Low | Test | The ECA shall format the DTCSnapshotRecordNumber parameter in accordance with ISO 14229-1. | N-SW-016 | REQ_UDS_0268 | ||
| SSR-SW-0068 | SW | Functional | QM | Low | Test | The ECA shall format the DTCSeverityMaskRecord parameter in accordance with ISO 14229-1. | N-SW-016 | REQ_UDS_0270 | ||
| SSR-SW-0069 | SW | Functional | QM | Low | Test | The ECA shall format the DTCSeverityMask parameter in accordance with ISO 14229-1. | N-SW-016 | REQ_UDS_0271 | ||
| SSR-SW-0070 | SW | Functional | QM | Low | Test | The ECA shall format the DTCStatusAvailabilityMask response parameter in accordance with ISO 14229-1. | N-SW-016 | REQ_UDS_0273 | ||
| SSR-SW-0071 | SW | Functional | QM | Low | Test | The ECA shall format the DTCFormatIdentifier response parameter in accordance with ISO 14229-1. | N-SW-016 | REQ_UDS_0274 | ||
| SSR-SW-0072 | SW | Functional | QM | Low | Test | The ECA shall format the DTCCount response parameter in accordance with ISO 14229-1. | N-SW-017 | REQ_UDS_0275 | ||
| SSR-SW-0073 | SW | Functional | QM | Low | Test | The ECA shall format the DTCAndStatusRecord response parameter in accordance with ISO 14229-1. | N-SW-017 | REQ_UDS_0276 | ||
| SSR-SW-0074 | SW | Functional | QM | Low | Test | The ECA shall format the DTCRecord response parameter in accordance with ISO 14229-1. | N-SW-017 | REQ_UDS_0277 | ||
| SSR-SW-0075 | SW | Functional | QM | Low | Test | The ECA shall populate the latest captured DTC snapshot record, DTCSnapshotRecordNumber#2, with the same data type and format as DTCSnapshotRecord[]#1. | N-SW-017 | CR-SW-0117 | The source is a garbled table extract; the other field definitions (dataIdentifier range, DTCSnapshotRecordNumberOfIdentifiers#2 and the #65..#70 byte layout) are not reconstructable and may carry separate field-level requirements. | |
| SSR-SW-0076 | SW | Functional | QM | Low | Test | The ECA shall associate DTCSnapshotRecordNumber#1 with the first occurrence of the DTC and DTCSnapshotRecordNumber#2 with the latest occurrence of the DTC. | N-SW-017 | REQ_UDS_0304 | ||
| SSR-SW-0077 | needs clarification | SW | Functional | QM | Low | Test | The ECA shall report the total vehicle distance at the latest DTC activation in bytes #35..#38 as a 4-byte big-endian integer with a resolution of 5 m per bit. | N-SW-017 | CR-SW-0120 | CLARIFY: The source for CR-SW-0120 is a garbled table extract. Please confirm the byte #35..#38 field definition for total vehicle distance at the latest DTC activation (4-byte big-endian, 5 m/bit resolution, range 0 to 21 307 064 315 m) and confirm whether the 0xFFFFFFFF 'not used' default applies to the ECA or only to TRATON external engine and marine ECUs.; Source table is garbled; the exact range/resolution encoding needs confirmation.; Applicability of the 0xFFFFFFFF 'not used' default value to the ECA (versus TRATON external engine and marine ECUs) is unclear. |
| SSR-SW-0078 | SW | Functional | QM | Low | Test | The ECA shall set the DTCExtDataRecordNumber#4 byte to the value 0x14. | N-SW-018 | CR-SW-0121 | The garbled distance-encoding portion of the source (total vehicle distance, 5 m/bit) may contain a separate field requirement that is not reconstructable here. | |
| SSR-SW-0079 | SW | Functional | QM | Low | Test | The ECA shall format the DTCSeverityAvailabilityMask response parameter in accordance with ISO 14229-1. | N-SW-018 | REQ_UDS_0279 | ||
| SSR-SW-0080 | SW | Functional | QM | Low | Test | The ECA shall format the DTCAndSeverityRecord response parameter in accordance with ISO 14229-1. | N-SW-018 | REQ_UDS_0280 | ||
| SSR-SW-0081 | SW | Functional | QM | Low | Test | The ECA shall reset each DTC status bit using only standardized reset conditions. | N-SW-018 | REQ_UDS_0197 | ||
| SSR-SW-0082 | SW | Functional | QM | Low | Test | When DTC status bit 0 testFailed and bit 3 confirmedDTC both change from 0 to 1, the ECA shall increment the occurrence counter. | N-SW-018 | REQ_UDS_0203 | ||
| SSR-SW-0083 | needs clarification | SW | Functional | QM | Low | Test | When DTC status bit 0 testFailed changes from 0 to 1, the ECA shall increment the occurrence counter. | N-SW-018 | REQ_UDS_0204 | CLARIFY: The customer statement is truncated at a trailing comma. Which condition qualifies this increment (for example, must bit 3 confirmedDTC already be 1, mirroring REQ_UDS_0205)?; Trailing qualifying condition for the occurrence-counter increment on bit 0 testFailed is truncated in the source (REQ_UDS_0204). |
| SSR-SW-0084 | SW | Functional | QM | Low | Test | When DTC status bit 3 confirmedDTC changes from 0 to 1 while bit 0 testFailed is already 1, the ECA shall increment the occurrence counter. | N-SW-019 | REQ_UDS_0205 | ||
| SSR-SW-0085 | SW | Functional | QM | Low | Test | When DTC status bit 0 testFailed and bit 3 confirmedDTC both change from 0 to 1, the ECA shall update the latest occurrence. | N-SW-019 | REQ_UDS_0210 | ||
| SSR-SW-0086 | SW | Functional | QM | Low | Test | When DTC status bit 0 testFailed changes from 0 to 1 while bit 3 confirmedDTC is already 1, the ECA shall update the latest occurrence. | N-SW-019 | REQ_UDS_0210 | ||
| SSR-SW-0087 | SW | Functional | QM | Low | Test | When DTC status bit 0 testFailed and bit 3 confirmedDTC change from 0 to 1 for the first time, the ECA shall update the first occurrence. | N-SW-019 | REQ_UDS_0212 | ||
| SSR-SYS-0335 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall agree each logged or stored data item with Traton. | N-SYS-066 | 6.25 | ||
| SSR-SYS-0336 | split | SYS | Design constraint | QM | Low | Review | The ECA shall ventilate the air inside the electronics enclosure by means of a membrane. | N-SYS-066 | 7.45 | |
| SSR-SYS-0336-2 | split | SYS | Design constraint | QM | Low | Review | The ECA shall withstand the salt-spray environment in accordance with CVS40 §6.1.6 without clogging of the membrane. | N-SYS-066 | 7.45 | |
| SSR-SYS-0336-3 | split | SYS | Design constraint | QM | Low | Review | The ECA shall position the membrane so that it is protected against blunt force, falling dust, and dripping salt-water. | N-SYS-066 | 7.45 | |
| SSR-SYS-0336-4 | split | SYS | Design constraint | QM | Low | Review | The ECA shall prevent accumulation of water on top of the membrane and in the cavity of the membrane. | N-SYS-066 | 7.45 | |
| SSR-SYS-0337 | SYS | Design constraint | QM | Low | Test | The ECA shall withstand the salt-spray environment in accordance with CVS40 §6.1.6 without clogging of the membrane. | N-SYS-066 | CR-SYS-0109 | ||
| SSR-SYS-0338 | SYS | Design constraint | QM | Low | Test | The ECA shall verify the version against the Major and Minor version of the DSC logic supported by the ECA for compliance. | N-SYS-066 | CR-SYS-0321 | Identity of 'the version' being verified is not specified in the source.; 'DSC logic' is a customer term whose definition is not provided. | |
| SSR-HW-0035 | split | HW | Design constraint | QM | Low | Test | When storing data, the ECA shall prevent corruption of the stored data. | N-HW-010 | 6.26 | |
| SSR-HW-0035-2 | split | HW | Design constraint | QM | Low | Test | When data corruption occurs, the ECA shall handle the corruption while preserving the stored data and the ECA function, except for purely statistical data from the active operation cycle following an abnormal shutdown. | N-HW-010 | 6.26 | |
| SSR-HW-0036 | HW | Design constraint | QM | Low | Test | The ECA shall draw its power solely from the battery positive terminal 30 connection. | N-HW-010 | 7.12 | ||
| SSR-HW-0037 | HW | Design constraint | QM | Low | Test | Where gaps between memory areas must be excluded from the hash calculation, the ECA shall support the definition of the hash calculation as one or several address ranges. | N-HW-010 | CR-HW-0038 | ||
| SSR-SYS-0339 | split | SYS | Design constraint | QM | Low | Inspection | The ECA supplier shall deliver exactly one calibration set of the ECA to Traton. | N-SYS-067 | 6.27 | |
| SSR-SYS-0339-2 | split | SYS | Design constraint | QM | Low | Inspection | The ECA shall use a calibration that is independent of the ECA installation variants. | N-SYS-067 | 6.27 | |
| SSR-SYS-0340 | SYS | Design constraint | QM | Low | Test | If higher resolution is required for the supplier to troubleshoot an individual occurrence, the ECA shall store the parameters internally. | N-SYS-067 | CR-SYS-0081 | The specific parameters ('these parameters') and the resolution threshold implied by 'higher resolution' are not defined in the source. | |
| SSR-SYS-0341 | SYS | Design constraint | QM | Low | Test | The ECA shall permit access to internally stored parameters only through supplier-defined tools. | N-SYS-067 | CR-SYS-0082 | ||
| SSR-SYS-0342 | needs clarification | SYS | Design constraint | QM | Low | Test | Where a client implements programming support using alternative service parameter values or an alternative set of programming steps, the ECA shall support that programming sequence. | N-SYS-067 | CR-SYS-0157 | CLARIFY: The source is truncated at 'than' and describes client behaviour rather than an ECA obligation. What must the ECA support with respect to alternative client programming parameter values or steps, and against which baseline sequence is the alternative compared?; Source truncated at 'than'; baseline programming sequence and the required ECA behaviour are unknown. |
| SSR-SYS-0343 | SYS | Design constraint | QM | Low | Review | The ECA boot loader shall comply with each requirement in CVS124 that is not explicitly stated to apply to the application only. | N-SYS-067 | CR-SYS-0162 | ||
| SSR-SYS-0344 | SYS | Design constraint | QM | Low | Test | When the module is programmed, the ECA shall override the default parameter values persisted in the boot loader software module with the parameter values in the module. | N-SYS-067 | CR-SYS-0172 | Identity of 'this module' is taken from prior CVS123-2 context and is likely the boot parameter module; not explicitly stated in the source. | |
| SSR-SYS-0345 | SYS | Design constraint | QM | Low | Inspection | The ECA shall implement the default values for the EOL parameters in a dedicated application data module named the EOL parameters module. | N-SYS-068 | CR-SYS-0173 | ||
| SSR-SYS-0346 | SYS | Design constraint | QM | Low | Test | The ECA shall support the addressing modes, SPRMIB values, and other parameter values specified for each service in CVS124. | N-SYS-068 | CR-SYS-0181 | ||
| SSR-SYS-0347 | SYS | Design constraint | QM | Low | Test | When the boot manager starts and executes the application at startup, the ECA shall apply the parameter values persisted in the boot parameter module. | N-SYS-068 | CR-SYS-0191 | ||
| SSR-SYS-0348 | SYS | Design constraint | QM | Low | Test | When at startup the ECA executes the boot loader and a valid boot parameter module has been successfully programmed, the ECA shall read and apply the parameter values from the boot parameter module. | N-SYS-068 | CR-SYS-0192 | ||
| SSR-SYS-0349 | SYS | Design constraint | QM | Low | Test | When at startup the ECA executes the boot loader and no boot parameter module has been successfully programmed, the ECA shall apply the parameter values persisted in the boot loader module. | N-SYS-068 | CR-SYS-0193 | ||
| SSR-SYS-0350 | SYS | Design constraint | QM | Low | Review | The ECA shall reject the transferRequestParameterRecord parameter. | N-SYS-068 | CR-SYS-0203 | ||
| SSR-SYS-0351 | SYS | Design constraint | QM | Low | Review | The ECA shall reject the transferResponseParameterRecord parameter. | N-SYS-069 | CR-SYS-0204 | ||
| SSR-SYS-0352 | SYS | Design constraint | QM | Low | Review | The ECA shall support the Anti-replay Counter (ANTIREPLAYCNT) parameter in accordance with CVS32. | N-SYS-069 | CR-SYS-0206 | ||
| SSR-SYS-0353 | SYS | Design constraint | QM | Low | Test | The ECA shall reject the transferRequestParameterRecord parameter. | N-SYS-069 | REQ_UDS_0122 | ||
| SSR-SYS-0354 | SYS | Design constraint | QM | Low | Test | The ECA shall reject the transferRequestParameterRecord parameter. | N-SYS-069 | REQ_UDS_0124 | ||
| SSR-FUSA-0001 | split | FUSA | Functional | QM | High | Test | When a power off-on cycle occurs after a functional safety event, the ECA shall reset the ECA application. | N-FUSA-001 | 6.28 | Detailed handling of the reset after functional safety events is TBD pending agreement with Traton. |
| SSR-FUSA-0001-2 | split | FUSA | Functional | QM | High | Test | The ECA supplier shall agree the handling of functional safety events with Traton. | N-FUSA-001 | 6.28 | |
| SSR-FUSA-0002 | FUSA | Functional | QM | High | Review | The ECA supplier shall handle the ECA as part of a safety-critical system. | N-FUSA-001 | CR-FUSA-0003 | ||
| SSR-FUSA-0003 | FUSA | Functional | QM | High | Review | The ECA supplier shall develop and implement the ECA in accordance with the objectives and requirements of ISO 26262, Road vehicles - Functional Safety. | N-FUSA-001 | CR-FUSA-0004 | ||
| SSR-FUSA-0004 | FUSA | Functional | QM | High | Review | The ECA supplier shall apply the methods of ISO 26262 as a minimum for the safety analyses. | N-FUSA-001 | CR-FUSA-0005 | 'these analyses' is not explicitly scoped in the source; assumed to mean the ECA safety analyses. | |
| SSR-FUSA-0005 | FUSA | Functional | QM | Medium | Test | While the actuator is moving, the ECA shall execute a safe memory read and write sequence. | N-FUSA-002 | 7.4 | Acceptance criteria for a 'safe' memory read/write sequence are defined by the safety goals in PD3339794 (Ref 14.16) and are not restated here. | |
| SSR-MECH-0040 | MECH | Design constraint | QM | Low | Test | The ECA shall provide DC isolation between the system ground and the ECA housing. | N-MECH-010 | 7.13 | ||
| SSR-SW-0088 | split | SW | Design constraint | QM | Low | Test | The ECA shall implement the termination resistance using two 60 Ω resistors with 1% tolerance. | N-SW-020 | CR-SW-0010 | |
| SSR-SW-0088-2 | split | SW | Design constraint | QM | Low | Test | The ECA shall support the baud rates 250 kbit/s, 500 kbit/s, and 1000 kbit/s. | N-SW-020 | CR-SW-0010 | |
| SSR-SW-0088-3 | split | SW | Design constraint | QM | Low | Test | The ECA shall support flashing in production at 1000 kbit/s. | N-SW-020 | CR-SW-0010 | |
| SSR-SW-0089 | needs clarification | SW | Design constraint | QM | Low | Test | The ECA shall implement the TRATON Software Update Variant 2 (SUV2) sequence in accordance with CVS123-2. | N-SW-020 | CR-SW-0011 | CLARIFY: The source is the CVS123-2 foreword/boilerplate and contains no specific obligation. Which requirement of the SUV2 sequence in CVS123-2 should this SSR capture?; Source is document foreword/scope text; no specific ECA obligation is stated. |
| SSR-SW-0090 | SW | Design constraint | QM | Low | Test | Where the ECA does not support boot loader reprogramming, the ECA shall store the boot loader software in a protected area of the memory. | N-SW-020 | CR-SW-0014 | ||
| SSR-SW-0091 | SW | Design constraint | QM | Low | Test | When programming of a subset of modules causes the consistency check at the end of the programming sequence to fail, the ECA shall preserve the already-programmed modules. | N-SW-020 | CR-SW-0015 | ||
| SSR-SW-0092 | SW | Design constraint | QM | Medium | Review | The ECA supplier shall agree the solution for maintaining and reorganizing data before and after reprogramming of software modules with the vehicle manufacturer. | N-SW-020 | CR-SW-0018 | ||
| SSR-SW-0093 | needs clarification | SW | Design constraint | QM | Low | Test | Where the client strategy updates specified entities before a software update, the ECA shall support that update sequence. | N-SW-020 | CR-SW-0025 | CLARIFY: The source describes an optional client strategy, not a firm ECA obligation, and does not identify the 'certain entities'. Which entities must the ECA support updating prior to a software update, and is this behaviour mandatory?; 'certain entities' not specified; obligation stated as an optional client strategy ('may be a client strategy'). |
| SSR-SW-0094 | SW | Design constraint | QM | Low | Test | The ECA shall check the reprogrammed flag C3 to determine whether application initialization is required. | N-SW-021 | CR-SW-0028 | ||
| SSR-SW-0095 | SW | Design constraint | QM | Low | Test | After reprogramming, the ECA shall store the DIDs F1AB, F1AA, and F1A9. | N-SW-021 | CR-SW-0031 | ||
| SSR-SW-0096 | needs clarification | SW | Design constraint | QM | Low | Review | Where each ECA software module is pre-programmed at the supplier premises, the in-vehicle software reprogramming requirement does not apply. | N-SW-021 | CR-SW-0034 | CLARIFY: This is a scope-exclusion note referring to 'This'. Which requirement does 'This' exclude, and should the exclusion be captured as an attribute of that requirement rather than as a standalone SSR?; Referent of 'This' (the excluded requirement) is not identified in the source. |
| SSR-SW-0097 | SW | Design constraint | QM | Low | Test | While a bootloader update procedure is ongoing and the non-volatile memory area is hosting a bootloader copy, the ECA shall preserve that memory area until a valid bootloader has been flashed in the bootloader memory area. | N-SW-021 | CR-SW-0050 | ||
| SSR-SW-0098 | SW | Design constraint | QM | Low | Review | The ECA supplier shall specify the byte value of an erased data byte as an input to the hashing process. | N-SW-021 | CR-SW-0062 | ||
| SSR-SW-0099 | SW | Design constraint | QM | Low | Test | The ECA shall store the DID under the flash memory module in flash memory. | N-SW-021 | REQ_UDS_0005 | The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source. | |
| SSR-SW-0100 | SW | Design constraint | QM | Low | Test | The ECA shall store the DID under the dataset module in flash memory. | N-SW-022 | REQ_UDS_0232 | The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source. | |
| SSR-SW-0101 | SW | Design constraint | QM | Low | Test | The ECA shall store the DID under the dataset module in flash memory. | N-SW-022 | REQ_UDS_0233 | The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source. | |
| SSR-SW-0102 | SW | Design constraint | QM | Low | Test | The ECA shall store the DID under the flash memory module in flash memory. | N-SW-022 | REQ_UDS_0236 | The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source. | |
| SSR-SW-0103 | SW | Design constraint | QM | Low | Test | The ECA shall store the DID under the flash memory module in flash memory. | N-SW-022 | REQ_UDS_0238 | The specific DID ('This DID') is defined by the preceding requirement context and is not given in the source. | |
| SSR-SW-0104 | SW | Design constraint | QM | Low | Test | While performing flashing or parametrisation, the ECA should use the communication control service to inhibit in-vehicle systems. | N-SW-022 | CR-SW-0095 | The in-vehicle systems to be inhibited are not enumerated in the source (example given: engine start). | |
| SSR-SW-0105 | SW | Design constraint | QM | Low | Test | While a bootloader update procedure is ongoing and the non-volatile memory area is hosting a bootloader copy, the ECA shall preserve that memory area until a valid bootloader has been flashed in the bootloader memory area. | N-SW-022 | REQ_UDS_0159 | ||
| SSR-HW-0038 | HW | Design constraint | QM | Low | Review | The ECA shall maintain the memory functions at Class A. | N-HW-011 | CR-HW-0025 | The classification scheme defining 'Class A' is not identified in the source. | |
| SSR-HW-0039 | HW | Design constraint | QM | Low | Test | Where the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another memory area before erasing the boot loader memory. | N-HW-011 | CR-HW-0035 | ||
| SSR-HW-0040 | HW | Design constraint | QM | Low | Test | Where the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another non-volatile memory area before erasing the boot loader memory. | N-HW-011 | CR-HW-0036 | ||
| SSR-HW-0041 | HW | Design constraint | QM | Low | Test | The ECA shall interpret the range start field as the memory address offset from the dataLocator field. | N-HW-011 | CR-HW-0037 | ||
| SSR-HW-0042 | HW | Design constraint | QM | Low | Test | The ECA shall verify that the erased-only blocks covered by the memory range are erased. | N-HW-011 | CR-HW-0039 | ||
| SSR-HW-0043 | HW | Design constraint | QM | Low | Test | Where the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another memory area before erasing the boot loader memory. | N-HW-011 | CR-HW-0044 | ||
| SSR-HW-0044 | HW | Design constraint | QM | Low | Test | Where the current boot loader is to be retained across erasure of the boot loader memory, the ECA shall copy the current boot loader into another non-volatile memory area before erasing the boot loader memory. | N-HW-012 | CR-HW-0047 | ||
| SSR-HW-0045 | HW | Design constraint | QM | Low | Test | Where the ECA implements Automatic erase, the ECA shall perform memory erasing in parallel with the data transfer. | N-HW-012 | CR-HW-0048 | ||
| SSR-SYS-0355 | needs clarification | SYS | Design constraint | QM | Low | Demonstration | Where Traton requests support for the CVS46 section 5.4 vehicle radiated-immunity test, the ECA supplier shall provide the requested support. | N-SYS-070 | 10.7.34 | CLARIFY: What specific support (samples, test setup, on-site attendance, analysis, etc.) must the supplier provide for the CVS46 section 5.4 vehicle radiated-immunity test, and does the 'Y' in the source confirm supplier support is mandatory?; Scope and deliverables of the required supplier support are not defined in the source.; The trailing 'Y' token is assumed to indicate that supplier support is required. |
| SSR-SYS-0356 | split | SYS | Design constraint | QM | Low | Test | The ECA supplier shall use a function test rig to perform the function tests between the durability intervals. | N-SYS-070 | CR-SYS-0154 | The cycling-frequency unit for '15 per minute' and '30 per minute' is assumed to be cycles per minute; the customer text uses the notation '15/min' and '30/min' without stating the unit.; The 'intermediate load' value for run-to-failure mode is not quantified by the customer. |
| SSR-SYS-0356-2 | split | SYS | Design constraint | QM | Low | Test | At 6.25 million cycles, the ECA supplier shall perform a function test at -40°C and the release frequency test before placing the rigs into run-to-failure mode. | N-SYS-070 | CR-SYS-0154 | |
| SSR-SYS-0356-3 | split | SYS | Design constraint | QM | Low | Test | During run-to-failure mode, the ECA supplier shall cycle the ECA at intermediate load and at room temperature or 80°C until failure. | N-SYS-070 | CR-SYS-0154 | |
| SSR-SYS-0356-4 | split | SYS | Design constraint | QM | Low | Test | The ECA supplier shall start the temperature durability test at a cycling frequency of 15 per minute in order to assess whether 30 per minute is feasible. | N-SYS-070 | CR-SYS-0154 | |
| SSR-SYS-0356-5 | split | SYS | Design constraint | QM | Low | Test | The ECA supplier shall run one rig at room temperature at a cycling frequency of 15 per minute as a reference unit for cycle acceleration. | N-SYS-070 | CR-SYS-0154 | |
| SSR-SYS-0357 | SYS | Design constraint | QM | Low | Test | The ECA shall support programming of each application software module, each application data module, and any subset of those modules within a single, uninterrupted programming sequence. | N-SYS-070 | CR-SYS-0167 | ||
| SSR-SYS-0358 | SYS | Design constraint | QM | Low | Test | The ECA shall format the software identification string according to the pattern 'Appl: <Diag.family> <Diag.generation> Boot: <Diag.family> <Diag.generation>_BOOT'. | N-SYS-070 | CR-SYS-0244 | The specific field or DID that carries this identification string is not named in the source. | |
| SSR-SYS-0359 | SYS | Design constraint | QM | Low | Review | The ECA shall comply with the diagnostic state diagram and state definitions specified in the referenced UDS specification. | N-SYS-070 | REQ_UDS_0051 | The state diagram and state list are referenced but not included in the source (the statement is truncated at 'the following state'); obtain the exact diagram and states from REQ_UDS_0051. | |
| SSR-SYS-0360 | SYS | Design constraint | QM | Low | Test | The ECA shall represent the vehicle distance as a four-byte big-endian integer with a resolution of 5 metres per bit. | N-SYS-070 | REQ_UDS_0213 | ||
| SSR-SYS-0361 | SYS | Design constraint | QM | Low | Test | The ECA shall use big-endian byte order for the DID. | N-SYS-071 | CR-SYS-0298 | ||
| SSR-SW-0106 | SW | Functional | QM | High | Test | The ECA shall implement two or more diagnostic servers. | N-SW-023 | CR-SW-0012 | ||
| SSR-SW-0107 | SW | Functional | QM | Medium | Test | The ECA shall be programmable both while integrated in the vehicle network and as a standalone unit, using only the conditions and diagnostic tester interventions defined in this specification. | N-SW-023 | CR-SW-0017 | ||
| SSR-SW-0108 | SW | Functional | QM | Medium | Test | The ECA shall persist the system name identified by DID 0xF197, the diagnostic address, and the bitrate in the application data module dedicated to boot parameters, named the boot parameter module. | N-SW-023 | CR-SW-0019 | ||
| SSR-SW-0109 | SW | Functional | QM | Medium | Test | Until a boot parameter module has been programmed, the ECA shall apply the project-specific default diagnostic address, baud rate, and DID. | N-SW-023 | CR-SW-0020 | The customer labelled the values as 'typical' and 'project-specific'; confirm the exact default diagnostic address, baud rate, and DID for project P112478. | |
| SSR-SW-0109-2 | split | SW | Functional | QM | Medium | Test | The default diagnostic address shall be 0xA7. | N-SW-023 | CR-SW-0020 | |
| SSR-SW-0109-3 | split | SW | Functional | QM | Medium | Test | The default baud rate shall be 500 kb/s. | N-SW-023 | CR-SW-0020 | |
| SSR-SW-0109-4 | split | SW | Functional | QM | Medium | Test | The default DID shall be 0xF197. | N-SW-023 | CR-SW-0020 | |
| SSR-SW-0110 | SW | Functional | QM | Medium | Test | When the ECA switches from the application to the boot loader, the ECA shall respond with the same diagnostic address that it used while running the application. | N-SW-023 | CR-SW-0029 | ||
| SSR-SW-0111 | SW | Functional | QM | Medium | Test | When power is applied, the ECA shall be available for complete diagnostic communication within 2 seconds. | N-SW-023 | REQ_UDS_0223 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SW-0112 | SW | Functional | QM | Medium | Test | If the diagnostic data is unavailable within the required time, the ECA shall respond with NRC 0x78 requestCorrectlyReceived-ResponsePending for up to the maximum allowed time. | N-SW-024 | REQ_UDS_0224 | The 'maximum allowed time' is not quantified; confirm the applicable ISO 14229-1 timing bound (e.g., P2*server_max) for this project. | |
| SSR-SW-0113 | SW | Functional | QM | Medium | Test | The ECA shall support, for each entry in the pattern rules, one octet for the pattern rule settings followed by the diagnostic pattern of variable length. | N-SW-024 | CR-SW-0190 | ||
| SSR-SW-0114 | SW | Functional | QM | High | Test | The ECA shall support SDT in each execution state through both the boot loader diagnostic server and the application diagnostic server. | N-SW-024 | CR-SW-0231 | ||
| SSR-SYS-0362 | split | SYS | Design constraint | QM | Low | Test | The ECA shall locate the boot loader in a memory area that is separate from the application software. | N-SYS-072 | CR-SYS-0160 | |
| SSR-SYS-0362-2 | split | SYS | Design constraint | QM | Low | Test | The ECA shall make the boot loader erasable and programmable independently of the application software. | N-SYS-072 | CR-SYS-0160 | |
| SSR-SYS-0363 | SYS | Design constraint | QM | Low | Test | The ECA shall verify each programmed software module by calculating a checksum over the programmed data and matching it against the pre-calculated checksum. | N-SYS-072 | CR-SYS-0207 | ||
| SSR-SYS-0364 | SYS | Design constraint | QM | Low | Test | If the specified memory area is already completely erased or is writable when the erase service is requested, the ECA shall respond with a positive response code and leave the memory contents unchanged. | N-SYS-072 | CR-SYS-0209 | ||
| SSR-SYS-0365 | SYS | Design constraint | QM | Low | Review | When the ECA has accepted a SDSC, the ECA shall store the receipt number provided in the EMP request in NVM. | N-SYS-072 | CR-SYS-0216 | ||
| SSR-SYS-0366 | SYS | Design constraint | QM | Low | Review | The ECA shall read from NVM, for hashing, the data range whose start and end addresses are specified by the Ranges parameter. | N-SYS-072 | CR-SYS-0226 | ||
| SSR-SYS-0367 | SYS | Design constraint | QM | Low | Test | When hashing software, the ECA shall support inclusion of the whole memory range of a memory module, including its erased-only bytes, in the hash calculation. | N-SYS-072 | CR-SYS-0227 | ||
| SSR-SYS-0368 | SYS | Design constraint | QM | Low | Test | The ECA shall decrypt received data before storing it to NVM. | N-SYS-073 | CR-SYS-0231 | ||
| SSR-SYS-0369 | SYS | Design constraint | QM | Low | Test | If the specified memory area is already completely erased or is writable when the erase service is requested, the ECA shall respond with a positive response code and leave the memory contents unchanged. | N-SYS-073 | REQ_UDS_0158 | ||
| SSR-SYS-0370 | SYS | Design constraint | QM | Low | Review | When the ECA receives a DSC, the ECA shall semantically verify the DSC by parsing its entire content before storing the DSC in NVM. | N-SYS-073 | CR-SYS-0319 | ||
| SSR-SW-0115 | SW | Functional | QM | High | Test | The ECA shall comply with ISO 14229-1:2020 and the Traton UDS specification CVS124, including the clarifications, extensions, and exceptions stated in this specification. | N-SW-025 | CR-SW-0013 | ||
| SSR-SW-0116 | SW | Functional | QM | Low | Review | The ECA supplier shall treat the causes specified in ISO 14229-1:2020 as non-exhaustive examples. | N-SW-025 | CR-SW-0032 | ||
| SSR-SW-0117 | SW | Functional | QM | Medium | Test | The ECA shall support the diagnostic services as specified in CVS124. | N-SW-025 | CR-SW-0033 | ||
| SSR-SW-0118 | SW | Functional | QM | Low | Test | The ECA shall support the service negative response as specified in ISO 14229-1:2020. | N-SW-025 | CR-SW-0040 | ||
| SSR-SW-0119 | SW | Functional | QM | Low | Test | The ECA shall support the request message format defined in ISO 14229-1:2020. | N-SW-025 | CR-SW-0041 | The specific diagnostic service that this request refers to is not identified in the source. | |
| SSR-SW-0120 | SW | Functional | QM | Low | Test | The ECA shall support the positive response format defined in ISO 14229-1:2020. | N-SW-025 | CR-SW-0042 | The specific diagnostic service that this positive response refers to is not identified in the source. | |
| SSR-SW-0121 | SW | Functional | QM | Low | Test | The ECA shall support the blockSequenceCounter parameter formatted according to ISO 14229-1:2020. | N-SW-026 | CR-SW-0044 | ||
| SSR-SW-0122 | SW | Functional | QM | Low | Test | The ECA shall support the transferRequestParameterRecord parameter formatted according to ISO 14229-1:2020. | N-SW-026 | CR-SW-0045 | ||
| SSR-SW-0123 | SW | Functional | QM | Low | Test | The ECA shall support the request message format defined in ISO 14229-1:2020. | N-SW-026 | CR-SW-0047 | The specific diagnostic service that this request refers to is not identified in the source. | |
| SSR-SW-0124 | SW | Functional | QM | Low | Test | The ECA shall support the positive response format defined in ISO 14229-1:2020. | N-SW-026 | CR-SW-0048 | The specific diagnostic service that this positive response refers to is not identified in the source. | |
| SSR-SW-0125 | SW | Functional | QM | Low | Test | The ECA shall support the Administrative Parameter formatted according to ISO 14229-1:2020. | N-SW-026 | CR-SW-0049 | ||
| SSR-SW-0126 | SW | Functional | QM | Medium | Test | If the ECA sets routineResult to 0x00 CorrectResult, the ECA shall reject the specified diagnostic services and routines with NRC 0x24 until a new SDSC is provided. | N-SW-026 | CR-SW-0056 | The set of diagnostic services and routines to be rejected ('the following ...') is referenced but not enumerated in the source. | |
| SSR-SW-0127 | SW | Functional | QM | Medium | Test | When the ECA has accepted a SDSC, the ECA shall accept the diagnostic routine 0xFF00 Erase Memory. | N-SW-027 | CR-SW-0060 | The source lists 'the following diagnostic services and routines' but shows only routine 0xFF00 Erase Memory; confirm whether additional entries apply. | |
| SSR-SW-0128 | SW | Functional | QM | Low | Test | The ECA shall support the routineControlOptionRecord request parameter as specified in ISO 14229-1. | N-SW-027 | REQ_UDS_0288 | ||
| SSR-SW-0129 | SW | Functional | QM | Low | Test | The ECA shall exclude the RoutineControlOptionRecord request parameter from the supported request parameters. | N-SW-027 | REQ_UDS_0151 | ||
| SSR-SW-0130 | SW | Functional | QM | Low | Test | The ECA shall exclude the routineControlType request parameter value 0x03 requestRoutineResults from the supported values. | N-SW-027 | REQ_UDS_0152 | ||
| SSR-SW-0131 | SW | Functional | QM | Low | Test | The ECA shall support the RoutineControl service without the requestRoutineResults routineControlType value 0x03. | N-SW-027 | REQ_UDS_0164 | ||
| SSR-SW-0132 | SW | Functional | QM | Low | Test | The ECA shall support the RoutineControl service without the routineControlOptionRecord parameter. | N-SW-027 | REQ_UDS_0174 | ||
| SSR-SW-0133 | needs clarification | SW | Functional | QM | Low | Test | The ECA shall format each positive response to a RoutineControl service request for Software Installation according to TBD. | N-SW-028 | REQ_UDS_0175 | CLARIFY: What is the required format and content of the positive response to a RoutineControl (Software Installation) service request? The source statement ends at 'shall be formatted'.; The required format and content of the positive RoutineControl (Software Installation) response is not stated; the customer statement is truncated after 'shall be formatted'. |
| SSR-SW-0134 | SW | Functional | QM | Low | Review | Where a requirement in the customer specification deviates from ISO 14229-1, the ECA supplier shall apply the requirement of the customer specification. | N-SW-028 | CR-SW-0230 | ||
| SSR-SW-0135 | SW | Functional | QM | Medium | Test | Where the encapsulated UDS response is negative, the ECA shall return it within a positive SDT response. | N-SW-028 | CR-SW-0242 | ||
| SSR-HW-0046 | HW | Design constraint | QM | Low | Test | The ECA shall allow the generic bootloader to be reused for future purposes or applications while retaining the existing platform part number. | N-HW-013 | CR-HW-0029 | ||
| SSR-CYBER-0078 | CYBER | Design constraint | QM | Low | Review | Where the ECA supplier delivers encrypted flash files to the vehicle manufacturer, the ECA supplier shall provide the information required to verify the flash files during the flash file update procedure. | N-CYBER-020 | CR-CYBER-0038 | ||
| SSR-CYBER-0079 | CYBER | Design constraint | QM | Low | Test | If the software to be updated is encrypted, the ECA shall have the decryption keys available before step P1Pro9. | N-CYBER-020 | CR-CYBER-0041 | ||
| SSR-CYBER-0080 | CYBER | Design constraint | QM | Low | Test | The ECA shall determine whether any part of the received data is encrypted by checking the address ranges for a match in an EncryptionEntry defined in the SDSC. | N-CYBER-020 | CR-CYBER-0045 | ||
| SSR-CYBER-0081 | CYBER | Design constraint | QM | Low | Test | If the software is encrypted, the ECA shall decrypt the software before decompression and software hash comparison verification are performed. | N-CYBER-020 | CR-CYBER-0046 | ||
| SSR-CYBER-0082 | CYBER | Design constraint | QM | Low | Test | The ECA shall support the Signature and Encryption Calculation parameter SIGENCRYPT according to CVS32. | N-CYBER-020 | CR-CYBER-0047 | ||
| SSR-CYBER-0083 | CYBER | Design constraint | QM | Low | Test | Where a match for the received data is found in an EncryptionEntry of the DSC and a cipher is not yet initialized, the ECA shall initialize a cipher. | N-CYBER-020 | CR-CYBER-0054 | ||
| SSR-CYBER-0084 | CYBER | Design constraint | QM | Low | Test | While received data continues to match the current EncryptionEntry, the ECA shall keep the initialized cipher scheme active. | N-CYBER-021 | CR-CYBER-0055 | ||
| SSR-CYBER-0085 | CYBER | Design constraint | QM | Low | Test | The ECA shall reinitialize the cipher for each new EncryptionEntry. | N-CYBER-021 | CR-CYBER-0056 | ||
| SSR-CYBER-0086 | CYBER | Design constraint | QM | Low | Test | When the ECA receives data that matches an address range in an EncryptionEntry, the ECA shall decrypt the data received in the TransferData request. | N-CYBER-021 | CR-CYBER-0057 | ||
| SSR-CYBER-0087 | CYBER | Design constraint | QM | Low | Test | When the ECA receives data within a range given as address and size in the RequestDownload request, the ECA shall decrypt the data before storing it. | N-CYBER-021 | CR-CYBER-0058 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-CYBER-0088 | CYBER | Design constraint | QM | Low | Test | The ECA shall allow the requests contained in the role 0 rule regardless of the value of the Confidentiality field setting. | N-CYBER-021 | CR-CYBER-0082 | ||
| SSR-CYBER-0089 | CYBER | Design constraint | QM | Low | Test | The ECA shall support a DSC containing encryptionEntries. | N-CYBER-021 | CR-CYBER-0085 | ||
| SSR-CYBER-0090 | CYBER | Design constraint | QM | Low | Test | The ECA shall accept a zero-length ASN.1 SEQUENCE tag for an empty encryptionEntries element in a DSC transmitted by the client. | N-CYBER-022 | CR-CYBER-0086 | ||
| SSR-CYBER-0091 | CYBER | Design constraint | QM | Low | Test | The ECA shall support an empty DSC that contains only the version and id Metadata and the empty sequences for verificationEntries, encryptionEntries and itemEntries. | N-CYBER-022 | CR-CYBER-0087 | ||
| SSR-CYBER-0092 | split | CYBER | Design constraint | QM | Low | Test | The ECA shall provide support for verification and encryption. | N-CYBER-022 | CR-CYBER-0088 | |
| SSR-CYBER-0092-2 | split | CYBER | Design constraint | QM | Low | Test | Where a DSC contains only the version and id, the ECA shall skip verification and encryption for that DSC. | N-CYBER-022 | CR-CYBER-0088 | |
| SSR-CYBER-0093 | CYBER | Design constraint | QM | Low | Test | The ECA shall support the ASN.1 content defined as: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }. | N-CYBER-022 | CR-CYBER-0090 | ||
| SSR-CYBER-0094 | CYBER | Design constraint | QM | Low | Test | The ECA shall support the EncryptionEntry algorithm. | N-CYBER-022 | CR-CYBER-0092 | ||
| SSR-CYBER-0095 | CYBER | Design constraint | QM | High | Test | The ECA shall verify the length of the key and the iv according to the algorithm stipulated in the EncryptionEntry. | N-CYBER-022 | CR-CYBER-0093 | ||
| SSR-CYBER-0096 | CYBER | Design constraint | QM | Low | Test | The ECA shall support a DSC in which the verificationEntries, encryptionEntries and itemEntries sequence tags are present with zero length. | N-CYBER-023 | CR-CYBER-0095 | ||
| SSR-CYBER-0097 | CYBER | Design constraint | QM | Low | Test | The ECA shall support the CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305. | N-CYBER-023 | CR-CYBER-0127 | ||
| SSR-CYBER-0098 | CYBER | Design constraint | QM | Low | Test | When the ECA receives an SDT message, the ECA shall verify or decrypt the message using the CipherScheme indicated by the SIGENCRYPT protocol element. | N-CYBER-023 | CR-CYBER-0128 | ||
| SSR-CYBER-0099 | CYBER | Design constraint | QM | Low | Test | Where the SDT response is positive, the ECA shall respond to the client request using the same CipherScheme that was used in the request. | N-CYBER-023 | CR-CYBER-0129 | ||
| SSR-CYBER-0100 | CYBER | Design constraint | QM | Low | Test | Where the client alters the CipherScheme between SDT requests within the same SDT sequence, the ECA shall accept the altered CipherScheme. | N-CYBER-023 | CR-CYBER-0130 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-CYBER-0101 | CYBER | Design constraint | QM | High | Test | The ECA shall maintain state variables that indicate which CipherScheme and which resulting key were used in the previous SDT transaction. | N-CYBER-023 | CR-CYBER-0131 | ||
| SSR-CYBER-0102 | split | CYBER | Design constraint | QM | Low | Test | Where an SDT request is being constructed and SIGENCRYPT differs from PSIGENCRYPT, the client shall re-run the KDF. | N-CYBER-024 | CR-CYBER-0132 | |
| SSR-CYBER-0102-2 | split | CYBER | Design constraint | QM | Low | Test | Where the authentication or encryption succeeds, the client shall update the state variables PSIGENCRYPT and PKEY with the new values. | N-CYBER-024 | CR-CYBER-0132 | |
| SSR-CYBER-0103 | split | CYBER | Design constraint | QM | Low | Test | When the ECA receives an SDT request whose SIGENCRYPT differs from PSIGENCRYPT, the ECA shall re-run the KDF. | N-CYBER-024 | CR-CYBER-0133 | |
| SSR-CYBER-0103-2 | split | CYBER | Design constraint | QM | Low | Test | Where the verification or decryption succeeds, the ECA shall update the state variables PSIGENCRYPT and PKEY with the new values. | N-CYBER-024 | CR-CYBER-0133 | |
| SSR-CYBER-0104 | needs clarification | CYBER | Design constraint | QM | Medium | Test | The client shall encrypt and authenticate the SDT request with the A argument set to TBD. | N-CYBER-024 | CR-CYBER-0140 | CLARIFY: What value must the A (associated data) argument be set to when the client encrypts and authenticates the SDT request? The source statement is truncated after 'with the A argument set to the'.; The value to which the A argument must be set is missing; the customer statement is truncated after 'set to the'. |
| SSR-CYBER-0105 | CYBER | Design constraint | QM | Low | Test | The client shall decrypt and verify the SDT response with the A argument set to the concatenated octet string comprising the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the value stored in the state variable PREQTAG. | N-CYBER-024 | CR-CYBER-0141 | ||
| SSR-CYBER-0106 | CYBER | Design constraint | QM | Low | Test | The ECA shall decrypt and verify the SDT request with the A argument set to the concatenated octet string comprising the SDT, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements. | N-CYBER-024 | CR-CYBER-0142 | ||
| SSR-CYBER-0107 | CYBER | Design constraint | QM | Medium | Test | The ECA shall encrypt and authenticate the SDT response with the A argument set to the concatenated octet string comprising the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the octet string carried by the SIGMACBYTE protocol element of the corresponding request. | N-CYBER-024 | CR-CYBER-0143 | ||
| SSR-CYBER-0108 | CYBER | Design constraint | QM | Medium | Test | Where the ECA successfully authenticates or encrypts the SDT response, the ECA shall update its state by incrementing PRESARC by one. | N-CYBER-025 | CR-CYBER-0149 | ||
| SSR-CYBER-0109 | CYBER | Design constraint | QM | Medium | Test | Where the client successfully authenticates or encrypts the SDT request, the client shall update its state by incrementing PREQARC by one. | N-CYBER-025 | CR-CYBER-0150 | ||
| SSR-CYBER-0110 | CYBER | Design constraint | QM | Low | Test | When the client receives an SDT response with an unsupported SIGENCRYPT value, the client shall discard the response. | N-CYBER-025 | CR-CYBER-0151 | ||
| SSR-CYBER-0111 | CYBER | Design constraint | QM | Low | Test | When the client receives an SDT response in which APAR conflicts with SIGENCRYPT, the client shall discard the response. | N-CYBER-025 | CR-CYBER-0152 | ||
| SSR-CYBER-0112 | CYBER | Design constraint | QM | Low | Test | When the client receives an SDT response in which SIGLEN conflicts with SIGENCRYPT, the client shall discard the response. | N-CYBER-025 | CR-CYBER-0153 | ||
| SSR-SW-0136 | SW | Functional | QM | Low | Test | The ECA shall perform an authentication sequence with the client by means of the Authentication service 0x29. | N-SW-029 | CR-SW-0023 | ||
| SSR-SW-0137 | SW | Functional | QM | Low | Test | When the ECA receives an Authentication service 0x29 request with the deAuthenticate sub-function 0x00 from the client, the ECA shall disable authorized access to the diagnostic programming services. | N-SW-029 | CR-SW-0024 | ||
| SSR-SW-0138 | SW | Functional | QM | Low | Test | The ECA shall format the negative response to the Authentication service 0x29 as specified in ISO 14229-1 section 5.5.18. | N-SW-029 | REQ_UDS_0129 | ||
| SSR-SW-0139 | SW | Functional | QM | Low | Test | The ECA shall use the Authentication service 0x29 for mutual authentication of the client and the ECA. | N-SW-029 | REQ_UDS_0130 | ||
| SSR-SW-0140 | SW | Functional | QM | Low | Test | The ECA shall implement the Authentication service 0x29 according to CVS31. | N-SW-029 | REQ_UDS_0133 | ||
| SSR-SW-0141 | SW | Functional | QM | Low | Test | If a normal condition defined in ISO 14229-1 for performing the service fails, the ECA shall return a negative response code. | N-SW-029 | CR-SW-0165 | ||
| SSR-SW-0142 | SW | Functional | QM | Low | Test | The ECA shall require that requests matching allow rules are authenticated using SecuredDataTransmission service 0x84. | N-SW-030 | CR-SW-0187 | ||
| SSR-SW-0143 | needs clarification | SW | Functional | QM | Low | Test | The ECA shall make each service, DID and RID assigned to role 0 available to each client regardless of the client diagnostic role, authorization status and authentication status. | N-SW-030 | CR-SW-0193 | CLARIFY: CR-SW-0193 is phrased as an explanatory note ('role 0 is particularly useful for defining ...'), not a normative shall. Please confirm the intended ECA obligation: shall every service, DID and RID configured under role 0 be available to every client irrespective of the client's diagnostic role, authorization status and authentication status? |
| SSR-SW-0144 | SW | Functional | QM | Low | Test | The ECA shall allow each request contained in the role 0 rule irrespective of whether the request is data-authenticated using SecuredDataTransmission service 0x84. | N-SW-030 | CR-SW-0194 | ||
| SSR-SW-0145 | SW | Functional | QM | Low | Test | The ECA shall generate the challengeClient using a CRNG. | N-SW-030 | CR-SW-0205 | ||
| SSR-SW-0146 | SW | Functional | QM | Low | Test | If the ECA determines that the client lacks an existing authentication pending state, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x24, indicating requestSequenceError. | N-SW-030 | CR-SW-0211 | ||
| SSR-SW-0147 | SW | Functional | QM | Low | Test | If the ECA determines that the client has an existing authentication pending state and the Authentication completion timer has expired, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x24, indicating requestSequenceError. | N-SW-030 | CR-SW-0212 | ||
| SSR-SW-0148 | SW | Functional | QM | Low | Test | If the ECA is unable to determine whether the client has an existing authentication pending state, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable. | N-SW-031 | CR-SW-0213 | ||
| SSR-SW-0149 | SW | Functional | QM | Low | Test | If the ECA is deleting the authentication pending state as a consequence of a client proofOfOwnership signature verification failure and the ECA determines that the authentication pending state was deleted, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x10, indicating generalReject. | N-SW-031 | CR-SW-0214 | ||
| SSR-SW-0150 | SW | Functional | QM | Low | Test | If the ECA is deleting the authentication pending state as a consequence of a client proofOfOwnership signature verification failure and the ECA is unable to determine that the authentication pending state was deleted, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable. | N-SW-031 | CR-SW-0215 | ||
| SSR-SW-0151 | SW | Functional | QM | Low | Test | If the ECA is deleting the authentication pending state as a consequence of a failure to store the authentication state, the ECA shall respond to the proofOfOwnership request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable. | N-SW-031 | CR-SW-0216 | ||
| SSR-SW-0152 | SW | Functional | QM | Low | Test | If the ECA determines that the client is currently unauthenticated, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x24, indicating requestSequenceError. | N-SW-031 | CR-SW-0217 | ||
| SSR-SW-0153 | SW | Functional | QM | Low | Test | If the ECA is unable to determine that the client is currently authenticated, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x94, indicating ResourceTemporarilyNotAvailable. | N-SW-031 | CR-SW-0218 | ||
| SSR-SW-0154 | SW | Functional | QM | Low | Test | If the ECA is unable to delete the client's authentication state or is unable to verify its presence, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x94. | N-SW-032 | CR-SW-0219 | ||
| SSR-SW-0155 | SW | Functional | QM | Low | Test | If the ECA is unable to delete the client's authentication state or is unable to retrieve it because of internal errors, the ECA shall respond to the deAuthenticate request with Negative Response Code 0x94. | N-SW-032 | CR-SW-0220 | ||
| SSR-SW-0156 | SW | Functional | QM | Medium | Test | When a client request triggers an ECA reset, the ECA shall send the corresponding response before invalidating the authentication pending state. | N-SW-032 | CR-SW-0226 | ||
| SSR-SW-0157 | SW | Functional | QM | Medium | Test | When a client request triggers an ECA reset, the ECA shall send the corresponding response before invalidating the authentication state. | N-SW-032 | CR-SW-0227 | ||
| SSR-SW-0158 | needs clarification | SW | Functional | QM | Low | Test | The ECA shall always allow the Authentication service 0x29. | N-SW-032 | CR-SW-0228 | CLARIFY: CR-SW-0228 is truncated at 'regardless of'. Please complete the clause: under exactly which conditions must the ECA always allow the Authentication service 0x29 (e.g. regardless of the active diagnostic session, security level, or RBACC access-control state)?; Truncated qualifier: what condition(s) the 'regardless of ...' clause was intended to cover (e.g. active diagnostic session, security level, RBACC rules). |
| SSR-SW-0159 | SW | Functional | QM | Low | Test | The ECA shall use the diagnostic tester address of the SDT client to identify the authentication state and the associated SecuredDataTransmissionKey. | N-SW-032 | CR-SW-0232 | ||
| SSR-SW-0160 | SW | Functional | QM | Low | Test | When either PREQARC or PRESARC reaches the maximum value 65535, the ECA shall require the client to re-authenticate before the ECA processes further Secured Data Transmission messages. | N-SW-033 | CR-SW-0235 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SW-0161 | SW | Functional | QM | Low | Test | In addition to the Negative Response Codes 0x3A, 0x13 and 0x21 specified by ISO 14229-1:2020, the ECA shall support Negative Response Code 0x34, indicating authenticationRequired. | N-SW-033 | CR-SW-0243 | ||
| SSR-SW-0162 | SW | Functional | QM | Low | Test | When the ECA receives an SDT request from an unauthenticated client, the ECA shall respond with an SDT negative response using Negative Response Code 0x34. | N-SW-033 | CR-SW-0244 | ||
| SSR-CYBER-0113 | needs clarification | CYBER | Design constraint | QM | High | Test | Where a client reads stored entities to verify their presence, the ECA shall provide read access to the certificate validity time and the RBAC configuration file. | N-CYBER-026 | CR-CYBER-0039 | CLARIFY: CR-CYBER-0039 is written as an illustrative example ('As example, the client may read ...'). Please confirm the normative ECA obligation: shall the ECA provide read access to the certificate validity time and the RBAC configuration file so a client can verify the stored entities, and via which service/DIDs? |
| SSR-CYBER-0114 | CYBER | Design constraint | QM | Highest | Test | If a conflicting or overlapping rule is found between the client certificate D-RBACC extension and a rule in the RBAC configuration in the RBACC, the ECA shall enforce the rule in the client certificate D-RBACC extension. | N-CYBER-026 | CR-CYBER-0075 | ||
| SSR-CYBER-0115 | CYBER | Design constraint | QM | Medium | Test | While the DynamicallyDefineDataIdentifier service is being used, the ECA shall evaluate each DID included in the request against the rules applicable to the client in the client certificate and in the RBACC. | N-CYBER-026 | CR-CYBER-0083 | ||
| SSR-CYBER-0116 | needs clarification | CYBER | Design constraint | QM | Low | Test | The ECA shall accept a verifyCertificateBidirectional subfunction request formatted according to TBD. | N-CYBER-026 | CR-CYBER-0096 | CLARIFY: CR-CYBER-0096 is truncated at 'shall be formatted according to'. Which specification, table or clause defines the required format of the verifyCertificateBidirectional subfunction request?; TBD: specification/table that defines the required format of the verifyCertificateBidirectional subfunction request (source truncated after 'according to'). |
| SSR-CYBER-0117 | CYBER | Design constraint | QM | Low | Test | If, upon reception of a verifyCertificateBidirectional request, the Authentication delay timer has expired, the ECA shall continue to process the verifyCertificateBidirectional request. | N-CYBER-026 | CR-CYBER-0097 | ||
| SSR-CYBER-0118 | CYBER | Design constraint | QM | Medium | Test | If the ECA verifies the client certificate as valid, the ECA shall create the requested client authentication pending state. | N-CYBER-026 | CR-CYBER-0099 | ||
| SSR-CYBER-0119 | CYBER | Design constraint | QM | Low | Test | When the ECA receives a verifyCertificateBidirectional request, the ECA shall verify the value of lengthOfCertificateClient. | N-CYBER-027 | CR-CYBER-0100 | ||
| SSR-CYBER-0120 | CYBER | Design constraint | QM | Low | Test | The ECA shall use certificates whose format and structure conform to CVS30. | N-CYBER-027 | CR-CYBER-0109 | ||
| SSR-CYBER-0121 | CYBER | Design constraint | QM | Highest | Test | If a client certificate received through the verifyCertificateBidirectional subfunction matches the ECA's own certificate, the ECA shall reject that client certificate. | N-CYBER-027 | CR-CYBER-0110 | ||
| SSR-CYBER-0122 | CYBER | Design constraint | QM | Highest | Test | The ECA shall reject each authentication attempt that uses the ECA's own key or certificate. | N-CYBER-027 | CR-CYBER-0111 | ||
| SSR-CYBER-0123 | CYBER | Design constraint | QM | High | Test | The ECA shall verify the client certificate sent using the verifyCertificateBidirectional subfunction in accordance with Figure 3 of the referenced specification. | N-CYBER-027 | CR-CYBER-0112 | The specification document containing Figure 3 is not identified in the item; the exact reference is TBD. | |
| SSR-CYBER-0124 | CYBER | Design constraint | QM | High | Test | The ECA shall verify the signature of the client certificate using the AUTH-CA EMP entity public key. | N-CYBER-027 | CR-CYBER-0113 | ||
| SSR-CYBER-0125 | CYBER | Design constraint | QM | Low | Test | If the D-RBACC extension is detected, the ECA shall override the RBACC permissions with the D-RBACC permissions. | N-CYBER-028 | CR-CYBER-0115 | ||
| SSR-CYBER-0126 | needs clarification | CYBER | Design constraint | QM | Low | Test | The ECA shall validate the D-RBACC by parsing its entire content. | N-CYBER-028 | CR-CYBER-0116 | CLARIFY: CR-CYBER-0116 is truncated at 'If content is invalid,'. What action shall the ECA take when the D-RBACC content is found to be invalid (e.g. reject the D-RBACC, fall back to the RBACC, respond with which NRC)?; TBD: action the ECA shall take when the D-RBACC content is invalid (source truncated after 'If content is invalid,'). |
| SSR-CYBER-0127 | CYBER | Design constraint | QM | Low | Test | The ECA shall verify that the D-RBACC version provided by the client is compatible with the ECA's supported D-RBACC version. | N-CYBER-028 | CR-CYBER-0117 | ||
| SSR-CYBER-0128 | CYBER | Design constraint | QM | High | Test | The ECA shall validate the certificate so that notBefore ≤ Certificate-time ≤ notAfter. | N-CYBER-028 | CR-CYBER-0122 | ||
| SSR-CYBER-0129 | needs clarification | CYBER | Design constraint | QM | Low | Test | The ECA shall enforce a minimum time of TBD between consecutive verifyCertificateBidirectional requests, defined by the delay timer. | N-CYBER-028 | CR-CYBER-0124 | CLARIFY: CR-CYBER-0124 is a truncated definition ('The delay timer represents the required minimum time between verifyCertificateBidirectional'). Please confirm the obligation and provide the value: what is the minimum time the ECA shall enforce between consecutive verifyCertificateBidirectional requests?; TBD: minimum time value the delay timer enforces between consecutive verifyCertificateBidirectional requests (source truncated after 'between verifyCertificateBidirectional'). |
| SSR-CYBER-0130 | CYBER | Design constraint | QM | Low | Test | While the delay timer is inactive, the ECA shall start the delay timer as part of processing a verifyCertificateBidirectional request. | N-CYBER-028 | CR-CYBER-0125 | ||
| SSR-CYBER-0131 | needs clarification | CYBER | Design constraint | QM | Medium | Test | Where a client updates the RBAC configuration file, the ECA shall update the stored entities according to the client's set request. | N-CYBER-029 | CR-CYBER-0040 | CLARIFY: CR-CYBER-0040 is written as an illustrative example ('As example, the client may ...'). Please confirm the normative ECA obligation: shall the ECA accept a client set request that updates the RBAC configuration file entities, and through which service/mechanism? |
| SSR-CYBER-0132 | needs clarification | CYBER | Design constraint | QM | Medium | Test | Where a client sets an updated RBAC configuration file entity via EMP, the ECA shall store the updated entity. | N-CYBER-029 | CR-CYBER-0043 | CLARIFY: CR-CYBER-0043 is written as an illustrative example ('As example, the client may ...'). Please confirm the normative ECA obligation: shall the ECA accept and store an updated RBAC configuration file entity that a client sets via EMP? |
| SSR-CYBER-0133 | CYBER | Design constraint | QM | Medium | Test | The ECA shall implement Role-Based Access Control in accordance with CVS151. | N-CYBER-029 | REQ_UDS_0047 | ||
| SSR-CYBER-0134 | CYBER | Design constraint | QM | Medium | Test | The ECA shall define the CVS31 and CVS32 requirement preconditions for each service within the RBAC configuration file. | N-CYBER-029 | REQ_UDS_0048 | ||
| SSR-CYBER-0135 | CYBER | Design constraint | QM | Low | Test | Each RBACC shall contain exactly one role configuration for each supported role. | N-CYBER-029 | CR-CYBER-0066 | ||
| SSR-CYBER-0136 | CYBER | Design constraint | QM | Low | Test | If no rule in the RBACC matches the request, the ECA shall deny the request. | N-CYBER-029 | CR-CYBER-0068 | ||
| SSR-CYBER-0137 | needs clarification | CYBER | Design constraint | QM | Low | Test | Each RBACC ALLOW rule shall include a setting that dictates whether a request matching the rule must be authenticated. | N-CYBER-030 | CR-CYBER-0069 | CLARIFY: CR-CYBER-0069 is garbled/truncated ('...must be 14229-1:2020)'). Please confirm: does each RBACC ALLOW rule carry a setting that dictates whether a request matching the rule must be data-authenticated (e.g. via SecuredDataTransmission per ISO 14229-1:2020)?; TBD: exact meaning of the truncated setting; source reads '...must be 14229-1:2020)' and appears to reference data authentication per ISO 14229-1:2020. |
| SSR-CYBER-0138 | CYBER | Design constraint | QM | Low | Test | The ECA shall define the RBACC in accordance with the following ASN.1 definition: RBACC ::= SEQUENCE { version OCTET STRING (SIZE(2)), rbacc-id OCTET STRING (SIZE(16)), role-configurations SEQUENCE (SIZE(0..MAX)) OF Role-configuration } Role-configuration ::= SEQUENCE { role INTEGER(0..MAX), pattern-rules-deny SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(2..MAX)), pattern-rules-allow SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(2..MAX)), did-rules-deny SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)), did-rules-allow SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)), rid-rules-deny SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)), rid-rules-allow SEQUENCE (SIZE(0..MAX)) OF OCTET STRING (SIZE(3)) }. | N-CYBER-030 | CR-CYBER-0071 | ||
| SSR-CYBER-0139 | CYBER | Design constraint | QM | Low | Test | Before the RBACC is stored, the ECA shall verify that the ECA supports the structure indicated by the version number. | N-CYBER-030 | CR-CYBER-0072 | ||
| SSR-CYBER-0140 | CYBER | Design constraint | QM | Low | Test | The ECA shall support 16 octets in the rbacc-id field. | N-CYBER-030 | CR-CYBER-0073 | ||
| SSR-CYBER-0141 | CYBER | Design constraint | QM | Low | Test | The ECA shall interpret the extnValue as one instance of a RBACC. | N-CYBER-030 | CR-CYBER-0076 | ||
| SSR-CYBER-0142 | CYBER | Design constraint | QM | Medium | Test | The ECA shall implement the RBAC internal logic as specified in Figure 4. | N-CYBER-030 | CR-CYBER-0077 | ||
| SSR-CYBER-0143 | CYBER | Design constraint | QM | Medium | Test | The ECA shall implement the RBAC pattern rule evaluation logic as specified in Figure 5. | N-CYBER-031 | CR-CYBER-0078 | ||
| SSR-CYBER-0144 | CYBER | Design constraint | QM | Medium | Test | The ECA shall implement the RBAC DID rule evaluation as specified in Figure 6. | N-CYBER-031 | CR-CYBER-0079 | ||
| SSR-CYBER-0145 | CYBER | Design constraint | QM | Medium | Test | The ECA shall implement the RBAC RID rule evaluation as specified in Figure 7. | N-CYBER-031 | CR-CYBER-0080 | ||
| SSR-SW-0163 | SW | Functional | QM | Low | Test | Where a LinkControl service request is received while an application programmed by the supplier is active, the ECA may respond with negative response code 0x7F, serviceNotSupportedInActiveSession. | N-SW-034 | CR-SW-0026 | ||
| SSR-SW-0164 | SW | Functional | QM | Low | Test | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall start erasing the memory area specified by the RequestDownload request. | N-SW-034 | CR-SW-0035 | ||
| SSR-SW-0165 | split | SW | Functional | QM | Low | Test | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall reset the identification DIDs to their default values. | N-SW-034 | CR-SW-0036 | The source enumerates identification DIDs only for the boot software download case (0xF180, 0xF191, 0xF187); the complete set of identification DIDs reset for other download cases is not provided in the source. |
| SSR-SW-0165-2 | split | SW | Functional | QM | Low | Test | Where boot software download is requested, the ECA shall reset the identification DIDs 0xF180, 0xF191 and 0xF187 to their default values. | N-SW-034 | CR-SW-0036 | |
| SSR-SW-0166 | SW | Functional | QM | Low | Test | When the RequestDownload service has started, the ECA shall permit only the TesterPresent, ECUReset, TransferData and DiagnosticSessionControl services until the RequestTransferExit service has been called or any of these services returns an error. | N-SW-034 | CR-SW-0037 | ||
| SSR-SW-0167 | SW | Functional | QM | Medium | Test | The ECA shall support the default diagnostic session. | N-SW-034 | REQ_UDS_0040 | ||
| SSR-SW-0168 | SW | Functional | QM | Medium | Test | The ECA shall support the non-default diagnostic session named extendedDiagnosticSession. | N-SW-034 | REQ_UDS_0042 | ||
| SSR-SW-0169 | SW | Functional | QM | High | Review | The ECA supplier shall agree each diagnostic session that is not defined in this document with the vehicle manufacturer. | N-SW-035 | REQ_UDS_0043 | ||
| SSR-SW-0170 | SW | Functional | QM | Low | Review | The ECA supplier shall agree the mapping of RoutineControl service routines to sessions with the vehicle manufacturer. | N-SW-035 | REQ_UDS_0046 | ||
| SSR-SW-0171 | SW | Functional | QM | Low | Test | The ECA shall process a DiagnosticSessionControl service request with the diagnosticSessionType parameter set to ProgrammingSession only when normal communication has been switched off by a previous CommunicationControl service call. | N-SW-035 | REQ_UDS_0057 | ||
| SSR-SW-0172 | SW | Functional | QM | Low | Test | The ECA shall set the response parameter diagnosticSessionType in accordance with ISO 14229-1. | N-SW-035 | REQ_UDS_0241 | ||
| SSR-SW-0173 | SW | Functional | QM | Low | Test | The ECA shall set the response parameter sessionParameterRecord in accordance with ISO 14229-1. | N-SW-035 | REQ_UDS_0242 | ||
| SSR-SW-0174 | SW | Functional | QM | Low | Test | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall start erasing the memory area specified by the RequestDownload request. | N-SW-035 | REQ_UDS_0108 | ||
| SSR-SW-0175 | split | SW | Functional | QM | Low | Test | If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00, then the ECA shall reset the identification DIDs to their default values. | N-SW-036 | REQ_UDS_0109 | The source enumerates identification DIDs only for the boot software download case (0xF180, 0xF191, 0xF187); the complete set of identification DIDs reset for other download cases is not provided in the source. |
| SSR-SW-0175-2 | split | SW | Functional | QM | Low | Test | Where boot software download is requested, the ECA shall reset the identification DIDs 0xF180, 0xF191 and 0xF187 to their default values. | N-SW-036 | REQ_UDS_0109 | |
| SSR-SW-0176 | SW | Functional | QM | Low | Test | When the RequestDownload service has started, the ECA shall permit only the TesterPresent, ECUReset, TransferData and DiagnosticSessionControl services until the RequestTransferExit service has been called or any of these services returns an error. | N-SW-036 | REQ_UDS_0110 | ||
| SSR-SW-0177 | SW | Functional | QM | Low | Test | The ECA shall support the routine in the Extended session of both the Application and the Boot software. | N-SW-036 | REQ_UDS_0150 | ||
| SSR-SW-0178 | SW | Functional | QM | Low | Test | The ECA shall support the routine in the Programming session. | N-SW-036 | REQ_UDS_0162 | ||
| SSR-SW-0179 | SW | Functional | QM | Low | Test | The ECA shall support the routine in the Programming session. | N-SW-036 | REQ_UDS_0173 | ||
| SSR-SW-0180 | SW | Functional | QM | Low | Test | The ECA shall support the routine in the Programming session. | N-SW-036 | REQ_UDS_0189 | ||
| SSR-SW-0181 | SW | Functional | QM | Low | Test | The ECA shall support the routine in each session of both the Application and the Boot software. | N-SW-037 | REQ_UDS_0195 | ||
| SSR-SW-0182 | needs clarification | SW | Functional | QM | Medium | Review | The ECA supplier shall interpret the keywords 'shall', 'should' and 'must' used in this document in accordance with RFC 2119. | N-SW-037 | 1.3 | CLARIFY: This source is a document-conventions paragraph (mnemonics, pseudo-code notation, requirement tagging, and keyword interpretation). Does it yield any verifiable ECA or supplier requirement, or should it be retained as informational only? If a requirement is intended, which specific obligation applies? |
| SSR-SW-0183 | SW | Functional | QM | Medium | Test | The ECA shall have the information required to verify the software integrity available before the RoutineControl eraseMemory step P1Pro6. | N-SW-038 | CR-SW-0027 | ||
| SSR-SW-0184 | needs clarification | SW | Functional | QM | Low | Test | The ECA shall support physical memory range erase in accordance with ISO 14229-1 Table H1. | N-SW-038 | CR-SW-0053 | CLARIFY: The source is a fragment of a table (module/index and memory-erase mapping with a legend 'M = Mandatory', 'C = Mandatory if required to meet the performance requirements') and cannot be parsed into a single requirement. Please provide the intended obligation and the complete table.; The module-to-index / memory-erase mapping is provided only as a table fragment (e.g. Module 2 Application SW, range 0x02-0xFF) and is not fully specified in the source. |
| SSR-SW-0185 | split | SW | Functional | QM | High | Test | When the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall simulate turning the ignition key off and back on. | N-SW-038 | REQ_UDS_0070 | |
| SSR-SW-0185-2 | split | SW | Functional | QM | High | Test | When the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall preserve the values of the non-volatile memory locations. | N-SW-038 | REQ_UDS_0070 | |
| SSR-SW-0185-3 | split | SW | Functional | QM | High | Test | When the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall initialize the volatile memory. | N-SW-038 | REQ_UDS_0070 | |
| SSR-SW-0186 | SW | Functional | QM | Low | Test | When the ECA processes an ECUReset service request with the requestParameter set to the keyOffOnReset value 0x02, the ECA shall store the buffered volatile-memory data into non-volatile memory before sending a positive response. | N-SW-038 | REQ_UDS_0072 | ||
| SSR-SW-0187 | SW | Functional | QM | Low | Test | The ECA shall store each changed data value into non-volatile memory in a valid state no later than the completion of an ECUReset service 0x11 subFunction 0x02 requested by the client. | N-SW-038 | REQ_UDS_0091 | ||
| SSR-SW-0188 | SW | Functional | QM | High | Test | The ECA shall support the forced transfer of buffered data into non-volatile memory both by an ECUReset service with subFunction 0x02 and by an ignition-key power cycle. | N-SW-038 | REQ_UDS_0092 | ||
| SSR-SW-0189 | SW | Functional | QM | Low | Test | The ECA shall define the MemoryAddress parameter in accordance with ISO 14229-1. | N-SW-039 | REQ_UDS_0291 | ||
| SSR-SW-0190 | SW | Functional | QM | Low | Test | The ECA shall define the MemorySize parameter in accordance with ISO 14229-1. | N-SW-039 | REQ_UDS_0292 | ||
| SSR-SW-0191 | SW | Functional | QM | Low | Test | The ECA shall define the MemoryAddress parameter in accordance with ISO 14229-1. | N-SW-039 | REQ_UDS_0296 | ||
| SSR-SW-0192 | SW | Functional | QM | Low | Test | The ECA shall define the MemorySize parameter in accordance with ISO 14229-1. | N-SW-039 | REQ_UDS_0297 | ||
| SSR-SW-0193 | needs clarification | SW | Functional | QM | Low | Test | The ECA shall support physical memory range erase in accordance with ISO 14229-1 Table H1. | N-SW-039 | CR-SW-0157 | CLARIFY: The source is a fragment of a table (module/index and memory-erase mapping with a legend 'M = Mandatory', 'C = Mandatory if required to meet the performance requirements') and cannot be parsed into a single requirement. Please provide the intended obligation and the complete table.; The module-to-index / memory-erase mapping is provided only as a table fragment (e.g. Module 2 Application SW, range 0x02-0xFF) and is not fully specified in the source. |
| SSR-SW-0194 | split | SW | Functional | QM | Low | Test | When the addressAndLengthFormatIdentifier is set to 0x01, the ECA shall apply the defined module-to-index mapping for the memoryStartAddress. | N-SW-039 | REQ_UDS_0166 | The module-to-index mapping is truncated in the source at index 4 ('4 ...'); index values from 4 onward are not provided. |
| SSR-SW-0194-2 | split | SW | Functional | QM | Low | Test | The ECA shall map memoryStartAddress index 1 to the Boot loader, index 2 to the Application and index 3 to the Application Data. | N-SW-039 | REQ_UDS_0166 | |
| SSR-HW-0047 | split | HW | Design constraint | QM | Low | Test | When the triggering condition (TBD) is met, the ECA shall perform the required checks or reorganization measures for the data structures. | N-HW-014 | CR-HW-0030 | The triggering condition is referenced only as 'If so' and its antecedent is not provided in the source.; The data structures were given as an open-ended example list (EEPROM data, operational data, adaptive data, ...) and are not exhaustively defined.; The stored DIDs were followed by 'etc.'; the complete set beyond F1AB, F1AA, F1A9 is not provided. |
| SSR-HW-0047-2 | split | HW | Design constraint | QM | Low | Test | When the triggering condition (TBD) is met, the ECA shall execute the self-test. | N-HW-014 | CR-HW-0030 | |
| SSR-HW-0047-3 | split | HW | Design constraint | QM | Low | Test | When the triggering condition (TBD) is met, the ECA shall store the event memory entries, the default values and the DIDs F1AB, F1AA and F1A9. | N-HW-014 | CR-HW-0030 | |
| SSR-HW-0048 | HW | Design constraint | QM | Low | Test | The ECA shall support downgrading of the software modules while the programmed modules are compatible with each other and with the hardware configuration. | N-HW-015 | CR-HW-0032 | ||
| SSR-SYS-0371 | split | SYS | Design constraint | QM | Low | Review | When the ECA is restarted for any reason, or is returned to the DefaultSession due to a lack of TesterPresent or unfulfilled preconditions, the ECA shall support programming from the start of the programming sequence at programming step P1Pre. | N-SYS-074 | CR-SYS-0195 | |
| SSR-SYS-0371-2 | split | SYS | Design constraint | QM | Low | Review | When the ECA is restarted for any reason, or is returned to the DefaultSession due to a lack of TesterPresent or unfulfilled preconditions, the ECA shall remain independent of any state from an interrupted programming sequence. | N-SYS-074 | CR-SYS-0195 | |
| SSR-SYS-0372 | SYS | Design constraint | QM | Low | Test | The ECA shall support the specified session transitions when requested by either physical or functional addressing. | N-SYS-074 | REQ_UDS_0338 | The set of session transitions ('stated below') is referenced but not included in the source. | |
| SSR-SYS-0373 | SYS | Design constraint | QM | Low | Test | When a request to switch to the ProgrammingSession has been accepted, the ECA shall complete the preparations required to perform the programming operation. | N-SYS-074 | REQ_UDS_0059 | The specific preparations required for reliable programming operation are not enumerated in the source ('all preparations to guarantee trouble-free programming operation'). | |
| SSR-SYS-0374 | SYS | Design constraint | QM | Low | Test | When switching to the Programming session, the ECA shall send the positive response before performing the actual session switch. | N-SYS-074 | REQ_UDS_0061 | ||
| SSR-SYS-0375 | SYS | Design constraint | QM | Low | Test | The ECA shall generate the sessionKey in accordance with the specified pseudo code. | N-SYS-074 | CR-SYS-0347 | The pseudo code defining sessionKey generation is referenced ('pseudo code below') but not included in the source. | |
| SSR-SYS-0376 | SYS | Design constraint | QM | Low | Test | The ECA shall use the sessionKey exclusively for the application responsible for communication over securedDataTransmission. | N-SYS-074 | CR-SYS-0348 | ||
| SSR-SW-0195 | SW | Functional | QM | Low | Test | If a non-permitted service is requested after the RequestDownload service has started and before the RequestTransferExit service has been called, then the ECA shall respond with negative response code 0x24. | N-SW-040 | CR-SW-0038 | ||
| SSR-SW-0196 | split | SW | Functional | QM | Low | Test | While erasing memory, the ECA shall allow the client to start a data transfer using the TransferData service (0x36). | N-SW-040 | CR-SW-0052 | |
| SSR-SW-0196-2 | split | SW | Functional | QM | Low | Test | Where the ECA implements automatic erase, the ECA shall perform the memory erasing in parallel with the data transfer. | N-SW-040 | CR-SW-0052 | |
| SSR-SW-0197 | SW | Functional | QM | Low | Test | If a non-permitted service is requested after the RequestDownload service has started and before the RequestTransferExit service has been called, then the ECA shall respond with negative response code 0x12. | N-SW-040 | REQ_UDS_0111 | The NRC name is truncated in the source as '(sub'; 0x12 corresponds to subFunctionNotSupported in ISO 14229-1, to be confirmed. | |
| SSR-SW-0198 | SW | Functional | QM | Low | Test | When a RequestFileTransfer request specifies modeOfOperation 0x06 (ResumeFile), the ECA shall resume downloading the file defined in the filePathAndName parameter at the returned filePosition indicator. | N-SW-040 | CR-SW-0145 | The 'U' support-classification marker in the CVS124 table is not defined in the source; if it denotes an unsupported mode, applicability of this requirement to the ECA is to be confirmed. | |
| SSR-SW-0199 | SW | Functional | QM | Low | Test | After erasing memory, the ECA shall allow the client to start a data transfer using the TransferData (0x36) service. | N-SW-040 | REQ_UDS_0161 | ||
| SSR-SW-0200 | split | SW | Functional | QM | Low | Test | When the addressAndLengthFormatIdentifier parameter is set to a value greater than 0x00, the ECA shall reset the software and data identification DIDs to their default values. | N-SW-041 | CR-SW-0051 | |
| SSR-SW-0200-2 | split | SW | Functional | QM | Low | Test | When any part of the boot software is erased, the ECA shall reset DIDs 0xF180, 0xF191 and 0xF187 to their default values. | N-SW-041 | CR-SW-0051 | |
| SSR-SW-0201 | SW | Functional | QM | Low | Test | The ECA shall hash the receipt number together with the routineStatus routineResult parameter, in this respective order. | N-SW-041 | CR-SW-0057 | ||
| SSR-SW-0202 | SW | Functional | QM | Low | Test | The ECA shall return the signed hash in the routineResultProof parameter. | N-SW-041 | CR-SW-0058 | ||
| SSR-SW-0203 | SW | Functional | QM | Low | Test | When the ECUReset service is requested with requestParameter value 0x02 (keyOffOnReset), the ECA shall finish each server task before sending a positive response. | N-SW-041 | REQ_UDS_0071 | ||
| SSR-SW-0204 | SW | Functional | QM | Low | Test | The ECA shall format the resetType response parameter in accordance with ISO 14229-1. | N-SW-041 | REQ_UDS_0245 | ||
| SSR-SW-0205 | SW | Functional | QM | Low | Test | The ECA shall format the request message and its parameters in accordance with ISO 14229-1. | N-SW-041 | REQ_UDS_0249 | The specific diagnostic service to which this request format applies is not identified in the source line. | |
| SSR-SW-0206 | SW | Functional | QM | Low | Test | The ECA shall define the DataIdentifier parameter in accordance with ISO 14229-1. | N-SW-042 | REQ_UDS_0255 | ||
| SSR-SW-0207 | SW | Functional | QM | Low | Test | The ECA shall format the request message and its parameters in accordance with ISO 14229-1. | N-SW-042 | REQ_UDS_0258 | The specific diagnostic service to which this request format applies is not identified in the source line (distinct from REQ_UDS_0249). | |
| SSR-SW-0208 | SW | Functional | QM | Low | Test | The ECA shall format the FunctionalGroupIdentifier response parameter in accordance with ISO 14229-1. | N-SW-042 | REQ_UDS_0269 | ||
| SSR-SW-0209 | SW | Functional | QM | Low | Test | The ECA shall format the FunctionalGroupIdentifier response parameter in accordance with ISO 14229-1. | N-SW-042 | REQ_UDS_0278 | Applies to a different service context than REQ_UDS_0269; the specific service is not identified in the source line. | |
| SSR-SW-0210 | SW | Functional | QM | Low | Test | The ECA shall format the ControlEnableMaskRecord parameter in accordance with ISO 14229-1. | N-SW-042 | REQ_UDS_0284 | ||
| SSR-SW-0211 | SW | Functional | QM | Low | Test | The ECA shall format the routineIdentifier request parameter in accordance with ISO 14229-1. | N-SW-042 | REQ_UDS_0106 | ||
| SSR-SW-0212 | SW | Functional | QM | Low | Test | The ECA shall define the data parameter in accordance with ISO 14229-1. | N-SW-043 | REQ_UDS_0126 | The specific service and 'data' parameter to which this definition applies are not identified in the source line. | |
| SSR-SW-0213 | SW | Functional | QM | Low | Test | When a RequestFileTransfer request specifies modeOfOperation 0x04 (ReadFile), the ECA shall read the file at the location defined by the filePathAndName parameter. | N-SW-043 | CR-SW-0143 | ||
| SSR-SW-0214 | SW | Functional | QM | Low | Test | When a RequestFileTransfer request specifies modeOfOperation 0x05 (ReadDir), the ECA shall read the directory defined in the filePathAndName parameter. | N-SW-043 | CR-SW-0144 | The 'U' support-classification marker in the CVS124 table is not defined in the source; if it denotes an unsupported mode, applicability of this requirement to the ECA is to be confirmed. | |
| SSR-SW-0215 | SW | Functional | QM | Low | Test | The ECA shall format the sub-function parameter in accordance with ISO 14229-1. | N-SW-043 | REQ_UDS_0142 | ||
| SSR-SW-0216 | SW | Functional | QM | Low | Test | When the addressAndLengthFormatIdentifier parameter is set to a value greater than 0x00, the ECA shall reset the software and data identification DIDs to their default values. | N-SW-043 | REQ_UDS_0160 | The specific list of software and data identification DIDs to reset was truncated in the source ('...(see'); the enumerated DID set is to be confirmed (see also CR-SW-0051). | |
| SSR-SW-0217 | SW | Design constraint | QM | Low | Review | When the vehicle mileage signal is first received with a good signal status after a software update, the ECA shall report through the DID a snapshot of the vehicle mileage as received on CAN or another ECU-external source. | N-SW-044 | REQ_UDS_0029 | The specific DID identifier referred to by 'This DID' is not given in the source line. | |
| SSR-SW-0218 | split | SW | Functional | QM | Low | Test | Before executing a diagnostics service, the ECA shall verify that the vehicle speed is approximately 0, the gear box is in neutral, and the parking brake is engaged. | N-SW-045 | CR-SW-0074 | The tolerance for 'approximately 0' (vehicle speed and engine speed) is not quantified in the source (TBD). |
| SSR-SW-0218-2 | split | SW | Functional | QM | Low | Test | Where the vehicle has an internal-combustion engine, the ECA shall additionally verify that the engine speed is approximately 0 before executing a diagnostics service. | N-SW-045 | CR-SW-0074 | |
| SSR-SW-0218-3 | split | SW | Functional | QM | Low | Test | Where the vehicle has a high-voltage battery system, the ECA shall additionally verify that the high-voltage system is disengaged before executing a diagnostics service. | N-SW-045 | CR-SW-0074 | |
| SSR-SW-0219 | SW | Functional | QM | Low | Test | When the ECUReset service is requested with requestParameter value 0x01 (hardReset), the ECA shall simulate the power-on or start-up sequence performed after the ECA has been disconnected from its power supply. | N-SW-045 | REQ_UDS_0069 | ||
| SSR-SW-0220 | SW | Functional | QM | Low | Test | If a service request is denied due to insufficient rights according to the RBACC check, the ECA shall respond with negative response code 0x22 (conditionsNotCorrect). | N-SW-046 | REQ_UDS_0342 | ||
| SSR-SW-0221 | needs clarification | SW | Functional | QM | Medium | Test | The ECA shall implement Role-Based Access Control (RBAC) for diagnostics in accordance with CVS151. | N-SW-046 | CR-SW-0184 | CLARIFY: This source line is CVS151 foreword/document-scope boilerplate ('This Commercial Vehicle Standard contains requirement specifications for TRATON Group...') and contains no ECA obligation. Is a requirement intended here, and if so, is it that the ECA shall implement diagnostics RBAC in accordance with CVS151? |
| SSR-SW-0222 | SW | Functional | QM | Highest | Test | The ECA shall provide Role-Based Access Control (RBAC) for diagnostics accessed over UDS. | N-SW-046 | CR-SW-0185 | ||
| SSR-SW-0223 | SW | Functional | QM | Medium | Review | Before executing a diagnostics service that is under RBAC, the ECA shall require the requesting client to have completed an authorization procedure. | N-SW-046 | CR-SW-0186 | ||
| SSR-SW-0224 | SW | Functional | QM | Low | Review | The ECA shall report the version of the currently stored RBACC via diagnostics. | N-SW-046 | CR-SW-0188 | ||
| SSR-SW-0225 | SW | Functional | QM | Low | Review | The ECA shall report the rbacc-id of the currently stored RBACC via diagnostics. | N-SW-046 | CR-SW-0189 | ||
| SSR-SW-0226 | SW | Functional | QM | Medium | Test | The ECA shall allow reception of UDS Authentication (0x29) requests regardless of the RBACC settings. | N-SW-047 | CR-SW-0195 | ||
| SSR-SW-0227 | SW | Functional | QM | Low | Test | The ECA shall accept a UDS Authentication (0x29) request regardless of whether the RBACC contains a corresponding matching rule. | N-SW-047 | CR-SW-0196 | ||
| SSR-SW-0228 | SW | Functional | QM | Medium | Review | When the ECA receives a UDS SecuredDataTransmission (0x84) request, the ECA shall evaluate the reported internal service against the RBACC rules. | N-SW-047 | CR-SW-0197 | ||
| SSR-SW-0229 | SW | Functional | QM | Medium | Test | The ECA shall allow reception of UDS SecuredDataTransmission (0x84) requests regardless of the RBACC settings. | N-SW-047 | CR-SW-0198 | ||
| SSR-SW-0230 | split | SW | Functional | QM | Low | Test | The ECA shall accept a UDS SecuredDataTransmission (0x84) request regardless of whether the RBACC contains a corresponding matching rule. | N-SW-047 | CR-SW-0199 | |
| SSR-SW-0230-2 | split | SW | Functional | QM | Low | Test | Before executing the internal request contained in a UDS SecuredDataTransmission (0x84) request, the ECA shall find a corresponding matching rule for that internal request in the RBACC. | N-SW-047 | CR-SW-0199 | |
| SSR-SW-0231 | SW | Functional | QM | Medium | Test | The ECA shall allow reception of UDS TesterPresent (0x3E) requests regardless of the RBACC settings. | N-SW-047 | CR-SW-0200 | ||
| SSR-SW-0232 | SW | Functional | QM | Low | Test | The ECA shall accept a UDS TesterPresent (0x3E) request regardless of whether the RBACC contains a corresponding matching rule. | N-SW-048 | CR-SW-0201 | ||
| SSR-SW-0233 | split | SW | Functional | QM | Low | Test | When entering the programming session, the ECA shall end each routine and function that influences programming. | N-SW-049 | CR-SW-0081 | The precise trigger 'this process' is inferred to be entry into the programming session (DiagnosticSessionControl to ProgrammingSession) from context; the customer text does not state it explicitly. |
| SSR-SW-0233-2 | split | SW | Functional | QM | Low | Test | When entering the programming session, the ECA shall check the safe-state conditions as a minimum. | N-SW-049 | CR-SW-0081 | |
| SSR-SW-0234 | SW | Functional | QM | High | Test | Where the ECA provides gateway server functionality, when the ECA receives a CommunicationControl service request, the ECA shall quiet down the network towards ECUs that have no diagnostic server and are present in its sub-buses. | N-SW-050 | REQ_UDS_0076 | Whether the ECA provides gateway server functionality with sub-buses is to be confirmed for project P112478. | |
| SSR-FUSA-0006 | FUSA | Functional | QM | Medium | Test | Before accepting a request to disable communication, the ECA shall verify that the applicable safety conditions are met. | N-FUSA-003 | REQ_UDS_0077 | The applicable safety conditions are project-specific and are not enumerated in the source (TBD for project P112478). | |
| SSR-SYS-0377 | SYS | Design constraint | QM | Low | Test | The ECA shall map authentication error cases to the corresponding negative response codes (NRCs) in accordance with the Authentication service implementation specification CVS31. | N-SYS-075 | REQ_UDS_0139 | ||
| SSR-SYS-0378 | SYS | Design constraint | QM | Low | Review | If an authentication pending state already exists, the ECA shall replace the existing authentication pending state with the newly established one. | N-SYS-075 | CR-SYS-0331 | Source sentence was truncated ('...replace the existing'); the object was completed by analogy to CR-SYS-0336 (active authentication state). | |
| SSR-SYS-0379 | SYS | Design constraint | QM | Low | Review | When the ECA sends a positive response, the ECA shall start the Authentication completion timer. | N-SYS-075 | CR-SYS-0333 | ||
| SSR-SYS-0380 | SYS | Design constraint | QM | Low | Test | The ECA shall generate the challengeServer field as 32 octets using a cryptographic random number generator (CRNG). | N-SYS-075 | CR-SYS-0334 | ||
| SSR-SYS-0381 | SYS | Design constraint | QM | Low | Review | If the ECA fails to store the authentication state or cannot determine that it was stored, the ECA shall delete the authentication pending state connected to the client that submitted the proofOfOwnership request. | N-SYS-075 | CR-SYS-0335 | ||
| SSR-SYS-0382 | SYS | Design constraint | QM | Low | Review | If an active authentication state already exists, the ECA shall replace the existing state with the newly established one. | N-SYS-075 | CR-SYS-0336 | ||
| SSR-SYS-0383 | SYS | Design constraint | QM | Low | Review | Before sending a positive response to the deAuthenticate request, the ECA shall delete or invalidate the client's authentication. | N-SYS-076 | CR-SYS-0338 | ||
| SSR-SYS-0384 | SYS | Design constraint | QM | Low | Review | The ECA shall include in its authentication pending state at least the address of the client that issued the authentication request. | N-SYS-076 | CR-SYS-0343 | The source list of pending-state contents is explicitly non-exhaustive; the full set of required fields is not enumerated. | |
| SSR-SYS-0385 | SYS | Design constraint | QM | Low | Review | The ECA shall include in its authentication state at least the SessionKey. | N-SYS-076 | CR-SYS-0344 | The source list of authentication-state contents is explicitly non-exhaustive; the full set of required fields is not enumerated. | |
| SSR-SYS-0386 | SYS | Design constraint | QM | Low | Review | The ECA shall support only one authentication state. | N-SYS-076 | CR-SYS-0345 | ||
| SSR-SYS-0387 | SYS | Design constraint | QM | Low | Review | The ECA shall support only one authentication pending state. | N-SYS-076 | CR-SYS-0346 | ||
| SSR-SYS-0388 | SYS | Design constraint | QM | Low | Test | The ECA shall support only passive time-based de-authentication. | N-SYS-076 | CR-SYS-0350 | ||
| SSR-SYS-0389 | SYS | Design constraint | QM | Low | Review | If the A3 timer times out before a new request from the same client is received, the ECA shall invalidate the authentication state. | N-SYS-077 | CR-SYS-0353 | ||
| SSR-SYS-0390 | SYS | Design constraint | QM | Low | Review | The ECA supplier shall define the passive timeout-based de-authentication parameter within the project. | N-SYS-077 | CR-SYS-0354 | Value of the passive timeout-based de-authentication parameter is TBD, to be decided within the project. | |
| SSR-SYS-0391 | SYS | Design constraint | QM | Low | Review | If the ECA can determine that a delay is not running after reset, the ECA shall accept a subsequent authentication request without delay. | N-SYS-077 | CR-SYS-0357 | ||
| SSR-SYS-0392 | SYS | Design constraint | QM | Low | Review | If the ECA cannot determine that a delay is not running after reset, the ECA shall accept a subsequent authentication request only after the delay has elapsed. | N-SYS-077 | CR-SYS-0358 | ||
| SSR-SYS-0393 | SYS | Design constraint | QM | Low | Test | The ECA shall set the Authentication completion timer to 1 minute. | N-SYS-077 | CR-SYS-0359 | ||
| SSR-SYS-0394 | needs clarification | SYS | Design constraint | QM | Low | Test | The ECA shall support more than one authentication state. | N-SYS-077 | CR-SYS-0364 | CLARIFY: The source text '(There may be more than one authentication state)' is an informational note, not an obligation. What is the intended requirement on the ECA - must it maintain multiple concurrent authentication states, how many, and under what conditions?; The number of authentication states to support and the conditions under which multiple states apply are not specified. |
| SSR-SYS-0395 | needs clarification | SYS | Design constraint | QM | Low | Test | The client shall authenticate the SDT request with the A argument set to the specified octet string. | N-SYS-078 | CR-SYS-0384 | CLARIFY: The customer statement is truncated after 'set to the octet string'. Which octet string shall the A argument be set to for the SDT request (for example, the concatenation of the SDT request protocol elements excluding SIGMACBYTE)?; Definition of the octet string to which the A argument is set for the SDT request is missing (customer statement ends at 'set to the octet string'). |
| SSR-SYS-0396 | SYS | Design constraint | QM | Low | Review | The ECA shall authenticate the SDT response with the A argument set to the octet string that comprises the protocol elements of the SDT response other than the SIGMACBYTE protocol element, concatenated with the octet string carried by the SIGMACBYTE protocol element of the corresponding request. | N-SYS-078 | CR-SYS-0390 | ||
| SSR-SYS-0397 | needs clarification | SYS | Design constraint | QM | Low | Test | When an SDT response is received and the client is unauthenticated, the client shall discard the SDT response. | N-SYS-078 | CR-SYS-0394 | CLARIFY: The customer statement is truncated after 'the client shall discard the'. What exactly shall the unauthenticated client discard upon reception of an SDT response (for example, the SDT response itself)?; The object the client shall discard is not stated (customer statement ends at 'discard the'). |
| SSR-FUSA-0007 | FUSA | Functional | QM | Low | Review | The ECA supplier shall include the Diag safe state conditions in the preconditions agreed with the vehicle manufacturer. | N-FUSA-004 | CR-FUSA-0007 | The complete set of preconditions is TBD, pending discussion with the vehicle manufacturer; only the Diag safe state conditions are confirmed. | |
| SSR-CYBER-0146 | CYBER | Design constraint | QM | Low | Test | If conflicting or overlapping rules are found within a role-configuration, the ECA shall enforce that the deny rule takes precedence over the allow rule. | N-CYBER-032 | CR-CYBER-0067 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-CYBER-0147 | CYBER | Design constraint | QM | Low | Test | The ECA shall evaluate each role-configuration independently. | N-CYBER-032 | CR-CYBER-0070 | ||
| SSR-CYBER-0148 | CYBER | Design constraint | QM | Low | Test | The ECA shall support role-configurations using a 32-bit unsigned integer. | N-CYBER-032 | CR-CYBER-0074 | ||
| SSR-SW-0235 | SW | Functional | QM | High | Test | The ECA shall exert the RBACC roles based on the ECU-diagnostics-Role extension in the client's certificate. | N-SW-051 | CR-SW-0191 | ||
| SSR-SW-0236 | SW | Functional | QM | Low | Test | The ECA shall accept lengthOfCertificateClient values within the range from 0x00C8 to 0x0800. | N-SW-051 | CR-SW-0206 | ||
| SSR-SW-0237 | SW | Functional | QM | Low | Test | If the lengthOfCertificateClient value is outside the expected range, the ECA shall send negative response code 0x13 indicating incorrectMessageLengthOrInvalidFormat. | N-SW-051 | CR-SW-0207 | quantitative target implied but not stated by the customer; to be defined at SYS.2 (TBD) | |
| SSR-SW-0238 | SW | Functional | QM | Low | Test | When a verifyCertificateBidirectional request is received while the Authentication delay timer is running, the ECA shall respond with negative response code 0x37 indicating requiredTimeDelayNotExpired. | N-SW-051 | CR-SW-0208 | ||
| SSR-SW-0239 | SW | Functional | QM | High | Test | If the ECA verifies the client certificate as invalid, the ECA shall respond to the verifyCertificateBidirectional request with negative response code 0x10 indicating generalReject. | N-SW-051 | CR-SW-0209 | ||
| SSR-SW-0240 | SW | Functional | QM | Low | Test | If the ECA fails to store the authentication pending state or cannot determine whether the authentication pending state was stored, the ECA shall respond to the verifyCertificateBidirectional request with negative response code 0x94 indicating ResourceTemporarilyNotAvailable. | N-SW-051 | CR-SW-0210 | ||
| SSR-SW-0241 | split | SW | Functional | QM | High | Test | If the ECA NodeUID is absent from the NodeUID extension, the ECA shall reject the certificate. | N-SW-052 | CR-SW-0221 | |
| SSR-SW-0241-2 | split | SW | Functional | QM | High | Test | If the ECA NodeUID is absent from the NodeUID extension, the ECA shall generate negative response code 0x10 indicating generalReject. | N-SW-052 | CR-SW-0221 | |
| SSR-SW-0242 | SW | Functional | QM | High | Test | The client certificate shall include the ECU-Diagnostic role extension. | N-SW-052 | CR-SW-0222 | ||
| SSR-SW-0243 | SW | Functional | QM | Low | Test | Where a D-RBACC extension is present in the client certificate, the ECA shall apply the additional permissions and the restrictions specified by the D-RBACC extension in addition to the permissions derived from the client's roles. | N-SW-052 | CR-SW-0223 | ||
| SSR-SW-0244 | SW | Functional | QM | High | Test | If the certificate content is invalid, the ECA shall return negative response code 0x10 indicating generalReject. | N-SW-052 | CR-SW-0224 | ||
| SSR-SW-0245 | SW | Functional | QM | High | Test | If the certificate is non-compliant, the ECA shall return negative response code 0x10 indicating generalReject. | N-SW-052 | CR-SW-0225 | ||
| SSR-SW-0246 | needs clarification | SW | Functional | QM | Low | Test | Where the evaluate pattern applies, the ECA shall set the Confidentiality rule setting to 0x01, requiring confidentiality. | N-SW-053 | CR-SW-0192 | CLARIFY: The source is introduced with 'E.g:', indicating an illustrative example. Is it a normative requirement that, for the evaluate pattern, the Confidentiality rule setting must be 0x01 (confidentiality required), or is it only an example of a possible rule setting? |
| SSR-SW-0247 | SW | Functional | QM | Low | Test | When an SDT request is received and the ECA does not support SIGENCRYPT, the ECA shall respond with an SDT negative response using negative response code 0x3A. | N-SW-053 | CR-SW-0248 | ||
| SSR-SW-0248 | SW | Functional | QM | Low | Test | When an SDT request is received and APAR is in conflict with SIGENCRYPT, the ECA shall respond with an SDT negative response using negative response code 0x3A. | N-SW-053 | CR-SW-0249 | ||
| SSR-SW-0249 | SW | Functional | QM | Low | Test | When an SDT request is received and SIGLEN is in conflict with SIGENCRYPT, the ECA shall respond with an SDT negative response using negative response code 0x3A. | N-SW-053 | CR-SW-0250 | ||
| SSR-CYBER-0149 | CYBER | Design constraint | QM | Low | Test | The ECA shall allow each request contained in the role 0 rules regardless of the client authentication state. | N-CYBER-033 | CR-CYBER-0081 | ||
| SSR-CYBER-0150 | CYBER | Design constraint | QM | Low | Test | If the client's proofOfOwnership signature is successfully verified, the ECA shall establish a new authentication state for the client. | N-CYBER-033 | CR-CYBER-0102 | ||
| SSR-CYBER-0151 | CYBER | Design constraint | QM | Low | Test | If verification of the client proofOfOwnership signature fails, the ECA shall delete the authentication pending state connected to the client that submitted the proofOfOwnership request. | N-CYBER-033 | CR-CYBER-0103 | ||
| SSR-CYBER-0152 | CYBER | Design constraint | QM | Low | Test | If the client's proofOfOwnership signature is successfully verified, the ECA shall establish a new authentication state for the client. | N-CYBER-033 | CR-CYBER-0104 | ||
| SSR-CYBER-0153 | CYBER | Design constraint | QM | Low | Test | The ECA shall use the ED25519 signature algorithm throughout the authentication process. | N-CYBER-033 | CR-CYBER-0106 | ||
| SSR-SYS-0398 | SYS | Design constraint | QM | Low | Test | While the client performs the ReadDataByIdentifier read operation, if the conditions and rules for each DID aliased by the dynamically defined identifier are not met, the ECA shall reject the request with the applicable negative response code. | N-SYS-079 | CR-SYS-0302 | The specific negative response code for rejection is not defined (source says 'an appropriate NRC'). | |
| SSR-SW-0250 | split | SW | Functional | QM | Low | Review | The ECA supplier shall document each deviation from this specification. | N-SW-054 | 1.1 | |
| SSR-SW-0250-2 | split | SW | Functional | QM | Low | Review | The ECA supplier shall submit each documented deviation from this specification to the vehicle manufacturer for review. | N-SW-054 | 1.1 | |
| SSR-SW-0250-3 | split | SW | Functional | QM | Low | Review | The ECA shall support only the APCE security concept of the Authentication (0x29) service specified in ISO 14229-1:2020. | N-SW-054 | 1.1 | |
| SSR-SW-0250-4 | split | SW | Functional | QM | Low | Review | Where a requirement in this specification or in the Traton UDS specification CVS124 conflicts with ISO 14229-1:2020, the ECA supplier shall implement the requirement in this specification or CVS124. | N-SW-054 | 1.1 | |
| SSR-HW-0049 | HW | Design constraint | QM | Low | Test | If an existing authentication pending state is found, the ECA shall verify whether the Authentication completion timer is currently running. | N-HW-016 | CR-HW-0049 | ||
| SSR-HW-0050 | HW | Design constraint | QM | Low | Test | While the Authentication completion timer is running, the ECA shall continue processing the client's proofOfOwnership request. | N-HW-016 | CR-HW-0050 | ||
| SSR-HW-0051 | HW | Design constraint | QM | Low | Test | If a client and the ECA have completed the authentication process successfully, the ECA shall invalidate the authentication state when the ECA is reset by a power cycle. | N-HW-016 | CR-HW-0051 | Source lists invalidation events under 'in the event of:' but presents only the power-cycle reset event; any further invalidation events are not captured in the source. | |
| SSR-SW-0251 | SW | Functional | QM | Low | Test | The ECA shall set the ikm argument of the HKDF function to the octet string containing the SecuredDataTransmissionKey from the service 0x29 authentication state. | N-SW-055 | CR-SW-0236 | ||
| SSR-SW-0252 | SW | Functional | QM | Low | Test | The ECA shall set the info argument of the HKDF function to the concatenation of the "SDT_0x84_KEY" octet string and the CipherScheme identifier. | N-SW-055 | CR-SW-0237 |
Jira import (ready)
Field mapping matches the P112478 requirement template (custom-field IDs). Reporter/Quality Reviewer carry the ${JIRA_DEFAULT_REPORTER} token; Due Date = 2026-07-31. The customer file keeps the verbatim statement in Description plus reference columns (GtWR verdict, violated rules, GtWR-compliant rewrite). The SSR file uses Requirements/Test Level = System (SYS.2,5), complete Summary, Status, clarification and traceability columns.
| File | Rows | Purpose | Download |
|---|---|---|---|
| Customer requirements — Jira import | 918 | Verbatim + GtWR rewrite | customer_requirements_jira_import.csv |
| System requirements (SSR) — Jira import | 1077 | Authored + verified, traceable | system_requirements_jira_import.csv |
| Customer GtWR compliance matrix | 918 | Per-item verdicts | compliance_customer.csv |
| SSR GtWR compliance matrix | 1077 | Per-item verdicts | compliance_ssr.csv |
| Validation checklist | — | INCOSE gate record | validation_checklist.md |