Traceability Matrix

End-to-end coverage from customer requirement to system requirement, design item, estimation, and Jira candidate.

Last updated: 2026-06-29 11:49
RTRFQX Review TeamWorkspace

Traceability Matrix

End-to-end coverage from customer requirement to system requirement, design item, estimation, and Jira candidate.

Traceability Rows1789customer requirement led
Complete916end-to-end linked
Incomplete / Review873needs engineering action
Status Types6filterable
Blocked by Customer Decision208clarification gate
Security Review Open442weak-area impact
Missing Clarification Evidence0closure evidence

Traceability Decision Impact

Downstream engineering artifacts remain provisional until customer clarification closure evidence is complete.

BLOCKED BY CUSTOMER DECISIONP1 OPENSECURITY REVIEW OPENNO AUTO CLOSURE
472open clarification questions
6P1 decisions
0answered by additional PDFs
6security weak areas

Open Customer Decisions & Clarifications

Search and Filters

End-to-End Traceability Matrix

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Customer Requirement IDCustomer Requirement Statement / Short TitleSystem Requirement ID(s)System Requirement Short TitleArchitecture / Design Item ID(s)Design TypeEstimation ID / EffortJira Issue KeyClarification StatusP1 Decision StatusSecurity Weak AreaEvidence StatusCoverage Status
RFQX-1001379436-P10-000-01-0001Summary
Statement

This document contains general cybersecurity requirements. The requirements specified in this document are applicable to all ECUs. The supplier of ECU is responsible to take all the necessary measures and steps to comply with the requirements listed in this document.

NoneNoneNoneNoneRFQX-1001379436-P10-000-01-0001 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-1001379436-P10-000-01-0002Target reader
Statement

The target readers of this specification are ECU suppliers, which can be either internal or external in relation to the vehicle manufacturer. In both cases, whenever the term “ECU supplier” or just “supplier” is used in this specification it refers to the company and organization which is responsible for the implementation and delivery of the ECU according to the requirements in this specification. And in both cases, whenever the term “vehicle manufacturer” is used in this specification this term refers to the system owner (responsible receiver) at the vehicle manufacturer.

NoneNoneNoneNoneRFQX-1001379436-P10-000-01-0002 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-1001379436-P10-000-01-0003Definition of terms
Statement

Term Definition Shall This word, or the term "Required", means that the definition is an absolute requirement of the specification. Threat Analysis and Risk Assessment A structured approach to identify possible threats and evaluate risks with respect to the potential damages and the effort needed for successful attack. Cybersecurity concept A cybersecurity concept is a work product that documents cybersecurity relevant aspects of the product. The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybe rsecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc. Table 1: Definition of terms

NoneNoneAD-007componentRFQX-1001379436-P10-000-01-0003 / 18hNot importedStill Requires Customer DecisionP1 OPENboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-1001379436-P10-000-01-0004Abbreviated terms
Statement

Abbreviation Description ECU Electronic Control Unit Table 2: Abbreviated terms

NoneNoneNoneNoneRFQX-1001379436-P10-000-01-0004 / 56hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-1001379436-P10-000-01-0005The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybe rsecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc.
Statement

The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybe rsecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc.

NoneNoneAD-007componentRFQX-1001379436-P10-000-01-0005 / 56hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-1001379436-P10-000-01-0006Cybersecurity principles are high level requirements that drive development and refinement of functional and technical cybersecurity requirements.
Statement

Cybersecurity principles are high level requirements that drive development and refinement of functional and technical cybersecurity requirements.

NoneNoneNoneNoneRFQX-1001379436-P10-000-01-0006 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-1001379436-P10-000-01-0007The supplier shall provide documentation describing their strategies and methods for working with embedded systems cybersecurity.
Statement

The supplier shall provide documentation describing their strategies and methods for working with embedded systems cybersecurity.

SSR-CON-001Security evidence and traceability — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0007 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0008The supplier shall perform risk assessment based on a threat and vulnerability analysis for each release, including any vehicle manufacturer-specific adaptations.
Statement

The supplier shall perform risk assessment based on a threat and vulnerability analysis for each release, including any vehicle manufacturer-specific adaptations.

SSR-VIH-001Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-007componentRFQX-1001379436-P10-000-01-0008 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0009Method and scope shall be proposed to and approved by the vehicle manufacturer.
Statement

Method and scope shall be proposed to and approved by the vehicle manufacturer.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0009 / 24hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0010Documentation on the method and results shall be provided to the vehicle manufacturer.
Statement

Documentation on the method and results shall be provided to the vehicle manufacturer.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0010 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0011Note: The vehicle manufacturer and supplier shall collaboratively define the context of the system or function to enable the supplier performing the risk assessment.
Statement

Note: The vehicle manufacturer and supplier shall collaboratively define the context of the system or function to enable the supplier performing the risk assessment.

NoneNoneAD-001componentRFQX-1001379436-P10-000-01-0011 / 24hNot importedStill Requires Customer DecisionP1 OPENboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0012The supplier shall describe the cybersecurity concept and how it is implemented in hardware and software respectively.
Statement

The supplier shall describe the cybersecurity concept and how it is implemented in hardware and software respectively.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0012 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0013All risks identified in cybersecurity risk analyses shall be evaluated.
Statement

All risks identified in cybersecurity risk analyses shall be evaluated.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0013 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-1001379436-P10-000-01-0014For each risk identified in the cybersecurity risk analyses, a risk treatment decision shall be made to avoid, reduce, share, or retain the risk.
Statement

For each risk identified in the cybersecurity risk analyses, a risk treatment decision shall be made to avoid, reduce, share, or retain the risk.

NoneNoneAD-007componentRFQX-1001379436-P10-000-01-0014 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0015Cybersecurity controls shall sufficiently reduce the risk.
Statement

Cybersecurity controls shall sufficiently reduce the risk.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0015 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-1001379436-P10-000-01-0016It shall be possible to verify which cybersecurity controls were derived from which requirements.
Statement

It shall be possible to verify which cybersecurity controls were derived from which requirements.

NoneNoneAD-007componentRFQX-1001379436-P10-000-01-0016 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0017The cybersecurity concept of the supplier shall contain a documentation of the accepted residual risk and be agreed with the vehicle manufacturer.
Statement

The cybersecurity concept of the supplier shall contain a documentation of the accepted residual risk and be agreed with the vehicle manufacturer.

SSR-CON-001Security evidence and traceability — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0017 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0018The supplier shall provide documentation of the verification and validation methods of cybersecurity features.
Statement

The supplier shall provide documentation of the verification and validation methods of cybersecurity features.

SSR-CON-001Security evidence and traceability — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0018 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0019The supplier shall provide test reports detailing the results from the verification and validation of cybersecurity features.
Statement

The supplier shall provide test reports detailing the results from the verification and validation of cybersecurity features.

SSR-CON-001Security evidence and traceability — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0019 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0020The vehicle manufacturer reserves the right to perform penetration testing on the ECU to identify potential vulnerabilities.
Statement

The vehicle manufacturer reserves the right to perform penetration testing on the ECU to identify potential vulnerabilities.

NoneNoneNoneNoneRFQX-1001379436-P10-000-01-0020 / 16hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-1001379436-P10-000-01-0021An inventory of software and protocols, including their versions, shall be provided by the supplier.
Statement

An inventory of software and protocols, including their versions, shall be provided by the supplier.

SSR-CON-003Security evidence and traceability — Cybersecurity Concept and EvidenceAD-001componentRFQX-1001379436-P10-000-01-0021 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0022A BOM containing part numbers and versions of hardware components used in the product shall be provided by the supplier.
Statement

A BOM containing part numbers and versions of hardware components used in the product shall be provided by the supplier.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-1001379436-P10-000-01-0022 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0023The vehicle manufacturer reserves the right to request documentation and evidence as well as to perform or order a compliance audit to determine whether the listed requirements are fulfilled.
Statement

The vehicle manufacturer reserves the right to request documentation and evidence as well as to perform or order a compliance audit to determine whether the listed requirements are fulfilled.

NoneNoneNoneNoneRFQX-1001379436-P10-000-01-0023 / 16hNot importedStill Requires Customer DecisionNo P1 linkevidence completenessMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-1001379436-P10-000-01-0024The vehicle manufacturer and the supplier shall set up a cybersecurity DIA to agree on the responsibilities for the distributed cybersecurity activities.
Statement

The vehicle manufacturer and the supplier shall set up a cybersecurity DIA to agree on the responsibilities for the distributed cybersecurity activities.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0024 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0025The ECU shall be able to verify integrity and authenticity of a vehicle manufacturer-specified set of data stored within the ECU.
Statement

The ECU shall be able to verify integrity and authenticity of a vehicle manufacturer-specified set of data stored within the ECU.

SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-007componentRFQX-1001379436-P10-000-01-0025 / 16hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0026Methods shall be proposed to and approved by the vehicle manufacturer.
Statement

Methods shall be proposed to and approved by the vehicle manufacturer.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0026 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0027The supplier shall apply methods for isolation of software/hardware components and data to reduce the effect in case of a cybersecurity breach.
Statement

The supplier shall apply methods for isolation of software/hardware components and data to reduce the effect in case of a cybersecurity breach.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0027 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0028Selection of cryptographic methods and their use shall be agreed upon between the vehicle manufacturer and the supplier.
Statement

Selection of cryptographic methods and their use shall be agreed upon between the vehicle manufacturer and the supplier.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0028 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0029All network services implemented in the ECU shall undergo hardening.
Statement

All network services implemented in the ECU shall undergo hardening.

SSR-PROD-001Supplier Development and Production Hardening — Supplier Development and Production HardeningAD-006componentRFQX-1001379436-P10-000-01-0029 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-1001379436-P10-000-01-0030The ECU shall only expose network and communication services that have been agreed upon with the vehicle manufacturer.
Statement

The ECU shall only expose network and communication services that have been agreed upon with the vehicle manufacturer.

SSR-COM-001OEM/Customer Review Interface — Secure Communication and Boundary ControlAD-006componentRFQX-1001379436-P10-000-01-0030 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0031Communication interfaces shall use boundary controls such as ingress/egress filtering.
Statement

Communication interfaces shall use boundary controls such as ingress/egress filtering.

SSR-COM-002Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-008componentRFQX-1001379436-P10-000-01-0031 / 16hNot importedNo linked clarificationNo P1 linkboundary ownershipNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0032Communication boundary controls shall be configurable by the vehicle manufacturer.
Statement

Communication boundary controls shall be configurable by the vehicle manufacturer.

SSR-COM-003OEM/Customer Review Interface — Secure Communication and Boundary ControlAD-008componentRFQX-1001379436-P10-000-01-0032 / 16hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0033Methods shall be proposed and approved by the vehicle manufacturer.
Statement

Methods shall be proposed and approved by the vehicle manufacturer.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0033 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0034Any interfaces used for development purposes shall be removed or disabled in series production.
Statement

Any interfaces used for development purposes shall be removed or disabled in series production.

SSR-COM-002Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-008componentRFQX-1001379436-P10-000-01-0034 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-1001379436-P10-000-01-0035The details shall be agreed upon between the vehicle manufacturer and the supplier.
Statement

The details shall be agreed upon between the vehicle manufacturer and the supplier.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0035 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0036Only hardware interfaces and protocols specified by the vehicle manufacturer shall be available in series production.
Statement

Only hardware interfaces and protocols specified by the vehicle manufacturer shall be available in series production.

SSR-COM-001OEM/Customer Review Interface — Secure Communication and Boundary ControlAD-006componentRFQX-1001379436-P10-000-01-0036 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0037It shall be possible for the vehicle manufacturer to securely inject data into the product in accordance with the specification provided by the vehicle manufacturer.
Statement

It shall be possible for the vehicle manufacturer to securely inject data into the product in accordance with the specification provided by the vehicle manufacturer.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0037 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0038Data specified by the vehicle manufacturer shall be protected from manipulations.
Statement

Data specified by the vehicle manufacturer shall be protected from manipulations.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0038 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0039Data specified by the vehicle manufacturer shall be protected from disclosure.
Statement

Data specified by the vehicle manufacturer shall be protected from disclosure.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0039 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0040Intellectual property of the vehicle manufacturer shall be protected from disclosure.
Statement

Intellectual property of the vehicle manufacturer shall be protected from disclosure.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0040 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0041It shall be possible for the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECU according to the specification of the vehicle manufacturer.
Statement

It shall be possible for the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECU according to the specification of the vehicle manufacturer.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-1001379436-P10-000-01-0041 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0042Secrets, public keys and other data used for cybersecurity controls in production vehicle systems shall be different from those used in pre-production phases.
Statement

Secrets, public keys and other data used for cybersecurity controls in production vehicle systems shall be different from those used in pre-production phases.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-1001379436-P10-000-01-0042 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0043ECUs shall only contain the secrets agreed between the vehicle manufacturer and the supplier.
Statement

ECUs shall only contain the secrets agreed between the vehicle manufacturer and the supplier.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0043 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0044ECUs shall conform to the harmonized Security Access specification [1] provided by the vehicle manufacturer.
Statement

ECUs shall conform to the harmonized Security Access specification [1] provided by the vehicle manufacturer.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0044 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0045It shall be possible to update the software of the ECU.
Statement

It shall be possible to update the software of the ECU.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0045 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0046The supplier shall inform the vehicle manufacturer if any cybersecurity patches are available.
Statement

The supplier shall inform the vehicle manufacturer if any cybersecurity patches are available.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-1001379436-P10-000-01-0046 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0047An incident response process shall be proposed to and approved by the vehicle manufacturer.
Statement

An incident response process shall be proposed to and approved by the vehicle manufacturer.

SSR-VIH-002Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-003componentRFQX-1001379436-P10-000-01-0047 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0048In case of cybersecurity incidents, the incident response process shall be used.
Statement

In case of cybersecurity incidents, the incident response process shall be used.

SSR-VIH-001Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-007componentRFQX-1001379436-P10-000-01-0048 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-1001379436-P10-000-01-0049The incident response process shall be maintained for the entire product lifetime.
Statement

The incident response process shall be maintained for the entire product lifetime.

SSR-VIH-002Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-003componentRFQX-1001379436-P10-000-01-0049 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-1001379436-P10-000-01-0050The incident response process shall ensure that risk is managed in coordination with the vehicle manufacturer.
Statement

The incident response process shall ensure that risk is managed in coordination with the vehicle manufacturer.

SSR-VIH-002Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-003componentRFQX-1001379436-P10-000-01-0050 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0051Any vulnerabilities that are identified during product lifecycle shall be promptly communicated to the vehicle manufacturer.
Statement

Any vulnerabilities that are identified during product lifecycle shall be promptly communicated to the vehicle manufacturer.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0051 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0052The report shall include information needed to identify the affected vehicles/products.
Statement

The report shall include information needed to identify the affected vehicles/products.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0052 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0053Methods including the stipulation of a reasonable notification time shall be proposed to and approved by the vehicle manufacturer.
Statement

Methods including the stipulation of a reasonable notification time shall be proposed to and approved by the vehicle manufacturer.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0053 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0054Following each identified and reported vulnerability, the supplier and vehicle manufacturer shall agree on an initial response to the vulnerability.
Statement

Following each identified and reported vulnerability, the supplier and vehicle manufacturer shall agree on an initial response to the vulnerability.

SSR-VIH-003Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-008componentRFQX-1001379436-P10-000-01-0054 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0055Within adequate time after the initial vulnerability report, the supplier shall provide more information about the identified vulnerability.
Statement

Within adequate time after the initial vulnerability report, the supplier shall provide more information about the identified vulnerability.

SSR-VIH-003Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-008componentRFQX-1001379436-P10-000-01-0055 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0056The information shall contain • the version(s) of affected hardware or software components, • nature of the vulnerability, • description of the affected cybersecurity goal, • technical conditions to exploit the vulnerability, • impact of the exploitation and • possibilities to remove the vulnerability.
Statement

The information shall contain • the version(s) of affected hardware or software components, • nature of the vulnerability, • description of the affected cybersecurity goal, • technical conditions to exploit the vulnerability, • impact of the exploitation and • possibilities to remove the vulnerability.

NoneNoneAD-007componentRFQX-1001379436-P10-000-01-0056 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0057Methods including the stipulation of a reasonable reporting time shall be proposed to and approved by the vehicle manufacturer.
Statement

Methods including the stipulation of a reasonable reporting time shall be proposed to and approved by the vehicle manufacturer.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0057 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0058The supplier shall have a method for monitoring available vulnerability databases for vulnerabilities that can affect the delivered product.
Statement

The supplier shall have a method for monitoring available vulnerability databases for vulnerabilities that can affect the delivered product.

SSR-VIH-004Vulnerability and Incident Handling — Vulnerability and Incident HandlingAD-005interfaceRFQX-1001379436-P10-000-01-0058 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0059Identified vulnerabilities shall be considered in all current development projects or projects under field monitoring.
Statement

Identified vulnerabilities shall be considered in all current development projects or projects under field monitoring.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0059 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-1001379436-P10-000-01-0060An ECU returned from field shall allow for field-return analysis.
Statement

An ECU returned from field shall allow for field-return analysis.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-1001379436-P10-000-01-0060 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-1001379436-P10-000-01-0061Field-return analysis secrets shall not be operational in the field.
Statement

Field-return analysis secrets shall not be operational in the field.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-1001379436-P10-000-01-0061 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-1001379436-P10-000-01-0062An ECU enabled for field-return analysis shall not be possible to use as a spare part.
Statement

An ECU enabled for field-return analysis shall not be possible to use as a spare part.

SSR-LIFE-001Lifecycle / Field Return / Decommissioning — Lifecycle / Field Return / DecommissioningAD-006componentRFQX-1001379436-P10-000-01-0062 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-1001379436-P10-000-01-0063All secrets specified by the vehicle manufacturer shall be protected throughout the lifecycle of the ECU.
Statement

All secrets specified by the vehicle manufacturer shall be protected throughout the lifecycle of the ECU.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-1001379436-P10-000-01-0063 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-1001379436-P10-000-01-0064End-of-life and decommissioning shall be specifically considered.
Statement

End-of-life and decommissioning shall be specifically considered.

NoneNoneAD-008componentRFQX-1001379436-P10-000-01-0064 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0065Notes: a) It shall not be possible for a third party to reuse an ECU without system support from the vehicle manufacturer.
Statement

Notes: a) It shall not be possible for a third party to reuse an ECU without system support from the vehicle manufacturer.

NoneNoneAD-006componentRFQX-1001379436-P10-000-01-0065 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0066b) Decommissioning of an ECU shall not have the potential of causing unacceptable risk to the road user or the vehicle manufacturer.
Statement

b) Decommissioning of an ECU shall not have the potential of causing unacceptable risk to the road user or the vehicle manufacturer.

NoneNoneAD-006componentRFQX-1001379436-P10-000-01-0066 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-1001379436-P10-000-01-0067Security related events shall be identified and logged.
Statement

Security related events shall be identified and logged.

SSR-LOG-001Security Logging and Event Handling — Security Logging and Event HandlingAD-007componentRFQX-1001379436-P10-000-01-0067 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0001The gearbox itself shall be used in all drivetrains and the ECA shall be common and must be complaint to be put on any driveline setup.
Statement

The gearbox itself shall be used in all drivetrains and the ECA shall be common and must be complaint to be put on any driveline setup.

NoneNoneAD-008componentRFQX-3299216-1-0001 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0002The clutch actuator shall be electrically driven
Statement

The clutch actuator shall be electrically driven

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0002 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0003The actuator is placed outside of the gearbox
Statement

The actuator is placed outside of the gearbox

NoneNoneNoneNoneRFQX-3299216-1-0003 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0004The ECA (Electric Clutch Actuator) must have its own internal ECU for manoeuvring and error handling.
Statement

The ECA (Electric Clutch Actuator) must have its own internal ECU for manoeuvring and error handling.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-3299216-1-0004 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0005The actuator will be controlled by a position and speed demand by CAN-bus
Statement

The actuator will be controlled by a position and speed demand by CAN-bus

NoneNoneNoneNoneRFQX-3299216-1-0005 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0006The actuator will be controlled by a position and speed demand by a 1kHz PWM signal on wake up connection
Statement

The actuator will be controlled by a position and speed demand by a 1kHz PWM signal on wake up connection

NoneNoneNoneNoneRFQX-3299216-1-0006 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0007The ECA units shall be manufactured with marking variants according to the requirements in Scania STD19 (Ref 14.17).
Statement

The ECA units shall be manufactured with marking variants according to the requirements in Scania STD19 (Ref 14.17). The variant type shall be based on delivery agreement and Brand involved. Variant 1: For Scania units, wordmark variant C1 Part number (7 digits). Variant 2: For MAN units, wordmark variant Z1. Part number (13 digits). Variant 3: For International units, wordmark variant X1. Part number (8 digits) Variant 4 Tentik wordmark variant W. Part number (9 digits, two spaces in format: 12 345 6789). Common marking requirements that must be fulfilled for each marking variant are: Marking method: MA1 Marking height: 3 mm Date format: YYMMDD A unique serial number A DMC according to Scania STD 4562 (Ref 14.18) that contains the part number and serial number information. The marking shall not be visible when the ECA is mounted on a gearbox. The ECA units shall be delivered to the required Traton brand’s production in a position in the pallet where the marking is visible.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0007 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0008The variant type shall be based on delivery agreement and Brand involved.
Statement

The variant type shall be based on delivery agreement and Brand involved.

NoneNoneAD-008componentRFQX-3299216-1-0008 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0009Common marking requirements that must be fulfilled for each marking variant are: Marking method: MA1 Marking height: 3 mm Date format: YYMMDD A unique serial number A DMC according to Scania STD 4562 (Ref 14.18) that contains the part number and serial number information.
Statement

Common marking requirements that must be fulfilled for each marking variant are: Marking method: MA1 Marking height: 3 mm Date format: YYMMDD A unique serial number A DMC according to Scania STD 4562 (Ref 14.18) that contains the part number and serial number information.

NoneNoneAD-008componentRFQX-3299216-1-0009 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0010The marking shall not be visible when the ECA is mounted on a gearbox.
Statement

The marking shall not be visible when the ECA is mounted on a gearbox.

NoneNoneAD-008componentRFQX-3299216-1-0010 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0011The ECA units shall be delivered to the required Traton brand’s production in a position in the pallet where the marking is visible.
Statement

The ECA units shall be delivered to the required Traton brand’s production in a position in the pallet where the marking is visible.

NoneNoneAD-008componentRFQX-3299216-1-0011 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0012The rubber cover (See req.
Statement

The rubber cover (See req. 4.16) shall be marked according to the requirements in Scania STD19 (Ref 14.17) Tentik, wordmark variant W Part number (9 digits, two spaces in format 12 345 6789) Marking method: CAS Marking height: 2-6 mm. Date dial: CVM. Alternative design: CXM or equivalent combination of date dial and date field The rubber cover marking shall not be visible when the ECA is mounted on a gearbox

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0012 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0013The ECA shall be designed with Remanufacturing and/or Refurbishment in mind with possibility of swapping out larger electronic assemblies/components.
Statement

The ECA shall be designed with Remanufacturing and/or Refurbishment in mind with possibility of swapping out larger electronic assemblies/components. Details to be agreed with Traton

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0013 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0014The mechanics shall also be tested and verified, in an overall durability test as stated in Appendix B etc.
Statement

The mechanics shall also be tested and verified, in an overall durability test as stated in Appendix B etc.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0014 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-00154.16) shall be marked according to the requirements in Scania STD19 (Ref 14.17) Tentik, wordmark variant W Part number (9 digits, two spaces in format 12 345 6789) Marking method: CAS Marking height: 2-6 mm.
Statement

4.16) shall be marked according to the requirements in Scania STD19 (Ref 14.17) Tentik, wordmark variant W Part number (9 digits, two spaces in format 12 345 6789) Marking method: CAS Marking height: 2-6 mm.

NoneNoneAD-008componentRFQX-3299216-1-0015 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0016Details to be agreed with Traton 2.9 Traton shall be invited to participate in electrical and mechanical design reviews.
Statement

Details to be agreed with Traton 2.9 Traton shall be invited to participate in electrical and mechanical design reviews.

NoneNoneAD-008componentRFQX-3299216-1-0016 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-00172.10 Traton requires extensive testing to be performed by the supplier to verify all demands stated in the requirement specification.
Statement

2.10 Traton requires extensive testing to be performed by the supplier to verify all demands stated in the requirement specification.

NoneNoneAD-008componentRFQX-3299216-1-0017 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-00182.12 Traton requires: - Documentation of the product, i.e.
Statement

2.12 Traton requires: - Documentation of the product, i.e.

NoneNoneAD-008componentRFQX-3299216-1-0018 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0019Should the PP be fully calculated from the AP-sensor, then this offset should not exist.
Statement

Should the PP be fully calculated from the AP-sensor, then this offset should not exist.

NoneNoneAD-006componentRFQX-3299216-1-0019 / 56hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0020The maximum release stroke is 22,4 mm from FCCP
Statement

The maximum release stroke is 22,4 mm from FCCP

NoneNoneNoneNoneRFQX-3299216-1-0020 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0021The total stroke of the actuator shall be 85 mm
Statement

The total stroke of the actuator shall be 85 mm

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0021 / 9hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0022The clutch actuator shall be able to reach the extreme positions A and B in with the center of the pushrod end.
Statement

The clutch actuator shall be able to reach the extreme positions A and B in with the center of the pushrod end. Dimensions measured on the ECA. See Figure 3 - Pushrod positions. Figure 3 - Pushrod positions

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0022 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0023The gearbox flange designated to the ECA has three different surfaces, see Figure 5 Gearbox flange.
Statement

The gearbox flange designated to the ECA has three different surfaces, see Figure 5 Gearbox flange. Surface A, which is machined pressure die cast aluminium that can act both as a heat source and heat sink for the ECA Surface B which is a raw pressure die casted surface. Surface C which is a rubber grommet, that does not require any different interface compared to the surrounding surface A.

NoneNoneNoneNoneRFQX-3299216-1-0023 / 8hNot importedStill Requires Customer DecisionNo P1 linkevidence completenessMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0024When the ECA is assembled, it shall not be possible to insert an object larger than Ø0,2 mm (A wire could be used as test object) between the ECA and gearbox flange, so that the object enters the space behind the ECA.
Statement

When the ECA is assembled, it shall not be possible to insert an object larger than Ø0,2 mm (A wire could be used as test object) between the ECA and gearbox flange, so that the object enters the space behind the ECA. The rubber grommet at the lower part of the flange can have the same interface as the surrounding aluminum flange.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-3299216-1-0024 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0025When the ECA is assembled, a gap of 3,5 mm towards surface B with a profile tolerance of ±1 mm to the nominal dimensions shall be provided.
Statement

When the ECA is assembled, a gap of 3,5 mm towards surface B with a profile tolerance of ±1 mm to the nominal dimensions shall be provided. The surface roughness of the ECA opposite to surface B shall be equal or finer than Ra 3,2 µm.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0025 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0026The ECA shall be adapted for 6 pcs M8 flange screws described by Scania STD4435
Statement

The ECA shall be adapted for 6 pcs M8 flange screws described by Scania STD4435

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0026 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0027P 1 Page 4.4 ECA shall not interfere with any geometry in the 3D envelope -1 1_RFQ2030.stp except where interference fits or other types of functional contacts are required.
Statement

P 1 Page 4.4 ECA shall not interfere with any geometry in the 3D envelope -1 1_RFQ2030.stp except where interference fits or other types of functional contacts are required.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0027 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0028The surface roughness of the ECA opposite to surface B shall be equal or finer than Ra 3,2 µm.
Statement

The surface roughness of the ECA opposite to surface B shall be equal or finer than Ra 3,2 µm.

NoneNoneAD-008componentRFQX-3299216-1-0028 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0029The ECA shall be adapted for 2 pcs 10 mm guide pins Figure 5 - Gearbox flange
Statement

The ECA shall be adapted for 2 pcs 10 mm guide pins Figure 5 - Gearbox flange

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0029 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0030The guide pin holes in the ECA shall be Ø 10,1±0.05 mm and at least 12 mm deep.
Statement

The guide pin holes in the ECA shall be Ø 10,1±0.05 mm and at least 12 mm deep. The holes shall also block the guide pin from protruding more than 14 mm from the gearbox housing. Both depths measured from the center of the oval hole in the Gearbox/ECA flange.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0030 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0031The ECA shall be able to be held by the guide pins only while being exposed to the max clutch load, (req.
Statement

The ECA shall be able to be held by the guide pins only while being exposed to the max clutch load, (req. 4.22) up to 50 times. The clutch load will be removed and the screw interface tightened between every load occasion. Surface indents in the contacts are allowed as long as the structural integrity is unaffected

SSR-DAI-002Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-005interfaceRFQX-3299216-1-0031 / 16hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0032The pushrod end that makes contact with the clutch lever shall be a Ø15,93±0,07 mm steel sphere.
Statement

The pushrod end that makes contact with the clutch lever shall be a Ø15,93±0,07 mm steel sphere.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0032 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0033It shall be possible to pull the pushrod 50 times with a force of 300 N without risk for it to come loose from the ECA.
Statement

It shall be possible to pull the pushrod 50 times with a force of 300 N without risk for it to come loose from the ECA. Alternatively it can have a loose fit in the ECA, but it shall be possible to reconnect it by pushing it back by hand.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-3299216-1-0033 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0034The ECA shall allow space for external tools according to the cylinders in the 3D envelope attached.
Statement

The ECA shall allow space for external tools according to the cylinders in the 3D envelope attached.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0034 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0035The ECA shall have a window where the volume shown in Figure 6 – Snap in tool space, could pass through(See req.
Statement

The ECA shall have a window where the volume shown in Figure 6 – Snap in tool space, could pass through(See req. 4.4).

SSR-TOOL-001Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-004componentRFQX-3299216-1-0035 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0036The ECA shall provide a support for a clutch snap in tool on the marked surface in Figure 4 ISO view of 3D envelope.
Statement

The ECA shall provide a support for a clutch snap in tool on the marked surface in Figure 4 ISO view of 3D envelope. The maximum force is 1kN. Surface indents are allowed as long as it does not affect other requirements or the structural integrity of the ECA.

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-3299216-1-0036 / 8hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0037The holes shall also block the guide pin from protruding more than 14 mm from the gearbox housing.
Statement

The holes shall also block the guide pin from protruding more than 14 mm from the gearbox housing.

NoneNoneAD-008componentRFQX-3299216-1-0037 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0038Alternatively it can have a loose fit in the ECA, but it shall be possible to reconnect it by pushing it back by hand.
Statement

Alternatively it can have a loose fit in the ECA, but it shall be possible to reconnect it by pushing it back by hand.

NoneNoneAD-002componentRFQX-3299216-1-0038 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0039The hole shall be equipped with a cover possible to assemble and disassemble at least 50 times without tools.
Statement

The hole shall be equipped with a cover possible to assemble and disassemble at least 50 times without tools. If an interference fit is chosen, the maximum force to assemble/disassemble shall be 50 N in room temperature. It shall still remain intac t and keep tightness after vibration testing (See req.10.5)

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0039 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0040When the cover is assembled it shall not be possible to insert an object larger than Ø0,2 mm into the gearbox housing between the cover and ECA.
Statement

When the cover is assembled it shall not be possible to insert an object larger than Ø0,2 mm into the gearbox housing between the cover and ECA. A wire could be used as test object. Figure 6 - Snap in tool space

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0040 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0041The ECA shall have a loop or similar feature where the cable can be fixated with a cable tie Optionally an M8 screw thread and rotation stop for a sheet metal bracket indicated in Figure 4 - ISO view of 3D envelope, can be provided.
Statement

The ECA shall have a loop or similar feature where the cable can be fixated with a cable tie Optionally an M8 screw thread and rotation stop for a sheet metal bracket indicated in Figure 4 - ISO view of 3D envelope, can be provided. The loop or Scania assembled bracket shall be located close to the centre ( ± 20 mm) of the cable section between the connector and last cable fixation point on the gearbox

SSR-COM-005Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-006componentRFQX-3299216-1-0041 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0042The connector for communication and power shall be positioned as indicated in Figure 4 ISO view of 3D envelope, when connected.
Statement

The connector for communication and power shall be positioned as indicated in Figure 4 ISO view of 3D envelope, when connected. Details regarding actual length and positioning tolerances shall be agreed in design phase.

SSR-COM-005Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-006componentRFQX-3299216-1-0042 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0043If the ECA is powered up with the PP in the utmost forward position (for example when not connected to the clutch lever) it shall move AP to its utmost reversed position.
Statement

If the ECA is powered up with the PP in the utmost forward position (for example when not connected to the clutch lever) it shall move AP to its utmost reversed position.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0043 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0044If an interference fit is chosen, the maximum force to assemble/disassemble shall be 50 N in room temperature.
Statement

If an interference fit is chosen, the maximum force to assemble/disassemble shall be 50 N in room temperature.

NoneNoneAD-008componentRFQX-3299216-1-0044 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0045Details regarding actual length and positioning tolerances shall be agreed in design phase.
Statement

Details regarding actual length and positioning tolerances shall be agreed in design phase.

NoneNoneAD-008componentRFQX-3299216-1-0045 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0046The clutch force acting on the pushrod is defined in Appendix A
Statement

The clutch force acting on the pushrod is defined in Appendix A

NoneNoneNoneNoneRFQX-3299216-1-0046 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0047The actuator shall apply a preload force for the release bearing.
Statement

The actuator shall apply a preload force for the release bearing. The preload force measured on the push rod shall be 150N to 250N independent of the clutch position

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0047 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0048The pushrod position when clutch is at rest and only preload force is applied, will vary randomly within 2 mm (± 1mm from FCCP).
Statement

The pushrod position when clutch is at rest and only preload force is applied, will vary randomly within 2 mm (± 1mm from FCCP).

NoneNoneNoneNoneRFQX-3299216-1-0048 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0049It must be possible to assemble the actuator independent of the lever position without any power connection.
Statement

It must be possible to assemble the actuator independent of the lever position without any power connection. This means that the push rod shall be possible to move by hand. Maximum force allowed is 300N.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0049 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0050This means that the push rod shall be possible to move by hand.
Statement

This means that the push rod shall be possible to move by hand.

NoneNoneAD-008componentRFQX-3299216-1-0050 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-00514.26 When the clutch is fully engaged, the active control mode is position or torque control mode and there is no active request to extract the pushrod (clutch opening motion), the ECA shall not apply a force outside of limits in preload force defined in req.
Statement

4.26 When the clutch is fully engaged, the active control mode is position or torque control mode and there is no active request to extract the pushrod (clutch opening motion), the ECA shall not apply a force outside of limits in preload force defined in req.

NoneNoneAD-008componentRFQX-3299216-1-0051 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0052P 1 Page 5 Clutch engage and disengage 5.1 It shall be possible to disengage the clutch in 180ms (= Ts) with accuracy according to ,and max speed set to 125mm/s (see
Statement

P 1 Page 5 Clutch engage and disengage 5.1 It shall be possible to disengage the clutch in 180ms (= Ts) with accuracy according to ,and max speed set to 125mm/s (see

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0052 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0053) Time is measured according to Figure 7 – Max disengage time, where the dashed line is the position request as it becomes available on the CAN bus, and the full line is the actual PP.
Statement

) Time is measured according to Figure 7 – Max disengage time, where the dashed line is the position request as it becomes available on the CAN bus, and the full line is the actual PP.

NoneNoneNoneNoneRFQX-3299216-1-0053 / 19hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0054This shall be measured against the maximum disengage force (See Appendix A) Figure 7 – Maximum disengage time
Statement

This shall be measured against the maximum disengage force (See Appendix A) Figure 7 – Maximum disengage time

NoneNoneAD-008componentRFQX-3299216-1-0054 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0055P 1 Page 5.2 It shall be possible to engage the clutch in 180ms (=Ts) with accuracy according to re q.5.10, and the max speed set to 125mm/s (see ).
Statement

P 1 Page 5.2 It shall be possible to engage the clutch in 180ms (=Ts) with accuracy according to re q.5.10, and the max speed set to 125mm/s (see ).

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0055 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0056This shall be measured against the minimum engage force (See Appendix A) Figure 8 - Maximum engage time
Statement

This shall be measured against the minimum engage force (See Appendix A) Figure 8 - Maximum engage time

NoneNoneAD-008componentRFQX-3299216-1-0056 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0057The clutch actuator shall report the absolute position of the current actuator stroke (AP) (Ref 14.14).
Statement

The clutch actuator shall report the absolute position of the current actuator stroke (AP) (Ref 14.14).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0057 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0058It shall also report the position that corresponds to a fully closed clutch position (FCCP), expressed in absolute position of the actuator stroke and relative to the absolute zero position (See req.
Statement

It shall also report the position that corresponds to a fully closed clutch position (FCCP), expressed in absolute position of the actuator stroke and relative to the absolute zero position (See req. 6.5).

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0058 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0059The clutch actuator shall be equipped with a displacement sensor measuring the movement of the push rod, (Ref 14.14)
Statement

The clutch actuator shall be equipped with a displacement sensor measuring the movement of the push rod, (Ref 14.14)

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-3299216-1-0059 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0060The actuator must be able to determine the pushrod position according to the following Accuracy (maximum difference between measured pushrod position and actual pushrod position): +/- 1.6mm.
Statement

The actuator must be able to determine the pushrod position according to the following Accuracy (maximum difference between measured pushrod position and actual pushrod position): +/- 1.6mm. Resolution (smallest discernible unit of change along the X axis): 0.0125mm. Repeatability (maximum variation between measurements at the same position and in the same unit, with equal environmental conditions): +/- 0.1mm. Range: 85mm (AP)

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0060 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0061For each stroke that the actuator performs it shall adjust to the current wear of the clutch.
Statement

For each stroke that the actuator performs it shall adjust to the current wear of the clutch. This means that is shall be possible to request a relative stroke from the fully closed clutch position and achieve the step accuracy as defined in req. 5.10. The implementation can be either a pure mechanical solution or it can be implemented using a software based solution.

SSR-COM-006Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-001componentRFQX-3299216-1-0061 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0062The maximum stationary position error relative to real FCCP (i e self-adjustment error + step response error) shall be ±0.15mm.
Statement

The maximum stationary position error relative to real FCCP (i e self-adjustment error + step response error) shall be ±0.15mm.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0062 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0063This means that is shall be possible to request a relative stroke from the fully closed clutch position and achieve the step accuracy as defined in req.
Statement

This means that is shall be possible to request a relative stroke from the fully closed clutch position and achieve the step accuracy as defined in req.

NoneNoneAD-008componentRFQX-3299216-1-0063 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0064The FCCP after a clutch engage shall be updated to 90% of the step within 0,2 s per mm that the FCCP have changed during the stroke.
Statement

The FCCP after a clutch engage shall be updated to 90% of the step within 0,2 s per mm that the FCCP have changed during the stroke.

NoneNoneAD-008componentRFQX-3299216-1-0064 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0065P 1 Page 5.10 The actuator shall move the pushrod according to the following points: Actuator maximum speed: The maximum achievable speed of the pushrod shall be at least 125 mm/s.
Statement

P 1 Page 5.10 The actuator shall move the pushrod according to the following points: Actuator maximum speed: The maximum achievable speed of the pushrod shall be at least 125 mm/s.

NoneNoneAD-008componentRFQX-3299216-1-0065 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0066The actuator shall move the pushrod at the highest possible speed, limited only by its maximum achievable speed and the maximum speed request.
Statement

The actuator shall move the pushrod at the highest possible speed, limited only by its maximum achievable speed and the maximum speed request.

NoneNoneAD-008componentRFQX-3299216-1-0066 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-00676.4) Dynamics start of movement: The requested speed (or 125mm/s, if requested speed > 125mm/s) shall be achieved within 50ms from when a new value for requested position is sent.
Statement

6.4) Dynamics start of movement: The requested speed (or 125mm/s, if requested speed > 125mm/s) shall be achieved within 50ms from when a new value for requested position is sent.

NoneNoneAD-008componentRFQX-3299216-1-0067 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0068Dynamics end of movement: The requested speed shall be kept until 2 mm from the target position.
Statement

Dynamics end of movement: The requested speed shall be kept until 2 mm from the target position.

NoneNoneAD-008componentRFQX-3299216-1-0068 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0069100ms after reaching 2 mm from target, the maximum position error should be ±0.1mm.
Statement

100ms after reaching 2 mm from target, the maximum position error should be ±0.1mm.

NoneNoneAD-008componentRFQX-3299216-1-0069 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredMISSING SYSTEM REQUIREMENT
RFQX-3299216-1-0070Maximum overshoot is 0.2 mm When a new position is requested, but the stroke is too short to reach requested speed, the ECA shall complete the stroke in minimum time with dynamic in compliance with the , 5.2 and this section.
Statement

Maximum overshoot is 0.2 mm When a new position is requested, but the stroke is too short to reach requested speed, the ECA shall complete the stroke in minimum time with dynamic in compliance with the , 5.2 and this section.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-3299216-1-0070 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0071Req.
Statement

Req. 5.10 shall be tested with a step response test cycle, according to description and Figure 10 - Step response test cycle. Step from FCCP to 0.5x fully open position Wait 2 seconds Step to fully open position Wait 2 seconds Step to 0.5x fully open position Wait 2 seconds Step to FCCP Figure 10 - Step response test cycle

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0071 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-00725.10 shall be tested with a step response test cycle, according to description and Figure 10 - Step response test cycle.
Statement

5.10 shall be tested with a step response test cycle, according to description and Figure 10 - Step response test cycle.

NoneNoneAD-008componentRFQX-3299216-1-0072 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0073P 1 Page 5.12 The ECA shall be able to run the 4 second test cycle in Figure 11 - Release frequency test continuously for 5 hours without any degradation or failure.
Statement

P 1 Page 5.12 The ECA shall be able to run the 4 second test cycle in Figure 11 - Release frequency test continuously for 5 hours without any degradation or failure.

NoneNoneAD-008componentRFQX-3299216-1-0073 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0074The test shall be done with the highest operating temperature (see ) and maximum clutch force (See Appendix A) Figure 11 - Release frequency test
Statement

The test shall be done with the highest operating temperature (see ) and maximum clutch force (See Appendix A) Figure 11 - Release frequency test

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0074 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0075It shall be possible to keep the clutch disengaged continuously without risk of loss of function for 120 min.
Statement

It shall be possible to keep the clutch disengaged continuously without risk of loss of function for 120 min. This shall be measured against the maximum disengage force (Appendix A) and an highest operating temperature (see req. 8.1).

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-3299216-1-0075 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0076Between 16V and loss of power the ECA shall hold its current position or move towards requested position without any time requirement.
Statement

Between 16V and loss of power the ECA shall hold its current position or move towards requested position without any time requirement.

NoneNoneAD-008componentRFQX-3299216-1-0076 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0077The strategy shall be disc ussed and approved with Traton.
Statement

The strategy shall be disc ussed and approved with Traton.

NoneNoneAD-008componentRFQX-3299216-1-0077 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0078This shall be measured against the maximum disengage force (Appendix A) and an highest operating temperature (see req.
Statement

This shall be measured against the maximum disengage force (Appendix A) and an highest operating temperature (see req.

NoneNoneAD-008componentRFQX-3299216-1-0078 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0079The ECA will be controlled by messages on the CAN bus and by the PWM signal specified in req.
Statement

The ECA will be controlled by messages on the CAN bus and by the PWM signal specified in req. 7.24-7.33. The CAN communication messages are specified in PD2497100 (Ref 14.14). It shall be followed to its full extent. If needed, some messages might be complemented with additional checksums and message counters

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-3299216-1-0079 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0080Control mode
Statement

Req. 6.3.1 to 6.3.5 describe the various control modes that can be requested via CAN (Ref 14.14)

NoneNoneNoneNoneRFQX-3299216-1-0080 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0081P 1 Page 6 SW functionality 6.1 TB4684 shall be applied.
Statement

P 1 Page 6 SW functionality 6.1 TB4684 shall be applied.

NoneNoneAD-008componentRFQX-3299216-1-0081 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0082It shall be followed to its full extent.
Statement

It shall be followed to its full extent.

NoneNoneAD-002componentRFQX-3299216-1-0082 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0083Description Mode Name Enom
Statement

When requesting Absolute Position Control the actuator shall move to the actuator position defined by the Requested Position (RP). The RP can in this mode correspond to the full wear travel of the clutch (see req. 4.3) It is allowed to control movement to protect the ECA and clutch from hardware damage. Specific cases shall be approved with Traton. Control mode Absolute position 0x01

SSR-COM-005Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-006componentRFQX-3299216-1-0083 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0084When requesting Relative Position
Statement

Control (RPC) the actuator shall move to an offset that corresponds to the Requested Position from the Fully Closed Clutch Position (FCCP). The RP can be up to a full Release Travel (22,4 mm) in this mode. How the FCCP can be identified is described in 6.5. When RP = 0 the actuator is allowed to have a position that is less than the FCCP but not more, since this would open the clutch. Control mode Relative position 0x02

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0084 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0085When requesting Absolute Position Control the actuator shall move to the actuator position defined by the Requested Position (RP).
Statement

When requesting Absolute Position Control the actuator shall move to the actuator position defined by the Requested Position (RP).

NoneNoneAD-008componentRFQX-3299216-1-0085 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0086Specific cases shall be approved with Traton.
Statement

Specific cases shall be approved with Traton.

NoneNoneAD-008componentRFQX-3299216-1-0086 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0087Control mode Relative position 0x02 6.3.3 When requesting Torque Control (TC) the actuator shall actuate the requested motor torque.
Statement

Control mode Relative position 0x02 6.3.3 When requesting Torque Control (TC) the actuator shall actuate the requested motor torque.

NoneNoneAD-008componentRFQX-3299216-1-0087 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0088Maximum speed
Statement

A maximum allowed speed of the actuator is sent as a separate signal on CAN. If the actuator can move faster than this value it shall be controlled in a such way that it does not exceed this limit.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-3299216-1-0088 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0089No update of the FCCP is allowed
Statement

The value shall be frozen at the last identified position and used for RPC. Self-adjustment disabled 0x3

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0089 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-00906.3.4 When requesting Test Mode, the actuator shall perform tests to detect latent faults.
Statement

6.3.4 When requesting Test Mode, the actuator shall perform tests to detect latent faults.

NoneNoneAD-008componentRFQX-3299216-1-0090 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0091ECA behavior and additional requirements for this mode can be found in (Ref 14.16) Control mode Test mode 0x04 6.3.5 When this Control Mode is sent the actuator shall behave as if the power supply was cut with aspect to control of the actuator.
Statement

ECA behavior and additional requirements for this mode can be found in (Ref 14.16) Control mode Test mode 0x04 6.3.5 When this Control Mode is sent the actuator shall behave as if the power supply was cut with aspect to control of the actuator.

NoneNoneAD-005interfaceRFQX-3299216-1-0091 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0092CAN communication shall still be active.
Statement

CAN communication shall still be active.

NoneNoneAD-005interfaceRFQX-3299216-1-0092 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0093If the actuator can move faster than this value it shall be controlled in a such way that it does not exceed this limit.
Statement

If the actuator can move faster than this value it shall be controlled in a such way that it does not exceed this limit.

NoneNoneAD-002componentRFQX-3299216-1-0093 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-00946.5 Self-adjustment The self-adjustment signal defines the restrictions of how the FCCP shall be identified.
Statement

6.5 Self-adjustment The self-adjustment signal defines the restrictions of how the FCCP shall be identified.

NoneNoneAD-005interfaceRFQX-3299216-1-0094 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0095).
Statement

).

NoneNoneNoneNoneRFQX-3299216-1-0095 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0096The value of the FCCP shall be reported via CAN(Ref 14.14) Req.
Statement

The value of the FCCP shall be reported via CAN(Ref 14.14) Req.

NoneNoneAD-005interfaceRFQX-3299216-1-0096 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0097The value shall be frozen at the last identified position and used for RPC.
Statement

The value shall be frozen at the last identified position and used for RPC.

NoneNoneAD-008componentRFQX-3299216-1-0097 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0098Accuracy mode
Statement

Accuracy mode

NoneNoneNoneNoneRFQX-3299216-1-0098 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0099Vehicle identification number(VIN
Statement

Not applicable.

NoneNoneNoneNoneRFQX-3299216-1-0099 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0100Feedback
Statement

Feedback from the ECA will also be sent via CAN. Specific error reporting as per req. 6.13. Message contents to be agreed with Traton

NoneNoneNoneNoneRFQX-3299216-1-0100 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0101ECA identification number
Statement

The ECA shall report a unique ECA individual identification number

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0101 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0102Supplier code
Statement

The ECA shall report supplier code 5 via CAN.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0102 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0103SW number
Statement

The ECA shall report a complete SW version number. The number is decided by the supplier and can be in the range 0-64255.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0103 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0104HW number
Statement

The ECA shall report a complete HW version number. The number is decided by the supplier and can be in the range 0-64255.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0104 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0105System state
Statement

The ECA shall report its current System State. Valid states are explained in requirements 6.14.1 - 6.14.9.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0105 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-01066.6.1 When low accuracy mode is requested, the maximum push rod position(PP) error can be ±0.5mm Accuracy mode Low accuracy 0x0 6.6.2 Accuracy according to 5.10 shall be fulfilled.
Statement

6.6.1 When low accuracy mode is requested, the maximum push rod position(PP) error can be ±0.5mm Accuracy mode Low accuracy 0x0 6.6.2 Accuracy according to 5.10 shall be fulfilled.

NoneNoneAD-005interfaceRFQX-3299216-1-0106 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-01076.13 Error State Diagnostic - ESD and Error State Action - ESA The ECA shall send a bit field via CAN containing errors present Additionally, see ,
Statement

6.13 Error State Diagnostic - ESD and Error State Action - ESA The ECA shall send a bit field via CAN containing errors present Additionally, see ,

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-3299216-1-0107 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0108,req.
Statement

,req.

NoneNoneNoneNoneRFQX-3299216-1-0108 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0109ESA definition( Ref 14.16) The supplier shall provide documentation for the ESD bits and related faults .
Statement

ESA definition( Ref 14.16) The supplier shall provide documentation for the ESD bits and related faults .

NoneNoneAD-008componentRFQX-3299216-1-0109 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0110Absolute Position Control
Statement

This value shall be sent when the ECA is actuating Absolute Position Control. 0x1

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0110 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0111Relative Position Control
Statement

This value shall be sent when the ECA is actuating Relative Position Control. 0x2

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0111 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0112Torque Control
Statement

This value shall be sent when the ECA is actuating Torque Control. The torque being controlled is the torque of the motor. 0x4

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0112 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0113Self-Adjustment
Statement

This value shall be sent when the ECA is performing a Self-Adjustment procedure that is not part of a RPC or TC request (i.e. passing FCCP). 0x5

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0113 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0114Initializing
Statement

This value shall be sent when the ECA is performing its initiation routine and is not yet available for control. 0xA

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0114 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0115Debug / Test
Statement

This value shall be sent when the actuator is in debug or test control state. 0xC

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0115 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0116Motor Brake Simulation
Statement

This value shall be sent when the actuator is performing a motor brake simulation. 0xD

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0116 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-01176.14.1 Boot Mode If the actuator is in boot mode, 0x00 shall be reported as active state.
Statement

6.14.1 Boot Mode If the actuator is in boot mode, 0x00 shall be reported as active state.

NoneNoneAD-008componentRFQX-3299216-1-0117 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-01180xA 6.14.7 Shut down This value shall be sent when the ECA is performing its shut down routing and is not available for control.
Statement

0xA 6.14.7 Shut down This value shall be sent when the ECA is performing its shut down routing and is not available for control.

NoneNoneAD-008componentRFQX-3299216-1-0118 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0119System Temperature
Statement

The ECA shall report the current system temperature.(Ref 14.14)

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0119 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0120Torque Feedback
Statement

The ECA shall calculate and report the actuator motor torque. (Ref 14.14)

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0120 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0121Current feedback
Statement

The ECA shall report the current for each phase of the actuator. These values shall be calculated using a moving mean filter. The filter time shall equal the update frequency . (Ref 14.14)

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0121 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0122Supply Voltage Feedback
Statement

The ECA shall report the current system voltage. (input voltage) (Ref 14.14)

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0122 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0123Operational hours
Statement

The ECA shall store and report its accumulated operational hours.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0123 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0124Total travelled length
Statement

The ECA shall report its accumulated lifetime travel length.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0124 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0125Diagnosis
Statement

CVS120 shall be applied (Ref 14.12).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0125 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0126Cyber Security
Statement

Cybersecurity shall be considered through a separate process with the latest Traton workflow in mind. The following apply: Mandatory: TRATON secure updates - CVS31,CVS32,CVS123-2,CVS154 TRATON secure diagnostics - CVS31,CVS32,CVS151 TRATON Specification on Unified diagnostic Services CVS124 Other applicable documents considered as supporting specifications: CVS30, CVS33, CVS34,CVS121,CVS122,SecureBoot,Vehicle Baseline Requirements, ECU Baseline Requirements Additional standards/documents will be made available, if applicable.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-3299216-1-0126 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0127Minimum diagnostic feedback
Statement

Minimum diagnostic feedback described in req. 6.22.1 - 6.22.11.

NoneNoneNoneNoneRFQX-3299216-1-0127 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0128Wrong rotation direction
Statement

Wrong rotation direction

NoneNoneNoneNoneRFQX-3299216-1-0128 / 56hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0129Short circuit / open load on the phases
Statement

Short circuit / open load on the phases

NoneNoneNoneNoneRFQX-3299216-1-0129 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0130Motor rotation feedback, short circuit / open load
Statement

Motor rotation feedback, short circuit / open load

NoneNoneNoneNoneRFQX-3299216-1-0130 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0131These values shall be calculated using a moving mean filter.
Statement

These values shall be calculated using a moving mean filter.

NoneNoneAD-008componentRFQX-3299216-1-0131 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0132The filter time shall equal the update frequency .
Statement

The filter time shall equal the update frequency .

NoneNoneAD-008componentRFQX-3299216-1-0132 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0134Validation and Invalidation
Statement

The reported ESD must be able to be validated and invalidated.

SSR-VV-001Security evidence and traceability — Verification and ValidationAD-008componentRFQX-3299216-1-0134 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0135Diagnosis tracking
Statement

The gearbox control unit(TCU) shall be responsible for setting DTCs based on received notifications from ECA via ESD, including time-stamps, occurrence counters etc. One unique DTC will be set per bit in the ESD signal. If higher resolution is required for the supplier to properly troubleshoot any individual occurrence, then the ECA is responsible for storing these parameters internally. Internally stored parameters may be accessible only using supplier defined tools .

SSR-DIAG-001Diagnostic Services — Diagnostic ServicesAD-005interfaceRFQX-3299216-1-0135 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0136Data logging
Statement

Any data logged or stored shall be agreed upon together with Traton.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0136 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0137Data storage
Statement

When storing data in the device, the supplier shall take measures to prevent corruption of data which can occur for example when suffering power loss during read or write cycles. The supplier shall also ensure that systems are in place that ensure that data corruption is handled without loss of data, or loss of function. This could be designed with for example data mirroring. It is acceptable if purely statistical data (e.g. operation hours) from the active operation cycle is not stored in case of an abnormal shutdown.

SSR-COM-008OEM/Customer Review Interface — Secure Communication and Boundary ControlAD-001componentRFQX-3299216-1-0137 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0138Calibration
Statement

There shall only be one calibration set of the ECA that is delivered to Traton, i.e, the calibration shall not be dependent of installation variants.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0138 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0139Reset
Statement

It shall be possible to reset the ECA application with a power off/on cycle after all functional safety events. Handling to be agreed with Traton.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-3299216-1-0139 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0140If higher resolution is required for the supplier to properly troubleshoot any individual occurrence, then the ECA is responsible for storing these parameters internally.
Statement

If higher resolution is required for the supplier to properly troubleshoot any individual occurrence, then the ECA is responsible for storing these parameters internally.

NoneNoneAD-008componentRFQX-3299216-1-0140 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0141Internally stored parameters may be accessible only using supplier defined tools .
Statement

Internally stored parameters may be accessible only using supplier defined tools .

NoneNoneNoneNoneRFQX-3299216-1-0141 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0142The supplier shall also ensure that systems are in place that ensure that data corruption is handled without loss of data, or loss of function.
Statement

The supplier shall also ensure that systems are in place that ensure that data corruption is handled without loss of data, or loss of function.

NoneNoneAD-001componentRFQX-3299216-1-0142 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0143The electrical design must ensure that an internal short circuit through one of H -bridges (“shoot through”) is avoided.
Statement

The electrical design must ensure that an internal short circuit through one of H -bridges (“shoot through”) is avoided.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0143 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0144A safe boot sequence must be set to prevent unwanted or undefined behavior during or after loss of power, or corruption of stored data.
Statement

A safe boot sequence must be set to prevent unwanted or undefined behavior during or after loss of power, or corruption of stored data.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0144 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0145A safe memory read/write sequence must also be implemented during actuator movement, in order to ensure safe and predictable behavior during operation, or in case of power lo ss.
Statement

A safe memory read/write sequence must also be implemented during actuator movement, in order to ensure safe and predictable behavior during operation, or in case of power lo ss. Relates to Safety Goals set in PD3339794 (Ref 14.16).

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-3299216-1-0145 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0146All external electrical connectors shall be geometrically coded.
Statement

All external electrical connectors shall be geometrically coded. If internal components are included in repair kits, the internal electrical connectors shall also be geometrically coded.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0146 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0147ECA power and communication connector
Statement

2*6.3mm (MCP) 6*2.8mm (MCP) Code A TE part no.: 1-2299782-1 Pin list with: Pin distribution, Pin size (see req. 7.41)

NoneNoneNoneNoneRFQX-3299216-1-0147 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-01487.2 Short circuit protection shall be implemented by hardware.
Statement

7.2 Short circuit protection shall be implemented by hardware.

NoneNoneAD-006componentRFQX-3299216-1-0148 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0149If internal components are included in repair kits, the internal electrical connectors shall also be geometrically coded.
Statement

If internal components are included in repair kits, the internal electrical connectors shall also be geometrically coded.

NoneNoneAD-008componentRFQX-3299216-1-0149 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-01507.8 ECU tab headers shall comply with TB1787.(Ref 14.6) 7.9 ECU tab headers shall be made of self-extinguishing materials (i.e.
Statement

7.8 ECU tab headers shall comply with TB1787.(Ref 14.6) 7.9 ECU tab headers shall be made of self-extinguishing materials (i.e.

NoneNoneAD-006componentRFQX-3299216-1-0150 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-01516.3mm Tin, Sn ≥3 μm thick.
Statement

6.3mm Tin, Sn ≥3 μm thick. ≥1 µm Ni

NoneNoneNoneNoneRFQX-3299216-1-0151 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-01522.8mm Gold, Au ≥0,8 μm thick.
Statement

2.8mm Gold, Au ≥0,8 μm thick. ≥1 µm Ni

NoneNoneNoneNoneRFQX-3299216-1-0152 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0153The ECA can be connected to the battery+ (30) permanently through the system fuse or through a master switch that physically cuts off power.
Statement

The ECA can be connected to the battery+ (30) permanently through the system fuse or through a master switch that physically cuts off power. All power used by the ECA shall be taken from this battery connection.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0153 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0154The ECA is connected directly to the battery GND (31).
Statement

The ECA is connected directly to the battery GND (31). This ground connection will act as system ground and reference for the entire ECA. The ground shall not be DC connected to the ECA housing. Requirements Power cable dimension: Operating parameters Remark Min Typ. Max. Unit

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0154 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0155Power cable length: - - 2*6000 mm
Statement

Power cable length: - - 2*6000 mm

NoneNoneNoneNoneRFQX-3299216-1-0155 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0156System fuse: - 601|2
Statement

A 1. According to ISO 8820-5:2015 SF30 type fuse-links. 2. According to ISO 8820-5:2015 SF51 type fuse-links.

NoneNoneNoneNoneRFQX-3299216-1-0156 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0157Umax: - - 32/36/48 A Specific test relations TBD
Statement

Umax: - - 32/36/48 A Specific test relations TBD

NoneNoneNoneNoneRFQX-3299216-1-0157 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0158Umin: 16 - - V
Statement

CVS41 limits may go below this value. Valid only for ECU and communication function. For clutch actuation see req. 5.13

NoneNoneNoneNoneRFQX-3299216-1-0158 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0159Peak current (Ipeak): - - See
Statement

Figure 133 A 3. Up to 100 kHz

NoneNoneNoneNoneRFQX-3299216-1-0159 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0160All power used by the ECA shall be taken from this battery connection.
Statement

All power used by the ECA shall be taken from this battery connection.

NoneNoneAD-008componentRFQX-3299216-1-0160 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0161The ground shall not be DC connected to the ECA housing.
Statement

The ground shall not be DC connected to the ECA housing.

NoneNoneAD-008componentRFQX-3299216-1-0161 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-01627.23 Quiescent current: According to CVS41 (Ref 14.2), must be met independent of input and output conditions.
Statement

7.23 Quiescent current: According to CVS41 (Ref 14.2), must be met independent of input and output conditions.

NoneNoneAD-008componentRFQX-3299216-1-0162 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0163It shall be used to control the power up sequence to the µP.
Statement

It shall be used to control the power up sequence to the µP.

NoneNoneAD-002componentRFQX-3299216-1-0163 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0164The Wake-up signal shall also be connected to a digital input on the µP.
Statement

The Wake-up signal shall also be connected to a digital input on the µP.

NoneNoneAD-005interfaceRFQX-3299216-1-0164 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0165Special precautions shall be taken to prevent direct connection between Wake-up and 30 in case of a single failure.
Statement

Special precautions shall be taken to prevent direct connection between Wake-up and 30 in case of a single failure.

NoneNoneAD-008componentRFQX-3299216-1-0165 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0166After the wake-up line goes to high state: The ECA shall communicate on the CAN line within 250ms in case of a normal start -up The ECA shall be ready to open the clutch within 350ms in case of a normal start -up The ECA shall be ready to open the clutch as soon as possible after necessary movements in case of an abnormal start-up.
Statement

After the wake-up line goes to high state: The ECA shall communicate on the CAN line within 250ms in case of a normal start -up The ECA shall be ready to open the clutch within 350ms in case of a normal start -up The ECA shall be ready to open the clutch as soon as possible after necessary movements in case of an abnormal start-up.

NoneNoneAD-005interfaceRFQX-3299216-1-0166 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0167After movement and reset, the ECA shall communicate on the CAN line within 250ms After movement and reset, the ECA shall be ready to open the clutch within 400ms In the case if the wake-up goes "high" at the same time as U30 signal the ECA should be ready to open the clutch within 3 seconds.
Statement

After movement and reset, the ECA shall communicate on the CAN line within 250ms After movement and reset, the ECA shall be ready to open the clutch within 400ms In the case if the wake-up goes "high" at the same time as U30 signal the ECA should be ready to open the clutch within 3 seconds.

NoneNoneAD-005interfaceRFQX-3299216-1-0167 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0168Definition ready to open clutch: The actuator position shall be between FCCP and FCCP -3mm and the ECA is capable to move to disengaged clutch directly when requeste d.
Statement

Definition ready to open clutch: The actuator position shall be between FCCP and FCCP -3mm and the ECA is capable to move to disengaged clutch directly when requeste d.

NoneNoneAD-008componentRFQX-3299216-1-0168 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0169Redundancies due improper shutdown shall be aligned with Traton.
Statement

Redundancies due improper shutdown shall be aligned with Traton.

NoneNoneAD-008componentRFQX-3299216-1-0169 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0170If a signal for disengaging the clutch is received the ECA shall actuate the request regardless of CAN-request.
Statement

If a signal for disengaging the clutch is received the ECA shall actuate the request regardless of CAN-request.

NoneNoneAD-005interfaceRFQX-3299216-1-0170 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0171The ECA has one CAN bus.
Statement

The ECA has one CAN bus. Any watchdog circuit shall have no influence on the CAN bus The CAN front end shall be designed to comply with TB1905 (Ref 14.3), with the following additional information in this chapter.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0171 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0172The controller and transceiver shall be CAN FD ready Parameter Limit values Unit Remarks Min.
Statement

The controller and transceiver shall be CAN FD ready Parameter Limit values Unit Remarks Min. Typ. Max.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0172 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0173Baud rate for
Statement

CAN FD: 4000 - - kbit/s Figure 15 - Reference circuit

NoneNoneNoneNoneRFQX-3299216-1-0173 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0174Any watchdog circuit shall have no influence on the CAN bus.
Statement

Any watchdog circuit shall have no influence on the CAN bus.

NoneNoneAD-005interfaceRFQX-3299216-1-0174 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0175The CAN front end shall be designed to comply with TB1905 (Ref 14.3), with the following additional information in this chapter.
Statement

The CAN front end shall be designed to comply with TB1905 (Ref 14.3), with the following additional information in this chapter.

NoneNoneAD-005interfaceRFQX-3299216-1-0175 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-01767.36 Termination resistance: - 2 x 60 - Ω 1% resistors shall be used 7.37 Baud rate: 250 500 1000 kbit/s Flashing in production shall be possible with 1000kbit/s.
Statement

7.36 Termination resistance: - 2 x 60 - Ω 1% resistors shall be used 7.37 Baud rate: 250 500 1000 kbit/s Flashing in production shall be possible with 1000kbit/s.

NoneNoneAD-008componentRFQX-3299216-1-0176 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0177Note
Statement

The layout shall always be present on the PCB and the supplier must be flexible in changing/removing the CAN related components in this section.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0177 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0178CAN_Shield
Statement

CAN shield. Footprint prepared for internal connection to system ground 31_ECA via a resistor and a capacitor in series. The components shall not be populated by default. The CAN front end shall be designed to comply with TB1905. (Ref 14.3)

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-3299216-1-0178 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0179The components shall not be populated by default.
Statement

The components shall not be populated by default.

NoneNoneAD-008componentRFQX-3299216-1-0179 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0180The CAN front end shall be designed to comply with TB1905.
Statement

The CAN front end shall be designed to comply with TB1905.

NoneNoneAD-005interfaceRFQX-3299216-1-0180 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0181Ventilation
Statement

The air inside the electronics enclosure shall be ventilated with the use of a membrane. The following requirements shall be fulfilled: The unit shall withstand the salt-spray environment, according to CVS40 §6.1.6, without clogging of the membrane. The membrane shall be placed so that it is protected against blunt force, falling dust and dripping salt-water. The design shall be made to prevent accumulation of water on top of the membrane, or in the cavity of the membrane.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0181 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0182The quality of the wire bonding and position shall be properly analyzed.
Statement

The quality of the wire bonding and position shall be properly analyzed.

NoneNoneAD-008componentRFQX-3299216-1-0182 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0183The material shall be lead free and of ”high temperatures solder type”.
Statement

The material shall be lead free and of ”high temperatures solder type”.

NoneNoneAD-008componentRFQX-3299216-1-0183 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0184The melting point of the soldering material and the composition of the soldering material shall be declared by supplier.
Statement

The melting point of the soldering material and the composition of the soldering material shall be declared by supplier.

NoneNoneAD-008componentRFQX-3299216-1-0184 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0185The PCB must be supported and must not bent in any direction during the process.
Statement

The PCB must be supported and must not bent in any direction during the process.

NoneNoneAD-003componentRFQX-3299216-1-0185 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0186Conformal coating or lacquer shall cover the entire PCB and all solder joints.
Statement

Conformal coating or lacquer shall cover the entire PCB and all solder joints.

NoneNoneAD-008componentRFQX-3299216-1-0186 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0187The layout of the PCB, including component placement, shall take the applying of conformal coating into consideration so that the aforementioned requirement can be met.
Statement

The layout of the PCB, including component placement, shall take the applying of conformal coating into consideration so that the aforementioned requirement can be met.

NoneNoneAD-005interfaceRFQX-3299216-1-0187 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0188shall be specified in the initial offer.
Statement

shall be specified in the initial offer.

NoneNoneAD-008componentRFQX-3299216-1-0188 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0189The conformal coating process and materials shall apply to the latest versions of IPC/EIA J-STD-001 (with applicable standards as e.g.
Statement

The conformal coating process and materials shall apply to the latest versions of IPC/EIA J-STD-001 (with applicable standards as e.g.

NoneNoneAD-003componentRFQX-3299216-1-0189 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0190HDBK-001, IPC-CC-830 and HDBK-830) and the visual appearance of the final coating shall be consistent with the latest version of IPC-A-610.
Statement

HDBK-001, IPC-CC-830 and HDBK-830) and the visual appearance of the final coating shall be consistent with the latest version of IPC-A-610.

NoneNoneAD-008componentRFQX-3299216-1-0190 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0191Water based and silicone lacquers shall not be used.
Statement

Water based and silicone lacquers shall not be used.

NoneNoneAD-008componentRFQX-3299216-1-0191 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0192The following requirements shall be fulfilled: The unit shall withstand the salt-spray environment, according to CVS40 §6.1.6, without clogging of the membrane.
Statement

The following requirements shall be fulfilled: The unit shall withstand the salt-spray environment, according to CVS40 §6.1.6, without clogging of the membrane.

NoneNoneAD-008componentRFQX-3299216-1-0192 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0193The membrane shall be placed so that it is protected against blunt force, falling dust and dripping salt-water.
Statement

The membrane shall be placed so that it is protected against blunt force, falling dust and dripping salt-water.

NoneNoneAD-002componentRFQX-3299216-1-0193 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0194The design shall be made to prevent accumulation of water on top of the membrane, or in the cavity of the membrane.
Statement

The design shall be made to prevent accumulation of water on top of the membrane, or in the cavity of the membrane.

NoneNoneAD-008componentRFQX-3299216-1-0194 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-01957.46 Forbidden components: BGA capsule in any form must not be used.
Statement

7.46 Forbidden components: BGA capsule in any form must not be used.

NoneNoneAD-008componentRFQX-3299216-1-0195 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0196Tantalum capacitors must not be used Serial resistors on power supply circuits must not be used.
Statement

Tantalum capacitors must not be used Serial resistors on power supply circuits must not be used.

NoneNoneAD-008componentRFQX-3299216-1-0196 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0197The life length requirement is minimum 3000 operating hours per year for 15 years
Statement

The life length requirement is minimum 3000 operating hours per year for 15 years

NoneNoneNoneNoneRFQX-3299216-1-0197 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0198The clutch actuator shall withstand 6 500 000 actuations with the test cycle described in Appendix B.
Statement

The clutch actuator shall withstand 6 500 000 actuations with the test cycle described in Appendix B.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0198 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0199The ECA must be maintenance free over the whole life time
Statement

The ECA must be maintenance free over the whole life time

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0199 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0200The maintenance window cover (See req.
Statement

The maintenance window cover (See req. 4.17) shall be provided as a spare part

SSR-LIFE-002Lifecycle / Field Return / Decommissioning — Lifecycle / Field Return / DecommissioningAD-008componentRFQX-3299216-1-0200 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0201In a situation where the ECA has jammed, and is holding the clutch open, it shall be possible to remove the clutch force by following an instruction documented on the ECA drawing.
Statement

In a situation where the ECA has jammed, and is holding the clutch open, it shall be possible to remove the clutch force by following an instruction documented on the ECA drawing. It is allowed to destroy the ECA in the process.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-3299216-1-0201 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-02028.4 Six consecutive units shall run past 6.5M actuations at the supplier, and continue to end of life.
Statement

8.4 Six consecutive units shall run past 6.5M actuations at the supplier, and continue to end of life.

NoneNoneAD-008componentRFQX-3299216-1-0202 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0203Three consecutive units shall run past 6.5M actuations at Scania, and continue to end of life.
Statement

Three consecutive units shall run past 6.5M actuations at Scania, and continue to end of life.

NoneNoneAD-008componentRFQX-3299216-1-0203 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-02048.6 Failure rate for ECU and electronics shall be less than: 0ppm @ “0” km 200ppm/year during year 1-5 400ppm/year during year 6-10 1000ppm/year during year 11-15 8.7 External vulnerable components might need to be replaceable.
Statement

8.6 Failure rate for ECU and electronics shall be less than: 0ppm @ “0” km 200ppm/year during year 1-5 400ppm/year during year 6-10 1000ppm/year during year 11-15 8.7 External vulnerable components might need to be replaceable.

NoneNoneAD-006componentRFQX-3299216-1-0204 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0205Spare parts or repair kits shall be defined together in agreement.
Statement

Spare parts or repair kits shall be defined together in agreement.

NoneNoneAD-008componentRFQX-3299216-1-0205 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-02064.17) shall be provided as a spare part.
Statement

4.17) shall be provided as a spare part.

NoneNoneAD-008componentRFQX-3299216-1-0206 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0207The ECA shall fulfil the requirements stated in STD3868 STD3868 is a comprehensive document referring to several underlying standards.
Statement

The ECA shall fulfil the requirements stated in STD3868 STD3868 is a comprehensive document referring to several underlying standards. Out of a recycling and environmental perspective the following standards shall be taken under consideration in addition to CVS55(Ref 14.32): STD4158, Chemical substances which shall not be used – Scania Black list. STD4159, Chemical substances with limited use – Scania Grey list. CVS 83, Material declaration according to Scania IMDS reporting std. The different parts of the housing shall be marked according to material content. The ECA shall be lead free.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0207 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0208All included parts shall fulfil applicable sections of Part 9 in Annex B to the latest ADR ,as applicable at the time of type approval.
Statement

All included parts shall fulfil applicable sections of Part 9 in Annex B to the latest ADR ,as applicable at the time of type approval. For type approval, the vehicle and its components shall comply with ECE Regulation No. 105 and with European Directive 2008/68/EC, as amended.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0208 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0209Out of a recycling and environmental perspective the following standards shall be taken under consideration in addition to CVS55(Ref 14.32): STD4158, Chemical substances which shall not be used – Scania Black list.
Statement

Out of a recycling and environmental perspective the following standards shall be taken under consideration in addition to CVS55(Ref 14.32): STD4158, Chemical substances which shall not be used – Scania Black list.

NoneNoneAD-008componentRFQX-3299216-1-0209 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0210The different parts of the housing shall be marked according to material content.
Statement

The different parts of the housing shall be marked according to material content.

NoneNoneAD-008componentRFQX-3299216-1-0210 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0211The ECA shall be lead free.
Statement

The ECA shall be lead free.

NoneNoneAD-008componentRFQX-3299216-1-0211 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0212For type approval, the vehicle and its components shall comply with ECE Regulation No.
Statement

For type approval, the vehicle and its components shall comply with ECE Regulation No.

NoneNoneAD-008componentRFQX-3299216-1-0212 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0213The ECA must fulfil the general requirements for Electronic Control Units (ECUs), which are stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2).
Statement

The ECA must fulfil the general requirements for Electronic Control Units (ECUs), which are stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0213 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0214The ECA must not be dependent on software for protection against requirements stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2).
Statement

The ECA must not be dependent on software for protection against requirements stated in CVS40 (Ref 14.1) and CVS41 (Ref 14.2).

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-3299216-1-0214 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0215CAN communication shall not be affected.
Statement

CAN communication shall not be affected.

NoneNoneAD-005interfaceRFQX-3299216-1-0215 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0216Memory functions shall remain Class A.
Statement

Memory functions shall remain Class A.

NoneNoneAD-006componentRFQX-3299216-1-0216 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0217Accepted behaviour in this case shall be agreed upon between Traton and Supplier.
Statement

Accepted behaviour in this case shall be agreed upon between Traton and Supplier.

NoneNoneAD-008componentRFQX-3299216-1-0217 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0218For this unit, the following definitions of test procedure I and test procedure II shall be used Test procedure I A comprehensive test where all functional requirements are verified.
Statement

For this unit, the following definitions of test procedure I and test procedure II shall be used Test procedure I A comprehensive test where all functional requirements are verified. This test shall be performed before and after exposure. Test procedure I (See Figure 17 - Test procedure I) shall at least contain: - Full stroke to evaluate speed - Staircase to evaluate accuracy - Power loss to evaluate safety Figure 17 - Test procedure I Test procedure II A reduced function test where the fundamental requirements are verified. This test shall be possible to perform during exposure. Reduced versions of test procedure II may be agreed and used during various tests. Alternative 1: Test cycle according to Appendix B, frequency 10 to 30 strokes per minute. Alternative 2: Release frequency test according to req. 5.12.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-3299216-1-0218 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0219This test shall be performed before and after exposure.
Statement

This test shall be performed before and after exposure.

NoneNoneAD-008componentRFQX-3299216-1-0219 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0220Test procedure I (See Figure 17 - Test procedure I) shall at least contain: - Full stroke to evaluate speed - Staircase to evaluate accuracy - Power loss to evaluate safety Figure 17 - Test procedure I Test procedure II A reduced function test where the fundamental requirements are verified.
Statement

Test procedure I (See Figure 17 - Test procedure I) shall at least contain: - Full stroke to evaluate speed - Staircase to evaluate accuracy - Power loss to evaluate safety Figure 17 - Test procedure I Test procedure II A reduced function test where the fundamental requirements are verified.

NoneNoneAD-001componentRFQX-3299216-1-0220 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0221This test shall be possible to perform during exposure.
Statement

This test shall be possible to perform during exposure.

NoneNoneAD-008componentRFQX-3299216-1-0221 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0222Reduced versions of test procedure II may be agreed and used during various tests.
Statement

Reduced versions of test procedure II may be agreed and used during various tests.

NoneNoneNoneNoneRFQX-3299216-1-0222 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0223CVS40 §5.5 TC-05 Temperature cycle test Tmax.tes= +120°C, Tmin.test=-40°C Y
Statement

CVS40 §5.5 TC-05 Temperature cycle test Tmax.tes= +120°C, Tmin.test=-40°C Y

NoneNoneNoneNoneRFQX-3299216-1-0223 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0224CVS40 §5.6 TC-06 Thermal shock Y
Statement

CVS40 §5.6 TC-06 Thermal shock Y

NoneNoneNoneNoneRFQX-3299216-1-0224 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0225CVS40 §5.7 TC-07 Splash water test Y
Statement

CVS40 §5.7 TC-07 Splash water test Y

NoneNoneNoneNoneRFQX-3299216-1-0225 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0226CVS40 §5.8 TC-08 Ice water / hot air shock test It is not allowed to use a snorkel to pass this test Y
Statement

CVS40 §5.8 TC-08 Ice water / hot air shock test It is not allowed to use a snorkel to pass this test Y

NoneNoneNoneNoneRFQX-3299216-1-0226 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0227CVS40 §5.9 TC-09 Leakage search test Y
Statement

CVS40 §5.9 TC-09 Leakage search test Y

NoneNoneNoneNoneRFQX-3299216-1-0227 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0228CVS40 §5.10 TC-10 Ingress protection The ECA shall also fulfil IP54 without mounted connectors.
Statement

CVS40 §5.10 TC-10 Ingress protection The ECA shall also fulfil IP54 without mounted connectors. IP classes to test: IP6K6K, IP6K7, and IP6K9K Y

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0228 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0229CVS40 §5.11 TC-11 Corrosion in flowing mixed noxious gas N
Statement

CVS40 §5.11 TC-11 Corrosion in flowing mixed noxious gas N

NoneNoneNoneNoneRFQX-3299216-1-0229 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0230CVS40 §5.12 TC-12 Salt spray test Y
Statement

CVS40 §5.12 TC-12 Salt spray test Y

NoneNoneNoneNoneRFQX-3299216-1-0230 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0231CVS40 §5.13 TC-13 Dirt spray test TBD
Statement

CVS40 §5.13 TC-13 Dirt spray test TBD

NoneNoneNoneNoneRFQX-3299216-1-0231 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0232CVS40 §6.2 TM-01 Resonance search Y
Statement

CVS40 §6.2 TM-01 Resonance search Y

NoneNoneNoneNoneRFQX-3299216-1-0232 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0233CVS40 §6.3 TM-02 Mechanical shock TBD
Statement

CVS40 §6.3 TM-02 Mechanical shock TBD

NoneNoneNoneNoneRFQX-3299216-1-0233 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0234CVS40 §6.4 TM-03 Random vibration and thermal cycle P1 Test 2 Y
Statement

CVS40 §6.4 TM-03 Random vibration and thermal cycle P1 Test 2 Y

NoneNoneNoneNoneRFQX-3299216-1-0234 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0235CVS40 §6.5 TM-04 Gravel bombardment and impact Y
Statement

CVS40 §6.5 TM-04 Gravel bombardment and impact Y

NoneNoneNoneNoneRFQX-3299216-1-0235 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0236CVS40 §6.6 TM-05 External forces Y
Statement

CVS40 §6.6 TM-05 External forces Y

NoneNoneNoneNoneRFQX-3299216-1-0236 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0237CVS40 §6.7 TM-06 Drop test – Free fall Y
Statement

CVS40 §6.7 TM-06 Drop test – Free fall Y

NoneNoneNoneNoneRFQX-3299216-1-0237 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0238CVS40 §7.1 TL-01 Life length As per Chapter 8 Y
Statement

CVS40 §7.1 TL-01 Life length As per Chapter 8 Y

NoneNoneNoneNoneRFQX-3299216-1-0238 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0239CVS40 §7.2.1 TL-02 Power cycling test Y
Statement

CVS40 §7.2.1 TL-02 Power cycling test Y

NoneNoneNoneNoneRFQX-3299216-1-0239 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0240CVS40 §7.2.2 TL-03 Extended thermal shock air TBD
Statement

CVS40 §7.2.2 TL-03 Extended thermal shock air TBD

NoneNoneNoneNoneRFQX-3299216-1-0240 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0241CVS40 §7.2.3 TL-04 High temperature endurance test TBD
Statement

CVS40 §7.2.3 TL-04 High temperature endurance test TBD

NoneNoneNoneNoneRFQX-3299216-1-0241 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0242CVS40 §7.2.4 TL-05 Endurance test / actuation TBD
Statement

CVS40 §7.2.4 TL-05 Endurance test / actuation TBD

NoneNoneNoneNoneRFQX-3299216-1-0242 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0243CVS40 §7.3 TL-06 Component specific test TBD
Statement

CVS40 §7.3 TL-06 Component specific test TBD

NoneNoneNoneNoneRFQX-3299216-1-0243 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0244CVS40 §7.4 TL-07 Ageing Y
Statement

CVS40 §7.4 TL-07 Ageing Y

NoneNoneNoneNoneRFQX-3299216-1-0244 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0245CVS40 §8.1 TS-01 Flammability In order to fulfil flammability demands, any plastic materials (i.e.
Statement

CVS40 §8.1 TS-01 Flammability In order to fulfil flammability demands, any plastic materials (i.e. tab headers) shall be made of self- extinguishing materials (i.e. UL94). Y

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-3299216-1-0245 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-3299216-1-0246CVS40 §8.2 TS-02 UV resistance Datasheet sufficient Y
Statement

CVS40 §8.2 TS-02 UV resistance Datasheet sufficient Y

NoneNoneNoneNoneRFQX-3299216-1-0246 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0247CVS40 §8.3 TS-03 Chemical resistance Application method TBD Y
Statement

CVS40 §8.3 TS-03 Chemical resistance Application method TBD Y

NoneNoneNoneNoneRFQX-3299216-1-0247 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0248CVS40 §8.4 TE-01 Isolation resistance and Dielectric strength tests N Exceptions and additional information to CVS41 [Y/N]
Statement

CVS40 §8.4 TE-01 Isolation resistance and Dielectric strength tests N Exceptions and additional information to CVS41 [Y/N]

NoneNoneNoneNoneRFQX-3299216-1-0248 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0249CVS41 §4 Electrical loads Y
Statement

CVS41 §4 Electrical loads Y

NoneNoneNoneNoneRFQX-3299216-1-0249 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0250CVS41 §4.1 TE-00 Operating Voltage Class A for ECU and communication.
Statement

CVS41 §4.1 TE-00 Operating Voltage Class A for ECU and communication. Class B for clutch actuation Y

NoneNoneNoneNoneRFQX-3299216-1-0250 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0251CVS41 §4.2 TE-01 Operating Voltage (Long-term overvoltage) Umax: 15 min, functional status Class B Y
Statement

CVS41 §4.2 TE-01 Operating Voltage (Long-term overvoltage) Umax: 15 min, functional status Class B Y

NoneNoneNoneNoneRFQX-3299216-1-0251 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0252CVS41 §4.3 TE-02 Transient Overvoltage Y
Statement

CVS41 §4.3 TE-02 Transient Overvoltage Y

NoneNoneNoneNoneRFQX-3299216-1-0252 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0253CVS41 §4.4 TE-03 Transient Undervoltage Y
Statement

CVS41 §4.4 TE-03 Transient Undervoltage Y

NoneNoneNoneNoneRFQX-3299216-1-0253 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0254CVS41 §4.5 TE-04 Jump start Y
Statement

CVS41 §4.5 TE-04 Jump start Y

NoneNoneNoneNoneRFQX-3299216-1-0254 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0255CVS41 §4.6 TE-05 Load dump, test pulse 5b Y
Statement

CVS41 §4.6 TE-05 Load dump, test pulse 5b Y

NoneNoneNoneNoneRFQX-3299216-1-0255 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0256tab headers) shall be made of self- extinguishing materials (i.e.
Statement

tab headers) shall be made of self- extinguishing materials (i.e.

NoneNoneAD-008componentRFQX-3299216-1-0256 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0257CVS46 §4.6.6 Test LFM: Low Frequency Magnetic Y
Statement

CVS46 §4.6.6 Test LFM: Low Frequency Magnetic Y

NoneNoneNoneNoneRFQX-3299216-1-0257 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0258CVS46 §4.7 Test VCB CTE N
Statement

CVS46 §4.7 Test VCB CTE N

NoneNoneNoneNoneRFQX-3299216-1-0258 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0259CVS46 §4.8 Test VCB AN and VCB CP N
Statement

CVS46 §4.8 Test VCB AN and VCB CP N

NoneNoneNoneNoneRFQX-3299216-1-0259 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0260CVS46 §4.9 Test C-VCB-VCA N
Statement

CVS46 §4.9 Test C-VCB-VCA N

NoneNoneNoneNoneRFQX-3299216-1-0260 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0261CVS46 §4.10 Test TSUP VCB A N
Statement

CVS46 §4.10 Test TSUP VCB A N

NoneNoneNoneNoneRFQX-3299216-1-0261 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0262CVS46 §4.11 Test TSUP VCB B N
Statement

CVS46 §4.11 Test TSUP VCB B N

NoneNoneNoneNoneRFQX-3299216-1-0262 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0263CVS46 §4.12 Test VCB Surge N
Statement

CVS46 §4.12 Test VCB Surge N

NoneNoneNoneNoneRFQX-3299216-1-0263 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0264CVS46 §4.13 Test VCB Burst N
Statement

CVS46 §4.13 Test VCB Burst N

NoneNoneNoneNoneRFQX-3299216-1-0264 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0265CVS46 §4.14 Test VCB Charging mode N
Statement

CVS46 §4.14 Test VCB Charging mode N

NoneNoneNoneNoneRFQX-3299216-1-0265 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0266CVS46 §4.15 Test ESD: Immunity to electrostatic discharge (ESD) Y
Statement

CVS46 §4.15 Test ESD: Immunity to electrostatic discharge (ESD) Y

NoneNoneNoneNoneRFQX-3299216-1-0266 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0267CVS46 §4.15.1 Test ESDD: Direct Discharge, Powered up Y
Statement

CVS46 §4.15.1 Test ESDD: Direct Discharge, Powered up Y

NoneNoneNoneNoneRFQX-3299216-1-0267 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0268CVS46 §4.15.2 Test ESDI: Indirect Discharge (Powered up) Y
Statement

CVS46 §4.15.2 Test ESDI: Indirect Discharge (Powered up) Y

NoneNoneNoneNoneRFQX-3299216-1-0268 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0269CVS46 §4.15.3 Test ESDH: ESD Handling, Component not energised Y
Statement

CVS46 §4.15.3 Test ESDH: ESD Handling, Component not energised Y

NoneNoneNoneNoneRFQX-3299216-1-0269 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0270CVS46 §5.1 Vehicle test ESD Traton performs Vehicle test, Traton may need support from supplier with any issues originating from the component.
Statement

CVS46 §5.1 Vehicle test ESD Traton performs Vehicle test, Traton may need support from supplier with any issues originating from the component. Y

NoneNoneNoneNoneRFQX-3299216-1-0270 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0271CVS46 §5.2 Vehicle test RE: Emitted interference of the complete vehicle Y
Statement

CVS46 §5.2 Vehicle test RE: Emitted interference of the complete vehicle Y

NoneNoneNoneNoneRFQX-3299216-1-0271 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0272CVS46 §5.2.1 Vehicle test RE: Protection of receivers outside the vehicle Y
Statement

CVS46 §5.2.1 Vehicle test RE: Protection of receivers outside the vehicle Y

NoneNoneNoneNoneRFQX-3299216-1-0272 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0273CVS46 §5.2.2 Vehicle test RE: Self interference Y
Statement

CVS46 §5.2.2 Vehicle test RE: Self interference Y

NoneNoneNoneNoneRFQX-3299216-1-0273 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0274CVS46 §5.3 Vehicle test charging: Vehicle in the AC charging mode N
Statement

CVS46 §5.3 Vehicle test charging: Vehicle in the AC charging mode N

NoneNoneNoneNoneRFQX-3299216-1-0274 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0275CVS46 §5.3.1 Vehicle test: AC charging Vehicle in AC charging mode N
Statement

CVS46 §5.3.1 Vehicle test: AC charging Vehicle in AC charging mode N

NoneNoneNoneNoneRFQX-3299216-1-0275 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0276CVS46 §5.3.2 Vehicle test: DC charging: Vehicle in DC charging mode N
Statement

CVS46 §5.3.2 Vehicle test: DC charging: Vehicle in DC charging mode N

NoneNoneNoneNoneRFQX-3299216-1-0276 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0277CVS46 §5.4 Vehicle test RI: Immunity of vehicles to radiated fields Traton performs Vehicle test, Traton may need support from supplier with Y
Statement

CVS46 §5.4 Vehicle test RI: Immunity of vehicles to radiated fields Traton performs Vehicle test, Traton may need support from supplier with Y

NoneNoneNoneNoneRFQX-3299216-1-0277 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0278CVS46 §5.4.1 Vehicle test RI: External interference sources Y
Statement

CVS46 §5.4.1 Vehicle test RI: External interference sources Y

NoneNoneNoneNoneRFQX-3299216-1-0278 / 24hNot importedStill Requires Customer DecisionNo P1 linkevidence completenessMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0279P 1 Page 11 Functional safety The ECA is a part of a safety critical system and shall be handled as such.
Statement

P 1 Page 11 Functional safety The ECA is a part of a safety critical system and shall be handled as such.

NoneNoneAD-008componentRFQX-3299216-1-0279 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0280The ECA shall therefore be developed and implemented in accordance with the objectives and requirements of ISO 26262 "Road vehicles - Functional Safety".
Statement

The ECA shall therefore be developed and implemented in accordance with the objectives and requirements of ISO 26262 "Road vehicles - Functional Safety".

NoneNoneAD-003componentRFQX-3299216-1-0280 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0281The supplier shall analyse risks of individua l HW and SW components, mechanics, and any other technologies, independently of the scope of ISO 26262.
Statement

The supplier shall analyse risks of individua l HW and SW components, mechanics, and any other technologies, independently of the scope of ISO 26262.

NoneNoneAD-003componentRFQX-3299216-1-0281 / 24hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0282For this purpose possible causes must be systematically identified.
Statement

For this purpose possible causes must be systematically identified.

NoneNoneAD-008componentRFQX-3299216-1-0282 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0283For these analyses at least the methods in ISO 26262 shall be applied.
Statement

For these analyses at least the methods in ISO 26262 shall be applied.

NoneNoneAD-003componentRFQX-3299216-1-0283 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0284Field test Traton will perform field tests with the unit mounted in trucks
Statement

Field test Traton will perform field tests with the unit mounted in trucks

NoneNoneNoneNoneRFQX-3299216-1-0284 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0285Testability
Statement

The supplier of the unit must write software to enable his own testing of the unit during development, production and on any claimed unit.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-3299216-1-0285 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-3299216-1-0286ID Verification methods 12.1 Conformance to Requirement Specification A1 The supplier must do conformance test of all external and internal I/O.
Statement

ID Verification methods 12.1 Conformance to Requirement Specification A1 The supplier must do conformance test of all external and internal I/O.

NoneNoneAD-008componentRFQX-3299216-1-0286 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0287This test must verify that all internal and external I/O fulfils the requirements in this specification.
Statement

This test must verify that all internal and external I/O fulfils the requirements in this specification.

NoneNoneAD-008componentRFQX-3299216-1-0287 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0288A2 The supplier must perform full DV (Design Verification at B-sample level) and full PV (Product Validation at C-sample level) environmental test programs according to CVS40 and CVS41 (incl.
Statement

A2 The supplier must perform full DV (Design Verification at B-sample level) and full PV (Product Validation at C-sample level) environmental test programs according to CVS40 and CVS41 (incl.

NoneNoneAD-008componentRFQX-3299216-1-0288 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0289the suppler must carry out two full test rounds according to the Traton test requirements.
Statement

the suppler must carry out two full test rounds according to the Traton test requirements.

NoneNoneAD-008componentRFQX-3299216-1-0289 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0290Additional tests initiated and performed by the supplier must be discussed with Traton.
Statement

Additional tests initiated and performed by the supplier must be discussed with Traton.

NoneNoneAD-008componentRFQX-3299216-1-0290 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0291A3 The supplier must test the connectors according to TB1787.
Statement

A3 The supplier must test the connectors according to TB1787.

NoneNoneAD-008componentRFQX-3299216-1-0291 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0292A4 The supplier must do EMC tests with the unit alone.
Statement

A4 The supplier must do EMC tests with the unit alone.

NoneNoneAD-008componentRFQX-3299216-1-0292 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0293The supplier must certify the ECA according to UN ECE R10 (EMC), according to the latest revision with all amendments.
Statement

The supplier must certify the ECA according to UN ECE R10 (EMC), according to the latest revision with all amendments.

NoneNoneAD-008componentRFQX-3299216-1-0293 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0294A5 The supplier must check that both prototypes and serial units fulfil the dimension requirement according to any relevant Traton supplied drawings.
Statement

A5 The supplier must check that both prototypes and serial units fulfil the dimension requirement according to any relevant Traton supplied drawings.

NoneNoneAD-008componentRFQX-3299216-1-0294 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0295A6 All prototypes and serial ECA’s shall fulfil requirements according to TB1822, IPC/EIA J-STD-001 class 3 and IPC-A-610 class 3.
Statement

A6 All prototypes and serial ECA’s shall fulfil requirements according to TB1822, IPC/EIA J-STD-001 class 3 and IPC-A-610 class 3.

NoneNoneAD-008componentRFQX-3299216-1-0295 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-3299216-1-0296However, dividing sample phases into several generations must be agreed upon between Traton and the supplier.
Statement

However, dividing sample phases into several generations must be agreed upon between Traton and the supplier.

NoneNoneAD-008componentRFQX-3299216-1-0296 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0297All samples shall be functionally tested before sent to Traton.
Statement

All samples shall be functionally tested before sent to Traton.

NoneNoneAD-008componentRFQX-3299216-1-0297 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0298Deviations shall be reported as a part of the sample delivery.
Statement

Deviations shall be reported as a part of the sample delivery.

NoneNoneAD-008componentRFQX-3299216-1-0298 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0299Dimensional checks shall be performed for B and C-samples prior to delivery to Traton.
Statement

Dimensional checks shall be performed for B and C-samples prior to delivery to Traton.

NoneNoneAD-008componentRFQX-3299216-1-0299 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0300The supplier must use the sample denominations requested by Traton.
Statement

The supplier must use the sample denominations requested by Traton.

NoneNoneAD-008componentRFQX-3299216-1-0300 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0301Unless otherwise stated, valid version is the latest available as of 1st May 2026.
Statement

Unless otherwise stated, valid version is the latest available as of 1st May 2026.

NoneNoneNoneNoneRFQX-3299216-1-0301 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-3299216-1-0302P 1 Page Appendix B – Life length test The life time testing of the ECA shall consist of 6500000 repetitions of the test cycle described in ”I – Test cycle” Two different test profiles/setups can be used.
Statement

P 1 Page Appendix B – Life length test The life time testing of the ECA shall consist of 6500000 repetitions of the test cycle described in ”I – Test cycle” Two different test profiles/setups can be used.

NoneNoneAD-005interfaceRFQX-3299216-1-0302 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0303and 5.2.
Statement

and 5.2.

NoneNoneAD-008componentRFQX-3299216-1-0303 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredMISSING SYSTEM REQUIREMENT
RFQX-3299216-1-0304Between the two movements the actuator should remain in the fully disengaged position.
Statement

Between the two movements the actuator should remain in the fully disengaged position.

NoneNoneAD-008componentRFQX-3299216-1-0304 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0305After the complete engagement the actuator should remain in this position until the next disengagement is requested.
Statement

After the complete engagement the actuator should remain in this position until the next disengagement is requested.

NoneNoneAD-008componentRFQX-3299216-1-0305 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0306• A function test rig shall be used for function tests between intervals • At 6.25M cycles a function test at -40C as well as the release frequency test is performed, before the rigs are put into run-to-failure mode • Run-to-failure mode implies cycling at intermediate load and RT/80C until failure • @Temp durability will start with 15/min frequency to verify if 30/min is feasible • One rig at RT shall run at 15/min as a reference unit for cycle acceleration.
Statement

• A function test rig shall be used for function tests between intervals • At 6.25M cycles a function test at -40C as well as the release frequency test is performed, before the rigs are put into run-to-failure mode • Run-to-failure mode implies cycling at intermediate load and RT/80C until failure • @Temp durability will start with 15/min frequency to verify if 30/min is feasible • One rig at RT shall run at 15/min as a reference unit for cycle acceleration.

NoneNoneAD-001componentRFQX-3299216-1-0306 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0307,
Statement

,

NoneNoneNoneNoneRFQX-3299216-1-0307 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0308Normal operation, Class A
Statement

Normal operation, Class A

NoneNoneNoneNoneRFQX-3299216-1-0308 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-3299216-1-0309This needs to be checked with the first test run and if necessary the test cycle used in profile B needs to be changed.
Statement

This needs to be checked with the first test run and if necessary the test cycle used in profile B needs to be changed.

NoneNoneNoneNoneRFQX-3299216-1-0309 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0001TRATON Software Update Variant 2 (SUV2) sequence Foreword This Commercial Vehicle Standard (“CVS123-2”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.
Statement

TRATON Software Update Variant 2 (SUV2) sequence Foreword This Commercial Vehicle Standard (“CVS123-2”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.

NoneNoneNoneNoneRFQX-CVS123-2-0001 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0002Any review of this CVS123-2 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.
Statement

Any review of this CVS123-2 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.

NoneNoneAD-003componentRFQX-CVS123-2-0002 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0003The User shall apply the latest version of this CVS123-2.
Statement

The User shall apply the latest version of this CVS123-2.

NoneNoneAD-008componentRFQX-CVS123-2-0003 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0004This document specifies the method to perform software download using Software Update Variant 2 (SUV2).
Statement

This document specifies the method to perform software download using Software Update Variant 2 (SUV2).

NoneNoneNoneNoneRFQX-CVS123-2-0004 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0005The vehicle manufacturer implementation of the Authentication service (0x29) is defined in CVS31 and SecuredDataTransmission service (0x84) is defined in CVS32.
Statement

The vehicle manufacturer implementation of the Authentication service (0x29) is defined in CVS31 and SecuredDataTransmission service (0x84) is defined in CVS32.

NoneNoneNoneNoneRFQX-CVS123-2-0005 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0006While the requirements are applicable for programmable servers, some of the programming steps outlined in this specification (CommunicationControl and ControlDTCSetting) do not primarily target the programmable ECU, but the other ECUs on the same network which need to support the programming of the targeted ECU.
Statement

While the requirements are applicable for programmable servers, some of the programming steps outlined in this specification (CommunicationControl and ControlDTCSetting) do not primarily target the programmable ECU, but the other ECUs on the same network which need to support the programming of the targeted ECU.

NoneNoneNoneNoneRFQX-CVS123-2-0006 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0007Support for programming as well as support for programming of other ECUs on the same network involves supporting what is referred to as pre- and post-programming steps.
Statement

Support for programming as well as support for programming of other ECUs on the same network involves supporting what is referred to as pre- and post-programming steps.

NoneNoneNoneNoneRFQX-CVS123-2-0007 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0008This specification is based on ISO14229-1:2020 and as such supports a “single server” approach to non-volatile memory programming with the intention to simplify client software development without significantly complicating server software development.
Statement

This specification is based on ISO14229-1:2020 and as such supports a “single server” approach to non-volatile memory programming with the intention to simplify client software development without significantly complicating server software development.

NoneNoneNoneNoneRFQX-CVS123-2-0008 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0009With a single server objective, an ECU will appear to be programmable through communication with a single diagnostic server even if the ECU in fact implements two or more diagnostic servers – one in the boot loader and one in each application – and in reality will be programmed through communication with either one of them or both.
Statement

With a single server objective, an ECU will appear to be programmable through communication with a single diagnostic server even if the ECU in fact implements two or more diagnostic servers – one in the boot loader and one in each application – and in reality will be programmed through communication with either one of them or both.

NoneNoneNoneNoneRFQX-CVS123-2-0009 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0010The reason to why an ECU must implement two or more diagnostic servers is that it needs to support two or more different ECU configurations: one for which no application is installed and one or more for which applications are installed in the ECU.
Statement

The reason to why an ECU must implement two or more diagnostic servers is that it needs to support two or more different ECU configurations: one for which no application is installed and one or more for which applications are installed in the ECU.

NoneNoneAD-007componentRFQX-CVS123-2-0010 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0011It should be noted that a single server view is not completely achievable and that clients still need to be aware of two physical servers.
Statement

It should be noted that a single server view is not completely achievable and that clients still need to be aware of two physical servers.

NoneNoneAD-002componentRFQX-CVS123-2-0011 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0012This specification targets ECUs, not clients.
Statement

This specification targets ECUs, not clients.

NoneNoneNoneNoneRFQX-CVS123-2-0012 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0013Clients may prefer to implement programming support using other service parameter values or even another set of programming steps than
Statement

Clients may prefer to implement programming support using other service parameter values or even another set of programming steps than

NoneNoneNoneNoneRFQX-CVS123-2-0013 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0014For this reason, only the server is required to support the specified sequence.
Statement

For this reason, only the server is required to support the specified sequence.

NoneNoneAD-002componentRFQX-CVS123-2-0014 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0015The target readers of this specification are ECU suppliers, which can be either internal or external in relation to the vehicle manufacturer.
Statement

The target readers of this specification are ECU suppliers, which can be either internal or external in relation to the vehicle manufacturer.

NoneNoneNoneNoneRFQX-CVS123-2-0015 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0016In both cases, whenever the term “ECU supplier” or just “supplier” is used in this specification it refers to the company and organization which is responsible for the implementation and delivery of the ECU according to the requirements in this specification.
Statement

In both cases, whenever the term “ECU supplier” or just “supplier” is used in this specification it refers to the company and organization which is responsible for the implementation and delivery of the ECU according to the requirements in this specification.

NoneNoneNoneNoneRFQX-CVS123-2-0016 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0017The following documents are normative and indispensable for the application of this document: • ISO14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements • CVS124, Traton Specification on Unified diagnostic services (UDS) requirements • CVS154, DSC Specification • CVS31, Authenticate 0x29 • CVS36, Secure ECU Parametrization • CVS32, SecuredDataTranmission 0x84 • CVS33, Entity Management Protocol (EMP) • CVS34, Entity Management Protocol (EMP) Basic Entity Definition
Statement

The following documents are normative and indispensable for the application of this document: • ISO14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements • CVS124, Traton Specification on Unified diagnostic services (UDS) requirements • CVS154, DSC Specification • CVS31, Authenticate 0x29 • CVS36, Secure ECU Parametrization • CVS32, SecuredDataTranmission 0x84 • CVS33, Entity Management Protocol (EMP) • CVS34, Entity Management Protocol (EMP) Basic Entity Definition

NoneNoneNoneNoneRFQX-CVS123-2-0017 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0018Several terms that are used in this document but not defined in Table 1 are defined by ISO or in the document CVS124.
Statement

Several terms that are used in this document but not defined in Table 1 are defined by ISO or in the document CVS124.

NoneNoneNoneNoneRFQX-CVS123-2-0018 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0019Application data module (Calibration data) Contains a variant-specific set of parameter values that is required for correct operation of the control unit in a specific vehicle variant.
Statement

Application data module (Calibration data) Contains a variant-specific set of parameter values that is required for correct operation of the control unit in a specific vehicle variant.

NoneNoneAD-001componentRFQX-CVS123-2-0019 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0020It must be clearly separated from the application software.
Statement

It must be clearly separated from the application software.

NoneNoneAD-001componentRFQX-CVS123-2-0020 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0021For this reason, it is located in a separate memory area and must also be erasable and programmable independently of the application software.
Statement

For this reason, it is located in a separate memory area and must also be erasable and programmable independently of the application software.

NoneNoneAD-001componentRFQX-CVS123-2-0021 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0022Application software module Contains all vehicle functions required for the normal server operation.
Statement

Application software module Contains all vehicle functions required for the normal server operation.

NoneNoneAD-001componentRFQX-CVS123-2-0022 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0023All software parts required for the reprogramming like CAN driver, network layer, diagnostic services, boot operating system, start-up code, low level flash routines (for erasing, writing, reading), EEPROM access routines (read, write functionality), software compatibility checks etc.
Statement

All software parts required for the reprogramming like CAN driver, network layer, diagnostic services, boot operating system, start-up code, low level flash routines (for erasing, writing, reading), EEPROM access routines (read, write functionality), software compatibility checks etc.

NoneNoneAD-007componentRFQX-CVS123-2-0023 / 56hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0024shall be implemented in the boot software code.
Statement

shall be implemented in the boot software code.

NoneNoneAD-001componentRFQX-CVS123-2-0024 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0025The value of this variable (and C2, see below) may be used by the boot manager to determine whether to start the application or the boot loader.
Statement

The value of this variable (and C2, see below) may be used by the boot manager to determine whether to start the application or the boot loader.

NoneNoneNoneNoneRFQX-CVS123-2-0025 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0026C2 Also referred to as “programming request” flag.
Statement

C2 Also referred to as “programming request” flag.

NoneNoneNoneNoneRFQX-CVS123-2-0026 / 32hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0027The value of this variable (and C1, see above) may be used by the boot manager to determine whether or not to start the application or the boot loader.
Statement

The value of this variable (and C1, see above) may be used by the boot manager to determine whether or not to start the application or the boot loader.

NoneNoneNoneNoneRFQX-CVS123-2-0027 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0028C3 Also referred to as “reprogrammed” flag.
Statement

C3 Also referred to as “reprogrammed” flag.

NoneNoneNoneNoneRFQX-CVS123-2-0028 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0029The value of this variable may be used by the application to determine whether or not initialization is required.
Statement

The value of this variable may be used by the application to determine whether or not initialization is required.

NoneNoneAD-001componentRFQX-CVS123-2-0029 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0030Satisfied programming precondition A programming precondition agreed between supplier and vehicle manufacturer which, together with other agreed programming preconditions, shall be fulfilled before an ECU is made eligible for programming.
Statement

Satisfied programming precondition A programming precondition agreed between supplier and vehicle manufacturer which, together with other agreed programming preconditions, shall be fulfilled before an ECU is made eligible for programming.

NoneNoneAD-006componentRFQX-CVS123-2-0030 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0031Tester System that controls functions such as test, inspection, monitoring, or diagnosis of an on-vehicle electronic control unit and may be dedicated to a specific type of operator (e.g., an off-board scan tool dedicated to garage mechanics, an off-board test tool dedicated to assembly plants, or an on-board tester) see (1) 3.2 Abbreviated terms Table 2: Abbreviated terms Abbreviation Description NRC Negative Response Code NR Negative Response APP Application software BLF Boot Loader Flash CDTCS Clear DTC Setting CF Consecutive Frame Def Default diagnostic session DIAG Changeable over diagnostics interface DID Data identifier DSC Data Security Container EMP Entity Management Protocol Ext Extended diagnostic session FF First Frame FLASH BOOT Boot loader module stored in flash memory FLASH DATA Data set module stored in flash memory
Statement

Tester System that controls functions such as test, inspection, monitoring, or diagnosis of an on-vehicle electronic control unit and may be dedicated to a specific type of operator (e.g., an off-board scan tool dedicated to garage mechanics, an off-board test tool dedicated to assembly plants, or an on-board tester) see (1) 3.2 Abbreviated terms Table 2: Abbreviated terms Abbreviation Description NRC Negative Response Code NR Negative Response APP Application software BLF Boot Loader Flash CDTCS Clear DTC Setting CF Consecutive Frame Def Default diagnostic session DIAG Changeable over diagnostics interface DID Data identifier DSC Data Security Container EMP Entity Management Protocol Ext Extended diagnostic session FF First Frame FLASH BOOT Boot loader module stored in flash memory FLASH DATA Data set module stored in flash memory

NoneNoneNoneNoneRFQX-CVS123-2-0031 / 56hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0032Requirements are prefixed “SUV2_REQ”.
Statement

Requirements are prefixed “SUV2_REQ”.

NoneNoneNoneNoneRFQX-CVS123-2-0032 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0033Similarly, informative text is prefixed “SUV2_INFO”.
Statement

Similarly, informative text is prefixed “SUV2_INFO”.

NoneNoneNoneNoneRFQX-CVS123-2-0033 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0034The implementation of the client and the server shall be compliant with (ISO14229-1:2020) and the Traton Specification on Unified diagnostic Service (UDS) requirements (CVS124) with the clarifications, extensions and exceptions stated in this specification.
Statement

The implementation of the client and the server shall be compliant with (ISO14229-1:2020) and the Traton Specification on Unified diagnostic Service (UDS) requirements (CVS124) with the clarifications, extensions and exceptions stated in this specification.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0034 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0035Requirements in (CVS124) which are not explicitly stated to apply to the application only (such as communication parameters) shall apply to the boot loader as well.
Statement

Requirements in (CVS124) which are not explicitly stated to apply to the application only (such as communication parameters) shall apply to the boot loader as well.

NoneNoneAD-001componentRFQX-CVS123-2-0035 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0036All deviations from this specification shall be agreed with the applicable vehicle manufacturer(s).
Statement

All deviations from this specification shall be agreed with the applicable vehicle manufacturer(s).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0036 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0037The programming requirements in this specification shall apply to the programming of all kinds of software modules (application, application data and boot loader), unless explicitly otherwise stated.
Statement

The programming requirements in this specification shall apply to the programming of all kinds of software modules (application, application data and boot loader), unless explicitly otherwise stated.

SSR-BOOT-001Secure software update and flash readiness — Bootloader and Application State HandlingAD-001componentRFQX-CVS123-2-0037 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0038If as a deviation with respect to
Statement

If as a deviation with respect to

NoneNoneNoneNoneRFQX-CVS123-2-0038 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0039an ECU will not support boot loader reprogramming, the boot loader SW shall be in a protected area of the memory.
Statement

an ECU will not support boot loader reprogramming, the boot loader SW shall be in a protected area of the memory.

SSR-BOOT-002Secure software update and flash readiness — Bootloader and Application State HandlingAD-006componentRFQX-CVS123-2-0039 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0040A SW or HW protection mechanism shall be used to protect the software from being accidentally erased or overwritten.
Statement

A SW or HW protection mechanism shall be used to protect the software from being accidentally erased or overwritten.

NoneNoneAD-001componentRFQX-CVS123-2-0040 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0041If the microcontroller supports HW protection, this shall be used.
Statement

If the microcontroller supports HW protection, this shall be used.

NoneNoneAD-008componentRFQX-CVS123-2-0041 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0042The server shall support programming of all application software and application data modules and any subset of such modules in a single sequence without any intermediate reset service requests.
Statement

The server shall support programming of all application software and application data modules and any subset of such modules in a single sequence without any intermediate reset service requests.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0042 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0043Programming of a subset of modules may lead to that the consistency check at the end of a programming sequence fails but shall not lead to that those programmed modules need to be reprogrammed from the beginning.
Statement

Programming of a subset of modules may lead to that the consistency check at the end of a programming sequence fails but shall not lead to that those programmed modules need to be reprogrammed from the beginning.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS123-2-0043 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0044Boot loader updating according to this specification shall be supported during development, from A-samples and onwards.
Statement

Boot loader updating according to this specification shall be supported during development, from A-samples and onwards.

SSR-BOOT-003Bootloader and Application State Handling — Bootloader and Application State HandlingAD-008componentRFQX-CVS123-2-0044 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0045Boot loaders need to be updated by the vehicle manufacturer on aftermarket workshop scenarios or at a test bench during component testing, when the ECU is mounted in a vehicle during system testing or in production to fix bugs.
Statement

Boot loaders need to be updated by the vehicle manufacturer on aftermarket workshop scenarios or at a test bench during component testing, when the ECU is mounted in a vehicle during system testing or in production to fix bugs.

NoneNoneNoneNoneRFQX-CVS123-2-0045 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0046A server shall be programmable according to this specification (i.e., not only using supplier tools) regardless of whether one or more DTCs are currently active, or one or more functions are currently degraded.
Statement

A server shall be programmable according to this specification (i.e., not only using supplier tools) regardless of whether one or more DTCs are currently active, or one or more functions are currently degraded.

SSR-DIAG-002Diagnostic Services — Diagnostic ServicesAD-002componentRFQX-CVS123-2-0046 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0047A server shall be programmable while integrated in the vehicle network and as a standalone server without further conditions and without further interventions by the diagnostic tester as per this specification.
Statement

A server shall be programmable while integrated in the vehicle network and as a standalone server without further conditions and without further interventions by the diagnostic tester as per this specification.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0047 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0048The solution for maintaining/reorganizing data (EEPROM data, operational data, adaptive data etc.) before and after reprogramming of software modules shall be discussed and agreed with the vehicle manufacturer.
Statement

The solution for maintaining/reorganizing data (EEPROM data, operational data, adaptive data etc.) before and after reprogramming of software modules shall be discussed and agreed with the vehicle manufacturer.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0048 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0049The supplier shall provide, for each committed software delivery, a document that describes the programming procedure together with any requirement exceptions and ECU specific behaviours.
Statement

The supplier shall provide, for each committed software delivery, a document that describes the programming procedure together with any requirement exceptions and ECU specific behaviours.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0049 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0050Normal and worst-case performance values shall be documented for: • Total time for the programming sequence (programming steps prefixed “P1Pro”, see section Programming step of phase #1 – Download of application software and data).
Statement

Normal and worst-case performance values shall be documented for: • Total time for the programming sequence (programming steps prefixed “P1Pro”, see section Programming step of phase #1 – Download of application software and data).

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0050 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0051The supplier shall document the versioning concept for supplier specific DIDs.
Statement

The supplier shall document the versioning concept for supplier specific DIDs.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0051 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0052System name (DID 0xF197), diagnostic address and bitrate shall be persisted in an application data module dedicated for boot parameters, referred to as “boot parameter module”.
Statement

System name (DID 0xF197), diagnostic address and bitrate shall be persisted in an application data module dedicated for boot parameters, referred to as “boot parameter module”.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0052 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0053When this module is programmed the parameter values in it shall override default parameter values persisted in the boot loader software module.
Statement

When this module is programmed the parameter values in it shall override default parameter values persisted in the boot loader software module.

NoneNoneAD-001componentRFQX-CVS123-2-0053 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0054The “boot parameter module” permits a generic bootloader to be an ECU application platform (ECU HW + boot loader software).
Statement

The “boot parameter module” permits a generic bootloader to be an ECU application platform (ECU HW + boot loader software).

NoneNoneNoneNoneRFQX-CVS123-2-0054 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0055It should be possible to reuse the generic bootloader for future currently unknown purposes/applications without a need to create a new part number for the platform.
Statement

It should be possible to reuse the generic bootloader for future currently unknown purposes/applications without a need to create a new part number for the platform.

SSR-BOOT-004Bootloader and Application State Handling — Bootloader and Application State HandlingAD-002componentRFQX-CVS123-2-0055 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCESECURITY REVIEW OPEN
RFQX-CVS123-2-0056When the boot loader software in an ECU has not yet been parameterized (a boot parameter module has not been programmed) the boot loader software shall apply project specific default values, typically: • diagnostic address 0xA7 • baud rate 500 kb/s • DID 0xF197
Statement

When the boot loader software in an ECU has not yet been parameterized (a boot parameter module has not been programmed) the boot loader software shall apply project specific default values, typically: • diagnostic address 0xA7 • baud rate 500 kb/s • DID 0xF197

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0056 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0057For definition of DID 0xF197 see CVS124.
Statement

For definition of DID 0xF197 see CVS124.

NoneNoneNoneNoneRFQX-CVS123-2-0057 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0058Default values for EOL parameters shall be implemented in a dedicated application data module, referred to as “EOL parameters module”.
Statement

Default values for EOL parameters shall be implemented in a dedicated application data module, referred to as “EOL parameters module”.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0058 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0059The partitioning of the ECU software into modules shall be discussed and agreed with the vehicle manufacturer.
Statement

The partitioning of the ECU software into modules shall be discussed and agreed with the vehicle manufacturer.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0059 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0060A joint use of program code for communication functions (com stack) by the application and the boot loader is not permitted.
Statement

A joint use of program code for communication functions (com stack) by the application and the boot loader is not permitted.

NoneNoneNoneNoneRFQX-CVS123-2-0060 / 16hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0061A software released for integration test, production or service market shall be hashed so its integrity can be verified by the server.
Statement

A software released for integration test, production or service market shall be hashed so its integrity can be verified by the server.

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS123-2-0061 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0062Flash files delivered from the supplier shall never have to be modified by the vehicle manufacturer.
Statement

Flash files delivered from the supplier shall never have to be modified by the vehicle manufacturer.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS123-2-0062 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0063It is within the scope of this specification that flash files delivered from the supplier can be encrypted by the vehicle manufacturer before storing in the vehicle manufacturer offboard database, but the server decryption of the received data will always restore it to servers memory into original data delivered by the supplier.
Statement

It is within the scope of this specification that flash files delivered from the supplier can be encrypted by the vehicle manufacturer before storing in the vehicle manufacturer offboard database, but the server decryption of the received data will always restore it to servers memory into original data delivered by the supplier.

NoneNoneNoneNoneRFQX-CVS123-2-0063 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; boot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0064The supplier shall deliver the necessary information to verify the integrity of the flash files.
Statement

The supplier shall deliver the necessary information to verify the integrity of the flash files.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS123-2-0064 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0065In case the supplier delivers encrypted flash files to the vehicle manufacturer, the supplier should also provide the necessary information so the flash files can be verified as part of flash files update procedure.
Statement

In case the supplier delivers encrypted flash files to the vehicle manufacturer, the supplier should also provide the necessary information so the flash files can be verified as part of flash files update procedure.

NoneNoneAD-005interfaceRFQX-CVS123-2-0065 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0066Whether or not the ECU shall be delivered from the supplier to the vehicle manufacturer with a pre-programmed application and pre-programmed application data shall be discussed and agreed with the vehicle manufacturer.
Statement

Whether or not the ECU shall be delivered from the supplier to the vehicle manufacturer with a pre-programmed application and pre-programmed application data shall be discussed and agreed with the vehicle manufacturer.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0066 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0067Regardless of if the ECU will be delivered from the supplier with a pre-programmed application and application data, the corresponding flash files shall be possible to request by vehicle manufacturer to be able to perform software verification at any time in vehicle manufacturer production site.
Statement

Regardless of if the ECU will be delivered from the supplier with a pre-programmed application and application data, the corresponding flash files shall be possible to request by vehicle manufacturer to be able to perform software verification at any time in vehicle manufacturer production site.

NoneNoneAD-001componentRFQX-CVS123-2-0067 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0068When the application module is pre-programmed by the supplier, ECU and software identifiers 0xF187 and 0xF188 shall be set to product specific vehicle manufacturer defined values.
Statement

When the application module is pre-programmed by the supplier, ECU and software identifiers 0xF187 and 0xF188 shall be set to product specific vehicle manufacturer defined values.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0068 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0069Otherwise 0xF187 and 0xF188 shall be set to default values, see CVS124.
Statement

Otherwise 0xF187 and 0xF188 shall be set to default values, see CVS124.

NoneNoneAD-008componentRFQX-CVS123-2-0069 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0070Programmable servers shall support the full programming sequence described in this chapter.
Statement

Programmable servers shall support the full programming sequence described in this chapter.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS123-2-0070 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0071Non-programmable servers shall support the pre-programming and post-programming steps of the programming sequence described in this chapter (phase 1 and 2).
Statement

Non-programmable servers shall support the pre-programming and post-programming steps of the programming sequence described in this chapter (phase 1 and 2).

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS123-2-0071 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0072The programming sequence described in this chapter shall be supported when a valid application is present as well as when no valid application is present in the ECU.
Statement

The programming sequence described in this chapter shall be supported when a valid application is present as well as when no valid application is present in the ECU.

SSR-BOOT-001Secure software update and flash readiness — Bootloader and Application State HandlingAD-001componentRFQX-CVS123-2-0072 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0073If a valid application is present in the ECU, some of the services described in the programming sequence will be executed in the application.
Statement

If a valid application is present in the ECU, some of the services described in the programming sequence will be executed in the application.

NoneNoneNoneNoneRFQX-CVS123-2-0073 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0074Each programming step will specify an addressing method (physical or functional), an SPRMIB (suppressPosRspMsgIndicationBit) bit value and other parameter values for the service(s) posted by the client.
Statement

Each programming step will specify an addressing method (physical or functional), an SPRMIB (suppressPosRspMsgIndicationBit) bit value and other parameter values for the service(s) posted by the client.

NoneNoneNoneNoneRFQX-CVS123-2-0074 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0075The full set of addressing modes, SPRMIB values and other parameter values that the server shall support for each service are specified with implementation requirements in CVS124.
Statement

The full set of addressing modes, SPRMIB values and other parameter values that the server shall support for each service are specified with implementation requirements in CVS124.

NoneNoneAD-001componentRFQX-CVS123-2-0075 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0076The numbering of the programming sequence steps in this document generally has a well- defined relation to the numbering of the sequence steps in (ISO14229-1:2020).
Statement

The numbering of the programming sequence steps in this document generally has a well- defined relation to the numbering of the sequence steps in (ISO14229-1:2020).

NoneNoneNoneNoneRFQX-CVS123-2-0076 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0077Programming phase #1 is defined to program a server (e.g., download of application software, application data or boot software).
Statement

Programming phase #1 is defined to program a server (e.g., download of application software, application data or boot software).

NoneNoneNoneNoneRFQX-CVS123-2-0077 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0078To enable access to diagnostic services in the programming sequence, an authentication sequence shall be performed between the client and the server by means of the Authentication 0x29 service.
Statement

To enable access to diagnostic services in the programming sequence, an authentication sequence shall be performed between the client and the server by means of the Authentication 0x29 service.

SSR-RBAC-002Secure software update and flash readiness — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0078 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0079The server shall receive a diagnostic service authentication (0x29) with SubFunction deAuthenticate (0x00) message from the client to disable authorized access to diagnostic programming services after an update is considered fulfilled.
Statement

The server shall receive a diagnostic service authentication (0x29) with SubFunction deAuthenticate (0x00) message from the client to disable authorized access to diagnostic programming services after an update is considered fulfilled.

SSR-RBAC-002Secure software update and flash readiness — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0079 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0080For further information on the service details and programming messages structure regarding the SecuredDataTransmission (0x84) service, refer to CVS32.
Statement

For further information on the service details and programming messages structure regarding the SecuredDataTransmission (0x84) service, refer to CVS32.

NoneNoneNoneNoneRFQX-CVS123-2-0080 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0081The sequence shown in the following figure shows the Pre-Programming step of phase #1.
Statement

The sequence shown in the following figure shows the Pre-Programming step of phase #1.

NoneNoneNoneNoneRFQX-CVS123-2-0081 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0082When this step is entered, the ECU is assumed to be in a state which enables it to receive UDS service requests.
Statement

When this step is entered, the ECU is assumed to be in a state which enables it to receive UDS service requests.

NoneNoneNoneNoneRFQX-CVS123-2-0082 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0083For each server in the network, depending on whether an application has been successfully flashed before, it will run in application or boot mode.
Statement

For each server in the network, depending on whether an application has been successfully flashed before, it will run in application or boot mode.

NoneNoneNoneNoneRFQX-CVS123-2-0083 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0084The client posts a functionally addressed DiagnosticSessionControl (0x10) service request with sessionType equal to DefaultSession and the SPRMIB not set.
Statement

The client posts a functionally addressed DiagnosticSessionControl (0x10) service request with sessionType equal to DefaultSession and the SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0084 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0085If servers which support wake-up on CAN are not awake before, this request causes them to wake-up.
Statement

If servers which support wake-up on CAN are not awake before, this request causes them to wake-up.

NoneNoneNoneNoneRFQX-CVS123-2-0085 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0086All servers available on the network and their diagnostic addresses are identified from the positive responses to this request.
Statement

All servers available on the network and their diagnostic addresses are identified from the positive responses to this request.

NoneNoneNoneNoneRFQX-CVS123-2-0086 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0087The client then posts physically or functionally addressed ReadDataByIdentifier (0x22) service requests to collect additional identification data from each identified server.
Statement

The client then posts physically or functionally addressed ReadDataByIdentifier (0x22) service requests to collect additional identification data from each identified server.

NoneNoneNoneNoneRFQX-CVS123-2-0087 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0088The client post physically addressed RoutineControl (0x31) (EMP) service request with SPRMIB not set and operation-type set to Get (0x01).
Statement

The client post physically addressed RoutineControl (0x31) (EMP) service request with SPRMIB not set and operation-type set to Get (0x01).

NoneNoneNoneNoneRFQX-CVS123-2-0088 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0089In this step, it is client dependent if and what cyber security entities are relevant to be read for performing the remaining steps of the sequence.
Statement

In this step, it is client dependent if and what cyber security entities are relevant to be read for performing the remaining steps of the sequence.

NoneNoneNoneNoneRFQX-CVS123-2-0089 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0090As example, the client may read certificate validity time and/or RBAC configuration file to verify if the appropriate entities are stored in the server.
Statement

As example, the client may read certificate validity time and/or RBAC configuration file to verify if the appropriate entities are stored in the server.

NoneNoneNoneNoneRFQX-CVS123-2-0090 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0091For reference on EMP control routine, see CVS33.
Statement

For reference on EMP control routine, see CVS33.

NoneNoneNoneNoneRFQX-CVS123-2-0091 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0092The client post physically addressed RoutineControl (0x31) (EMP) service request with SPRMIB not set and operation-type set to Set (0x00).
Statement

The client post physically addressed RoutineControl (0x31) (EMP) service request with SPRMIB not set and operation-type set to Set (0x00).

NoneNoneNoneNoneRFQX-CVS123-2-0092 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0093In this step, the client will set a new SDSC entity, and it is client dependent if and what other entities are relevant to be set/update for performing the remaining steps of the sequence.
Statement

In this step, the client will set a new SDSC entity, and it is client dependent if and what other entities are relevant to be set/update for performing the remaining steps of the sequence.

NoneNoneNoneNoneRFQX-CVS123-2-0093 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0094As example, the client may have identified that the RBAC configuration file requires update and perform the appropriate set to update the entities stored in the server.
Statement

As example, the client may have identified that the RBAC configuration file requires update and perform the appropriate set to update the entities stored in the server.

NoneNoneAD-002componentRFQX-CVS123-2-0094 / 56hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0095Alternatively, it may be a client strategy to always update certain entities prior to a software update.
Statement

Alternatively, it may be a client strategy to always update certain entities prior to a software update.

NoneNoneNoneNoneRFQX-CVS123-2-0095 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0096For reference on EMP control routine, see CVS33.
Statement

For reference on EMP control routine, see CVS33.

NoneNoneNoneNoneRFQX-CVS123-2-0096 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0097The client post physically addressed authentication sequence based on CVS31 with SPRMIB not set.
Statement

The client post physically addressed authentication sequence based on CVS31 with SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0097 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0098The client posts a functionally addressed DiagnosticSessionControl (0x10) service request with sessionType equal to extended diagnostic session and the SPRMIB set.
Statement

The client posts a functionally addressed DiagnosticSessionControl (0x10) service request with sessionType equal to extended diagnostic session and the SPRMIB set.

NoneNoneNoneNoneRFQX-CVS123-2-0098 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0099From this point, onwards (throughout the entire programming sequence) the client posts functionally addressed TesterPresent (0x3E) service requests at regular intervals, with the SPRMIB set, with the purpose to make the server(s) stay in the currently active non-default session and maintain its authenticated state.
Statement

From this point, onwards (throughout the entire programming sequence) the client posts functionally addressed TesterPresent (0x3E) service requests at regular intervals, with the SPRMIB set, with the purpose to make the server(s) stay in the currently active non-default session and maintain its authenticated state.

NoneNoneNoneNoneRFQX-CVS123-2-0099 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0100The client disables the setting of DTCs in each server by posting a functionally addressed ControlDTCSetting (0x85) service request with the sub-function parameter DTCSettingType set to off and the SPRMIB set.
Statement

The client disables the setting of DTCs in each server by posting a functionally addressed ControlDTCSetting (0x85) service request with the sub-function parameter DTCSettingType set to off and the SPRMIB set.

NoneNoneNoneNoneRFQX-CVS123-2-0100 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0101If the server is executing in the boot loader it will accept the request without performing any action, as DTCs are already disabled (DTC setting not supported by boot loader).
Statement

If the server is executing in the boot loader it will accept the request without performing any action, as DTCs are already disabled (DTC setting not supported by boot loader).

NoneNoneNoneNoneRFQX-CVS123-2-0101 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0102The client disables the transmission of non-diagnostic messages by posting a functionally addressed CommunicationControl (0x28) service request with parameter controlType set to enableRxAndDisableTx, parameter communicationType set to normalCommunicationMessages and SPRMIB set.
Statement

The client disables the transmission of non-diagnostic messages by posting a functionally addressed CommunicationControl (0x28) service request with parameter controlType set to enableRxAndDisableTx, parameter communicationType set to normalCommunicationMessages and SPRMIB set.

NoneNoneNoneNoneRFQX-CVS123-2-0102 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0103If the server is executing in the boot loader when this service request is received no action will be performed by the server as non-diagnostic messages are already disabled.
Statement

If the server is executing in the boot loader when this service request is received no action will be performed by the server as non-diagnostic messages are already disabled.

NoneNoneNoneNoneRFQX-CVS123-2-0103 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0104Link control is only applicable to standalone programming (i.e., when the ECU is not mounted in the vehicle) at vehicle manufacturer premises when no application has been programmed by the supplier, communication network permits baud rate switch (e.g CAN) and only if performance requirement cannot be met without using this service.
Statement

Link control is only applicable to standalone programming (i.e., when the ECU is not mounted in the vehicle) at vehicle manufacturer premises when no application has been programmed by the supplier, communication network permits baud rate switch (e.g CAN) and only if performance requirement cannot be met without using this service.

NoneNoneNoneNoneRFQX-CVS123-2-0104 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0105The client posts a physically addressed LinkControl (0x87) service request with parameter linkControlType set to verifyBaudrateTransitionWithFixedParameter, SPRMIB not set and linkControlModeIdentifier set to desired baud rate.
Statement

The client posts a physically addressed LinkControl (0x87) service request with parameter linkControlType set to verifyBaudrateTransitionWithFixedParameter, SPRMIB not set and linkControlModeIdentifier set to desired baud rate.

NoneNoneNoneNoneRFQX-CVS123-2-0105 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0106After reception of a positive response message the client posts a physically addressed LinkControl (0x87) service request with sub-function parameter linkControlType set to transitionMode and the SPRMIB set.
Statement

After reception of a positive response message the client posts a physically addressed LinkControl (0x87) service request with sub-function parameter linkControlType set to transitionMode and the SPRMIB set.

NoneNoneNoneNoneRFQX-CVS123-2-0106 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0107The client will then switch to the new baud rate and re-establish communication with the ECU considering the maximum specified time it will take for the server to start responding to the newly selected baud rate.
Statement

The client will then switch to the new baud rate and re-establish communication with the ECU considering the maximum specified time it will take for the server to start responding to the newly selected baud rate.

NoneNoneNoneNoneRFQX-CVS123-2-0107 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0108Since Link Control is only applicable in production when no application has been programmed by the supplier, the application may return NRC 0x7F (serviceNotSupportedInActiveSession) to this service request and expect the client to proceed to the next step.
Statement

Since Link Control is only applicable in production when no application has been programmed by the supplier, the application may return NRC 0x7F (serviceNotSupportedInActiveSession) to this service request and expect the client to proceed to the next step.

NoneNoneNoneNoneRFQX-CVS123-2-0108 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0109The sequence in Figure 3 shows the programming step of phase #1.
Statement

The sequence in Figure 3 shows the programming step of phase #1.

NoneNoneNoneNoneRFQX-CVS123-2-0109 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0110For the server to verify the integrity of the software, the information to verify shall be available to the server before step P1Pro6: Routine Control (erase Memory).
Statement

For the server to verify the integrity of the software, the information to verify shall be available to the server before step P1Pro6: Routine Control (erase Memory).

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS123-2-0110 / 19hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0111The information to verify integrity of the software is contained in software data security container (SDSC), which is transmitted in P1PreB step.
Statement

The information to verify integrity of the software is contained in software data security container (SDSC), which is transmitted in P1PreB step.

NoneNoneNoneNoneRFQX-CVS123-2-0111 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0112If the SW to be updated is encrypted, decryption keys shall be available to the server before step P1Pro9.
Statement

If the SW to be updated is encrypted, decryption keys shall be available to the server before step P1Pro9.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0112 / 29hNot importedNo linked clarificationNo P1 linkboot/update trust; certificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0113If SDSC dictates decryption, the decryption keys are contained in software data security container (SDSC) which is transmitted in P1PreB step.
Statement

If SDSC dictates decryption, the decryption keys are contained in software data security container (SDSC) which is transmitted in P1PreB step.

NoneNoneNoneNoneRFQX-CVS123-2-0113 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0114Before the server executes the TransferData service, the server shall check if the data received during RequestDownload requests needs to be decrypted before writing the received data to non-volatile memory.
Statement

Before the server executes the TransferData service, the server shall check if the data received during RequestDownload requests needs to be decrypted before writing the received data to non-volatile memory.

SSR-SDT-001Secure Data Transfer / Data Security Container — Secure Data Transfer / Data Security ContainerAD-001componentRFQX-CVS123-2-0114 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0115The client posts a physically addressed DiagnosticSessionControl (0x10) service request with sub-function parameter diagnosticSessionType set to ProgrammingSession and the SPRMIB not set.
Statement

The client posts a physically addressed DiagnosticSessionControl (0x10) service request with sub-function parameter diagnosticSessionType set to ProgrammingSession and the SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0115 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0116If CommunicationControl has not been previously called in the Extended Diagnostic Session the server rejects the request with negative response code NRC 0x22 (conditionsNotCorrect).
Statement

If CommunicationControl has not been previously called in the Extended Diagnostic Session the server rejects the request with negative response code NRC 0x22 (conditionsNotCorrect).

NoneNoneNoneNoneRFQX-CVS123-2-0116 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0117Implementation hint: If the server is executing the application the server sets a “programming request” flag (C2, see section Boot software session requirements).
Statement

Implementation hint: If the server is executing the application the server sets a “programming request” flag (C2, see section Boot software session requirements).

NoneNoneNoneNoneRFQX-CVS123-2-0117 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0118If the server is executing the application the server responds to the request with one or more negative response codes NRC 0x78 (requestCorrectlyReceived-ResponsePending) and triggers a server restart.
Statement

If the server is executing the application the server responds to the request with one or more negative response codes NRC 0x78 (requestCorrectlyReceived-ResponsePending) and triggers a server restart.

NoneNoneNoneNoneRFQX-CVS123-2-0118 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0119The boot manager notes the programming request and starts the boot loader.
Statement

The boot manager notes the programming request and starts the boot loader.

NoneNoneNoneNoneRFQX-CVS123-2-0119 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0120Implementation hint: The boot manager recognizes the programming request by checking the “programming request” flag (C2).
Statement

Implementation hint: The boot manager recognizes the programming request by checking the “programming request” flag (C2).

NoneNoneNoneNoneRFQX-CVS123-2-0120 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0121Implementation hint: The boot manager or the boot loader resets the “programming request” flag (C2).
Statement

Implementation hint: The boot manager or the boot loader resets the “programming request” flag (C2).

NoneNoneNoneNoneRFQX-CVS123-2-0121 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0122Finally, the boot loader sends a positive response.
Statement

Finally, the boot loader sends a positive response.

NoneNoneNoneNoneRFQX-CVS123-2-0122 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0123The client post physically addressed authentication sequence based on Authenticate 0x29 with SPRMIB not set.
Statement

The client post physically addressed authentication sequence based on Authenticate 0x29 with SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0123 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0124The client posts a physically addressed RoutineControl (0x31) (eraseMemory) service request with a memory start address and a memory size value set for parameter RoutineControlOptionRecord and the SPRMIB not set.
Statement

The client posts a physically addressed RoutineControl (0x31) (eraseMemory) service request with a memory start address and a memory size value set for parameter RoutineControlOptionRecord and the SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0124 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0125Implementation hint: The server resets the “application valid” flag (C1, see CVS124
Statement

Implementation hint: The server resets the “application valid” flag (C1, see CVS124

NoneNoneNoneNoneRFQX-CVS123-2-0125 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0126) before the erase process starts, to ensure that the server will start in boot loader mode if the programming gets interrupted or if the programming is faulty.
Statement

) before the erase process starts, to ensure that the server will start in boot loader mode if the programming gets interrupted or if the programming is faulty.

NoneNoneNoneNoneRFQX-CVS123-2-0126 / 32hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0127The server erases the applicable SW identification DIDs, see Erase Memory routine requirements in 8.3.
Statement

The server erases the applicable SW identification DIDs, see Erase Memory routine requirements in 8.3.

NoneNoneNoneNoneRFQX-CVS123-2-0127 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0128The client posts physically addressed RequestDownload (0x34) service requests with the SPRMIB not set.
Statement

The client posts physically addressed RequestDownload (0x34) service requests with the SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0128 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0129If the boot software module is updated in this step, DID 0xF180 (bootSoftwareIdentificationDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the boot software module.
Statement

If the boot software module is updated in this step, DID 0xF180 (bootSoftwareIdentificationDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the boot software module.

NoneNoneNoneNoneRFQX-CVS123-2-0129 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0130If the application software module is updated in this step, DID 0xF181 (applicationSoftwareIdentificationDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application software module.
Statement

If the application software module is updated in this step, DID 0xF181 (applicationSoftwareIdentificationDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application software module.

NoneNoneNoneNoneRFQX-CVS123-2-0130 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0131If the application data module is updated in this step DID 0xF182 (applicationDataIdentificationDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application data module.
Statement

If the application data module is updated in this step DID 0xF182 (applicationDataIdentificationDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application data module.

NoneNoneNoneNoneRFQX-CVS123-2-0131 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0132If the application software module is updated in this step, DID 0xF187 (vehicleManufacturerSparePartNumberDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application data module.
Statement

If the application software module is updated in this step, DID 0xF187 (vehicleManufacturerSparePartNumberDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application data module.

NoneNoneNoneNoneRFQX-CVS123-2-0132 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0133If the application software module is updated in this step, DID 0xF188 (vehicleManufacturerECUSoftwareNumberDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application software module.
Statement

If the application software module is updated in this step, DID 0xF188 (vehicleManufacturerECUSoftwareNumberDataIdentifier) will be automatically updated as well as this ID will be implemented as part of the application software module.

NoneNoneNoneNoneRFQX-CVS123-2-0133 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0134It is client specific if P1Pro10 will be sent as part of programming phase #1.
Statement

It is client specific if P1Pro10 will be sent as part of programming phase #1.

NoneNoneNoneNoneRFQX-CVS123-2-0134 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0135This routineIdentifier is supported to allow process improvement during the software update since it allows client to react as soon as a corruption is identified in the transferred module data.
Statement

This routineIdentifier is supported to allow process improvement during the software update since it allows client to react as soon as a corruption is identified in the transferred module data.

NoneNoneNoneNoneRFQX-CVS123-2-0135 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0136The client posts a physically addressed RoutineControl (0x31) (checkMemory) service request with the SPRMIB not set.
Statement

The client posts a physically addressed RoutineControl (0x31) (checkMemory) service request with the SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0136 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0137According to
Statement

According to

NoneNoneNoneNoneRFQX-CVS123-2-0137 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0138, this routineIdentifier allows the server to verify if the transferred data is correct (has not been corrupted) by calculating a checksum and comparing this checksum with the checksum transferred as part of the data (via transferData).
Statement

, this routineIdentifier allows the server to verify if the transferred data is correct (has not been corrupted) by calculating a checksum and comparing this checksum with the checksum transferred as part of the data (via transferData).

NoneNoneNoneNoneRFQX-CVS123-2-0138 / 18hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0139The response of this routineIdentifier allows the client to identify if the specific transferred block is corrupted.
Statement

The response of this routineIdentifier allows the client to identify if the specific transferred block is corrupted.

NoneNoneNoneNoneRFQX-CVS123-2-0139 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0140According to
Statement

According to

NoneNoneNoneNoneRFQX-CVS123-2-0140 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0141, as a part of the consistency check the server verifies the integrity of the programmed software.
Statement

, as a part of the consistency check the server verifies the integrity of the programmed software.

NoneNoneNoneNoneRFQX-CVS123-2-0141 / 5hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0142According to
Statement

According to

NoneNoneNoneNoneRFQX-CVS123-2-0142 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0143, the check on consistency can produce a positive result only if the integrity verification is valid, the software was successfully installed and the installed software are compatible between all software module and the software is compatible with the ECU hardware.
Statement

, the check on consistency can produce a positive result only if the integrity verification is valid, the software was successfully installed and the installed software are compatible between all software module and the software is compatible with the ECU hardware.

NoneNoneNoneNoneRFQX-CVS123-2-0143 / 18hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0144As part of the routine checks, the server will use the information defined in SDSC to perform the software verification, see 9.2.
Statement

As part of the routine checks, the server will use the information defined in SDSC to perform the software verification, see 9.2.

NoneNoneNoneNoneRFQX-CVS123-2-0144 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0145Implementation hint: The integrity information may contain parts of memory not programmed, regardless of this the server verifies the integrity according to the supplied information on SDSC, see 9.
Statement

Implementation hint: The integrity information may contain parts of memory not programmed, regardless of this the server verifies the integrity according to the supplied information on SDSC, see 9.

NoneNoneNoneNoneRFQX-CVS123-2-0145 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0146The sequence shown in the following figure shows the post-programming step of phase #1.
Statement

The sequence shown in the following figure shows the post-programming step of phase #1.

NoneNoneNoneNoneRFQX-CVS123-2-0146 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0147After the consistency check (independent of the result), the client initiates a server restart by posting a physically addressed ECUReset (0x11) (hardReset) service request with the SPRMIB not set.
Statement

After the consistency check (independent of the result), the client initiates a server restart by posting a physically addressed ECUReset (0x11) (hardReset) service request with the SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0147 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0148The server responds positively to the request before the reset takes place.
Statement

The server responds positively to the request before the reset takes place.

NoneNoneNoneNoneRFQX-CVS123-2-0148 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0149After reset, if the ECU hardware/software is deemed to be consistent and all software and data identification DIDs in CVS124 which have been flashed or written as part of the programming
Statement

After reset, if the ECU hardware/software is deemed to be consistent and all software and data identification DIDs in CVS124 which have been flashed or written as part of the programming

NoneNoneNoneNoneRFQX-CVS123-2-0149 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0150The application reads and applies the boot parameter values from the boot parameter module.
Statement

The application reads and applies the boot parameter values from the boot parameter module.

NoneNoneNoneNoneRFQX-CVS123-2-0150 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0151Implementation hint: The boot manager checks the “application valid” flag (C1) to see if the ECU hardware/software is consistent and all software and data identification DIDs in CVS124 contain non-default values.
Statement

Implementation hint: The boot manager checks the “application valid” flag (C1) to see if the ECU hardware/software is consistent and all software and data identification DIDs in CVS124 contain non-default values.

NoneNoneNoneNoneRFQX-CVS123-2-0151 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0152If the application was started, it checks if application initialization is required.
Statement

If the application was started, it checks if application initialization is required.

NoneNoneAD-001componentRFQX-CVS123-2-0152 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0153If so, the server performs the required checks/reorganization measures for the data structures (EEPROM data, operational data, adaptive data etc.), executes the self-test and stores event memory entries, default values, DIDs F1AB, F1AA, F1A9 etc.
Statement

If so, the server performs the required checks/reorganization measures for the data structures (EEPROM data, operational data, adaptive data etc.), executes the self-test and stores event memory entries, default values, DIDs F1AB, F1AA, F1A9 etc.

NoneNoneAD-006componentRFQX-CVS123-2-0153 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0154Implementation hint: The ECU application checks the reprogrammed flag (C3, see programming step P1Pro11) to see if application initialization is required.
Statement

Implementation hint: The ECU application checks the reprogrammed flag (C3, see programming step P1Pro11) to see if application initialization is required.

NoneNoneAD-001componentRFQX-CVS123-2-0154 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0155Implementation hint: If the “application valid” flag (C1) indicates that the ECU application state is not valid, the boot manager will execute the boot loader.
Statement

Implementation hint: If the “application valid” flag (C1) indicates that the ECU application state is not valid, the boot manager will execute the boot loader.

NoneNoneNoneNoneRFQX-CVS123-2-0155 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0156If the boot loader is executed and a boot parameter module exists, the boot loader reads and applies the boot parameter values from this module.
Statement

If the boot loader is executed and a boot parameter module exists, the boot loader reads and applies the boot parameter values from this module.

NoneNoneNoneNoneRFQX-CVS123-2-0156 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0157According to
Statement

According to

NoneNoneNoneNoneRFQX-CVS123-2-0157 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0158, the client post physically addressed authentication (0x29) request with subfunction deAuthenticate (0x00) based on CVS31 with SPRMIB not set.
Statement

, the client post physically addressed authentication (0x29) request with subfunction deAuthenticate (0x00) based on CVS31 with SPRMIB not set.

NoneNoneNoneNoneRFQX-CVS123-2-0158 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0159The client post physically addressed RoutineControl (0x31) (EMP) service request with SPRMIB not set and operation-type set to Set (0x00).
Statement

The client post physically addressed RoutineControl (0x31) (EMP) service request with SPRMIB not set and operation-type set to Set (0x00).

NoneNoneNoneNoneRFQX-CVS123-2-0159 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0160In this step, it is client dependent if and what entities are relevant to be set after updating the software.
Statement

In this step, it is client dependent if and what entities are relevant to be set after updating the software.

NoneNoneNoneNoneRFQX-CVS123-2-0160 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0161As example, the client may have identified that the new software requires an updated RBAC configuration file and therefore set the entity on the server via EMP.
Statement

As example, the client may have identified that the new software requires an updated RBAC configuration file and therefore set the entity on the server via EMP.

NoneNoneAD-001componentRFQX-CVS123-2-0161 / 56hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0162For reference on EMP control routine, see CVS33.
Statement

For reference on EMP control routine, see CVS33.

NoneNoneNoneNoneRFQX-CVS123-2-0162 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0163The programming phase #2 (server configuration or also known as parametrization) as defined in ISO 14229-2 is defined in CVS36.
Statement

The programming phase #2 (server configuration or also known as parametrization) as defined in ISO 14229-2 is defined in CVS36.

NoneNoneNoneNoneRFQX-CVS123-2-0163 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0164ECUs that will be programmed stand-alone at the vehicle manufacturer over DoCAN shall support 1 Mbit transfer speed.
Statement

ECUs that will be programmed stand-alone at the vehicle manufacturer over DoCAN shall support 1 Mbit transfer speed.

SSR-UPD-003Secure software update and flash readiness — Software Update / FlashingAD-002componentRFQX-CVS123-2-0164 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0165Whether or not the ECU shall support stand-alone programming at the vehicle manufacturer premises shall be discussed and agreed with the vehicle manufacturer.
Statement

Whether or not the ECU shall support stand-alone programming at the vehicle manufacturer premises shall be discussed and agreed with the vehicle manufacturer.

SSR-UPD-004Secure software update and flash readiness — Software Update / FlashingAD-006componentRFQX-CVS123-2-0165 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0166A server that is running in the application shall respond with the same diagnostic address after a switch to boot.
Statement

A server that is running in the application shall respond with the same diagnostic address after a switch to boot.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0166 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0167It shall be possible to downgrade server software modules as long as the programmed modules are compatible with each other and with the hardware configuration.
Statement

It shall be possible to downgrade server software modules as long as the programmed modules are compatible with each other and with the hardware configuration.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0167 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0168Application software and application data modules shall be programmable in any order.
Statement

Application software and application data modules shall be programmable in any order.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0168 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0169The server shall be able to update an individual module independently from any other module.
Statement

The server shall be able to update an individual module independently from any other module.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0169 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0170This is to keep the programming time to a minimum.
Statement

This is to keep the programming time to a minimum.

NoneNoneNoneNoneRFQX-CVS123-2-0170 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0171If the performance requirements
Statement

If the performance requirements

NoneNoneNoneNoneRFQX-CVS123-2-0171 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0172or
Statement

or

NoneNoneNoneNoneRFQX-CVS123-2-0172 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0173cannot be met, a compression method shall be implemented.
Statement

cannot be met, a compression method shall be implemented.

SSR-COM-002Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-008componentRFQX-CVS123-2-0173 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0174This is to shorten the time for the data transfer from the tester to the ECU to be programmed.
Statement

This is to shorten the time for the data transfer from the tester to the ECU to be programmed.

NoneNoneNoneNoneRFQX-CVS123-2-0174 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0175The LZSS algorithm with a dictionary size of 1 023 bytes or a newer compression/decompression method with a higher compression ratio shall be used as the compression/decompression algorithm.
Statement

The LZSS algorithm with a dictionary size of 1 023 bytes or a newer compression/decompression method with a higher compression ratio shall be used as the compression/decompression algorithm.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0175 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0176The use of alternative compression/decompression algorithms shall be agreed with the vehicle manufacturer.
Statement

The use of alternative compression/decompression algorithms shall be agreed with the vehicle manufacturer.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0176 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0177It shall be possible to program the same software version repeatedly.
Statement

It shall be possible to program the same software version repeatedly.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0177 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0178If at startup the ECU hardware/software is consistent and a programming request is not pending, the boot manager shall start and execute the application.
Statement

If at startup the ECU hardware/software is consistent and a programming request is not pending, the boot manager shall start and execute the application.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0178 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0179Otherwise if at startup the ECU hardware/software is inconsistent the boot manager shall start and execute the boot loader and reset DIDs 0xF181, 0xF187 and 0xF188 and 0xF1A1 to default values.
Statement

Otherwise if at startup the ECU hardware/software is inconsistent the boot manager shall start and execute the boot loader and reset DIDs 0xF181, 0xF187 and 0xF188 and 0xF1A1 to default values.

SSR-BOOT-005Bootloader and Application State Handling — Bootloader and Application State HandlingAD-001componentRFQX-CVS123-2-0179 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0180In case of e.g., flash interruption resetting the DIDs to default values will enable the client to identify the ECU as not having a valid application.
Statement

In case of e.g., flash interruption resetting the DIDs to default values will enable the client to identify the ECU as not having a valid application.

NoneNoneNoneNoneRFQX-CVS123-2-0180 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0181If at startup the boot manager starts and executes the application, the application shall read and apply the parameter values persisted in the boot parameter module.
Statement

If at startup the boot manager starts and executes the application, the application shall read and apply the parameter values persisted in the boot parameter module.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0181 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0182Otherwise if at startup the boot manager starts and executes the boot loader and a valid boot parameter module has been successfully programmed, the boot loader shall read and apply these parameter values from the boot parameter module.
Statement

Otherwise if at startup the boot manager starts and executes the boot loader and a valid boot parameter module has been successfully programmed, the boot loader shall read and apply these parameter values from the boot parameter module.

NoneNoneAD-008componentRFQX-CVS123-2-0182 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0183Otherwise if no boot parameter module has been successfully programmed, the boot loader shall apply the corresponding parameter values persisted in the boot loader module.
Statement

Otherwise if no boot parameter module has been successfully programmed, the boot loader shall apply the corresponding parameter values persisted in the boot loader module.

NoneNoneAD-008componentRFQX-CVS123-2-0183 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0184After reprogramming, the application shall store DIDs F1AB, F1AA, F1A9.
Statement

After reprogramming, the application shall store DIDs F1AB, F1AA, F1A9.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0184 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0185The technical implementation of the programming preconditions shall be agreed between the supplier and the vehicle manufacturer.
Statement

The technical implementation of the programming preconditions shall be agreed between the supplier and the vehicle manufacturer.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS123-2-0185 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0186A programmable server shall guarantee re-programmability within the normal operating voltage range specified by [11] for 24V systems or [12] for 12V systems.
Statement

A programmable server shall guarantee re-programmability within the normal operating voltage range specified by [11] for 24V systems or [12] for 12V systems.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0186 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0187A server that is restarted for any reason or thrown back to DefaultSession due to lack of TesterPresent or unfulfilled preconditions shall always support programming from the start of the programming sequence (programming step P1Pre), i.e., shall not depend on any state from an interrupted programming sequence.
Statement

A server that is restarted for any reason or thrown back to DefaultSession due to lack of TesterPresent or unfulfilled preconditions shall always support programming from the start of the programming sequence (programming step P1Pre), i.e., shall not depend on any state from an interrupted programming sequence.

SSR-UPD-003Secure software update and flash readiness — Software Update / FlashingAD-002componentRFQX-CVS123-2-0187 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0188The server shall guarantee re-programmability in the event of error conditions during the programming process regardless of cause.
Statement

The server shall guarantee re-programmability in the event of error conditions during the programming process regardless of cause.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0188 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0189The causes specified in (ISO14229-1:2020) shall be regarded as examples.
Statement

The causes specified in (ISO14229-1:2020) shall be regarded as examples.

NoneNoneAD-008componentRFQX-CVS123-2-0189 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0190The server shall be re-programmable (standalone and in the vehicle) regardless of whether the application and application data is valid or has been corrupted.
Statement

The server shall be re-programmable (standalone and in the vehicle) regardless of whether the application and application data is valid or has been corrupted.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0190 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0191This means, for example, that loss of application server specific diagnostic address, -bitrate or - system name as a result of a failure during boot parameter module programming in the workshop is not acceptable.
Statement

This means, for example, that loss of application server specific diagnostic address, -bitrate or - system name as a result of a failure during boot parameter module programming in the workshop is not acceptable.

NoneNoneNoneNoneRFQX-CVS123-2-0191 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0192Diagnostic services support shall be as per CVS124.
Statement

Diagnostic services support shall be as per CVS124.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0192 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0193Additionally, the services specified in Table 3 shall be supported.
Statement

Additionally, the services specified in Table 3 shall be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0193 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0194In case of divergences between CVS124 and Table 3, this document takes precedence.
Statement

In case of divergences between CVS124 and Table 3, this document takes precedence.

NoneNoneNoneNoneRFQX-CVS123-2-0194 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0195For a server, it is the combination of services support in CVS124 and Table 3 that will constitute the complete picture of supported services.
Statement

For a server, it is the combination of services support in CVS124 and Table 3 that will constitute the complete picture of supported services.

NoneNoneNoneNoneRFQX-CVS123-2-0195 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0196ECU identification data support shall be as per CVS124.
Statement

ECU identification data support shall be as per CVS124.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-CVS123-2-0196 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0197When programmed in the vehicle manufacturer’s production facility the total time for programming of all modules shall not exceed 90 seconds with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2).
Statement

When programmed in the vehicle manufacturer’s production facility the total time for programming of all modules shall not exceed 90 seconds with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2).

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0197 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0198This does not apply to ECUs for which all software modules are pre-programmed in supplier premises, even if a software update capability is required in vehicle manufacturer production premises, e.g., for bug fixing.
Statement

This does not apply to ECUs for which all software modules are pre-programmed in supplier premises, even if a software update capability is required in vehicle manufacturer production premises, e.g., for bug fixing.

NoneNoneAD-001componentRFQX-CVS123-2-0198 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0199When programmed in the workshop the total time for programming of all modules shall not exceed 10 minutes with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2).
Statement

When programmed in the workshop the total time for programming of all modules shall not exceed 10 minutes with the programming sequence described in chapter Programming phase #1 – Download of application software and/or application data (phase #1 and phase #2).

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0199 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0200The server shall support the routines specified in Table 4.
Statement

The server shall support the routines specified in Table 4.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0200 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0201If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request.
Statement

If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-CVS123-2-0201 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0202In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint.
Statement

In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint.

NoneNoneNoneNoneRFQX-CVS123-2-0202 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0203If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).
Statement

If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0203 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0204Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error.
Statement

Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error.

SSR-SDT-001Secure Data Transfer / Data Security Container — Secure Data Transfer / Data Security ContainerAD-001componentRFQX-CVS123-2-0204 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0205If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x24
Statement

If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x24

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0205 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0206(requestSequenceError) and shall accept programming to proceed from the state at which it was executing before this non-permitted service was requested.
Statement

(requestSequenceError) and shall accept programming to proceed from the state at which it was executing before this non-permitted service was requested.

NoneNoneAD-001componentRFQX-CVS123-2-0206 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0207For each received RequestDownload request, the server shall check if there is a VerificationEntry match in SDSC.
Statement

For each received RequestDownload request, the server shall check if there is a VerificationEntry match in SDSC.

SSR-VV-002Security evidence and traceability — Verification and ValidationAD-002componentRFQX-CVS123-2-0207 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0208For more information on SDSC, see chapter 9.
Statement

For more information on SDSC, see chapter 9.

NoneNoneNoneNoneRFQX-CVS123-2-0208 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0209The server shall check whether any part of the received data is encrypted or not by checking the address ranges for a match in EncryptionEntry defined in SDSC.
Statement

The server shall check whether any part of the received data is encrypted or not by checking the address ranges for a match in EncryptionEntry defined in SDSC.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0209 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0210If an encryptionEntry match is found, see chapter 9.3.
Statement

If an encryptionEntry match is found, see chapter 9.3.

NoneNoneNoneNoneRFQX-CVS123-2-0210 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0211The server shall not execute the new software until it can be verified using routine 0xFF01.
Statement

The server shall not execute the new software until it can be verified using routine 0xFF01.

SSR-COM-006Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-001componentRFQX-CVS123-2-0211 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0212The software to be received over TransferData (0x36) is to be considered NOT_OK until a verification takes place.
Statement

The software to be received over TransferData (0x36) is to be considered NOT_OK until a verification takes place.

NoneNoneNoneNoneRFQX-CVS123-2-0212 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0213The server shall support service request formatted according to Table 5.
Statement

The server shall support service request formatted according to Table 5.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0213 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0214The server shall support service positive response formatted according to Table 6.
Statement

The server shall support service positive response formatted according to Table 6.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0214 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0215The server shall support service negative response as per ISO14229-1:2020.
Statement

The server shall support service negative response as per ISO14229-1:2020.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0215 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0216In case a software is encrypted, the server shall decrypt the software before decompression and software hash comparison verification are performed.
Statement

In case a software is encrypted, the server shall decrypt the software before decompression and software hash comparison verification are performed.

SSR-VV-003Security evidence and traceability — Verification and ValidationAD-001componentRFQX-CVS123-2-0216 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0217In case a software is compressed, the server shall decompress the software before software hash comparison verification is performed.
Statement

In case a software is compressed, the server shall decompress the software before software hash comparison verification is performed.

SSR-VV-003Security evidence and traceability — Verification and ValidationAD-001componentRFQX-CVS123-2-0217 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0218The server shall verify the software hash after decryption and/or decompression are performed.
Statement

The server shall verify the software hash after decryption and/or decompression are performed.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0218 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0219Considering that hashing, compression and encryption methods were used prior to transfer a software to the server, the server will decrypt, decompress, and perform software hashing comparison verification in this respective order.
Statement

Considering that hashing, compression and encryption methods were used prior to transfer a software to the server, the server will decrypt, decompress, and perform software hashing comparison verification in this respective order.

NoneNoneNoneNoneRFQX-CVS123-2-0219 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0220The server shall support parameter dataFormatIdentifier formatted according to Table 7.
Statement

The server shall support parameter dataFormatIdentifier formatted according to Table 7.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0220 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0221Negative Response
Statement

Negative Response

NoneNoneNoneNoneRFQX-CVS123-2-0221 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0222The server shall support parameter addressAndLengthFormatIdentifier formatted according to Table 8.
Statement

The server shall support parameter addressAndLengthFormatIdentifier formatted according to Table 8.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0222 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0223Table 8: Service 0x34 addressAndLengthFormatIdentifier Format Bits Description Cvt Values 7 - 4 Length (number of bytes) of the memorySize parameter M 3,4 3 - 0 Length (number of bytes) of the memoryAddress parameter M 3, 4 7.1.4.3 Parameter lengthFormatIdentifier The server shall support parameter lengthFormatIdentifier formatted according to Table 9.
Statement

Table 8: Service 0x34 addressAndLengthFormatIdentifier Format Bits Description Cvt Values 7 - 4 Length (number of bytes) of the memorySize parameter M 3,4 3 - 0 Length (number of bytes) of the memoryAddress parameter M 3, 4 7.1.4.3 Parameter lengthFormatIdentifier The server shall support parameter lengthFormatIdentifier formatted according to Table 9.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0223 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0224The server shall support request formatted according to ISO14229-1:2020.
Statement

The server shall support request formatted according to ISO14229-1:2020.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0224 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0225The server shall support positive response formatted according to ISO14229-1:2020.
Statement

The server shall support positive response formatted according to ISO14229-1:2020.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0225 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0226If for any reason an error occurs during decryption of data, the server shall return NRC 0x10.
Statement

If for any reason an error occurs during decryption of data, the server shall return NRC 0x10.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0226 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0227The server shall support parameter blockSequenceCounter formatted according to ISO14229-1:2020.
Statement

The server shall support parameter blockSequenceCounter formatted according to ISO14229-1:2020.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0227 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0228The server shall support parameter transferRequestParameterRecord formatted according to ISO14229-1:2020.
Statement

The server shall support parameter transferRequestParameterRecord formatted according to ISO14229-1:2020.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0228 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0229The server shall support request formatted according to Table 10.
Statement

The server shall support request formatted according to Table 10.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0229 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0230The server shall support positive response formatted according to Table 11.
Statement

The server shall support positive response formatted according to Table 11.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0230 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-02317.3.4 Service 0x37 Parameters 7.3.4.1 Parameter transferRequestParameterRecord
Statement

7.3.4 Service 0x37 Parameters 7.3.4.1 Parameter transferRequestParameterRecord

NoneNoneNoneNoneRFQX-CVS123-2-0231 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0232The server shall not support transferRequestParameterRecord parameter.
Statement

The server shall not support transferRequestParameterRecord parameter.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0232 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0233The server shall not support transferResponseParameterRecord parameter.
Statement

The server shall not support transferResponseParameterRecord parameter.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0233 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0234The server shall support service 0x84 according to CVS32.
Statement

The server shall support service 0x84 according to CVS32.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0234 / 18hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0235The server shall support request formatted according to ISO14229-1:2020.
Statement

The server shall support request formatted according to ISO14229-1:2020.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0235 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0236Negative Response
Statement

Negative Response

NoneNoneNoneNoneRFQX-CVS123-2-0236 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0237The server shall support positive response formatted according to ISO14229-1:2020.
Statement

The server shall support positive response formatted according to ISO14229-1:2020.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0237 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0238The server shall support negative response codes according to CVS32.
Statement

The server shall support negative response codes according to CVS32.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0238 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0239The server shall support parameter Administrative Parameter formatted according to ISO14229-1:2020.
Statement

The server shall support parameter Administrative Parameter formatted according to ISO14229-1:2020.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0239 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0240The server shall support parameter Signature/Encryption Calculation (SIGENCRYPT) according to CVS32.
Statement

The server shall support parameter Signature/Encryption Calculation (SIGENCRYPT) according to CVS32.

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS123-2-0240 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0241The server shall support parameter Anti-replay Counter (ANTIREPLAYCNT) according to CVS32.
Statement

The server shall support parameter Anti-replay Counter (ANTIREPLAYCNT) according to CVS32.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS123-2-0241 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0242The server shall support the routine in the diagnosticSession according to Table 12.
Statement

The server shall support the routine in the diagnosticSession according to Table 12.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0242 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0243The server shall support the routineControlType according to Table 13.
Statement

The server shall support the routineControlType according to Table 13.

SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceAD-007componentRFQX-CVS123-2-0243 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0244Table 13: Routine Support per routineControlType RID Name routineControlType startRoutine (0x01) stopRoutine (0x02) requestRoutineResults (0x03) 0x2202 Check Memory Block M - - 0xFF00 EraseMemory M - - 0xFF01 CheckProgrammingDependencies M - - 0xCAFE Entity Management Protocol (EMP) M - - M = Mandatory 8.1.3 Routine Safe State Requirement The server shall implement diagnostic safe state, as per CVS124, as preconditions to the routines according to Table 14.
Statement

Table 13: Routine Support per routineControlType RID Name routineControlType startRoutine (0x01) stopRoutine (0x02) requestRoutineResults (0x03) 0x2202 Check Memory Block M - - 0xFF00 EraseMemory M - - 0xFF01 CheckProgrammingDependencies M - - 0xCAFE Entity Management Protocol (EMP) M - - M = Mandatory 8.1.3 Routine Safe State Requirement The server shall implement diagnostic safe state, as per CVS124, as preconditions to the routines according to Table 14.

SSR-RBAC-002Secure software update and flash readiness — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0244 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0245Table 14: Routine support for Safe State Conditions RID Name Safe State 0x2202 Check Memory Block M 0xFF00 EraseMemory M - 0xFF01 CheckProgrammingDependencies M M 0xCAFE Entity Management Protocol (EMP) M M M = Mandatory 8.2 Routine 0x2202 – Check Memory Block The RoutineIdentifier allows the client to start a server routine which verifies the correctness of a programmed module.
Statement

Table 14: Routine support for Safe State Conditions RID Name Safe State 0x2202 Check Memory Block M 0xFF00 EraseMemory M - 0xFF01 CheckProgrammingDependencies M M 0xCAFE Entity Management Protocol (EMP) M M M = Mandatory 8.2 Routine 0x2202 – Check Memory Block The RoutineIdentifier allows the client to start a server routine which verifies the correctness of a programmed module.

NoneNoneNoneNoneRFQX-CVS123-2-0245 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0246The server shall verify the programmed software module by calculating a checksum on the programmed data by matching this checksum with a pre-calculated checksum.
Statement

The server shall verify the programmed software module by calculating a checksum on the programmed data by matching this checksum with a pre-calculated checksum.

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS123-2-0246 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0247The pre-calculated checksum shall be provided as part of the data submitted with the TransferData service request.
Statement

The pre-calculated checksum shall be provided as part of the data submitted with the TransferData service request.

SSR-SDT-001Secure Data Transfer / Data Security Container — Secure Data Transfer / Data Security ContainerAD-001componentRFQX-CVS123-2-0247 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0248It is server specific the generator polynomial and initial value to be used.
Statement

It is server specific the generator polynomial and initial value to be used.

NoneNoneNoneNoneRFQX-CVS123-2-0248 / 18hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0249Implementation Hint: The following generator polynomial with the following initial value are suggested to be used for calculation of the checksum: G(X) = x32 + x26 + x23 + x22 + x16 + x12 + x11 + x10 + x8 + x7 + x5 + x4 + x2 + x + 1 Initial value: 0xFFFFFFFF 8.2.1 Request
Statement

Implementation Hint: The following generator polynomial with the following initial value are suggested to be used for calculation of the checksum: G(X) = x32 + x26 + x23 + x22 + x16 + x12 + x11 + x10 + x8 + x7 + x5 + x4 + x2 + x + 1 Initial value: 0xFFFFFFFF 8.2.1 Request

NoneNoneNoneNoneRFQX-CVS123-2-0249 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0250The server shall support the routine request according to Table 15.
Statement

The server shall support the routine request according to Table 15.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0250 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0251Table 15: Routine 0x2202 Request Format Byte Description Cvt Hex #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0x22 #4 routineIdentifier (LSB) M 0x02 8.2.2 Positive Response The server shall support the routine positive response according to Table 16.
Statement

Table 15: Routine 0x2202 Request Format Byte Description Cvt Hex #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0x22 #4 routineIdentifier (LSB) M 0x02 8.2.2 Positive Response The server shall support the routine positive response according to Table 16.

SSR-DIAG-002Diagnostic Services — Diagnostic ServicesAD-002componentRFQX-CVS123-2-0251 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0252Table 16: Routine 0x2202 Positive Response Format Byte Description Cvt Byte Value #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) checkMemory [byte#1] M 0x22 #4 routineIdentifier (LSB) checkMemory [byte#2] M 0x02 #5 routineStatus routineResult M 0x00-0xFF 8.2.3 Negative Response
Statement

Table 16: Routine 0x2202 Positive Response Format Byte Description Cvt Byte Value #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) checkMemory [byte#1] M 0x22 #4 routineIdentifier (LSB) checkMemory [byte#2] M 0x02 #5 routineStatus routineResult M 0x00-0xFF 8.2.3 Negative Response

NoneNoneNoneNoneRFQX-CVS123-2-0252 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0253SUV2_REQ 4 prevents the scenario of erasing the copied bootloader while boot loader update and leaving the ECU without any bootloader.
Statement

SUV2_REQ 4 prevents the scenario of erasing the copied bootloader while boot loader update and leaving the ECU without any bootloader.

NoneNoneNoneNoneRFQX-CVS123-2-0253 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0254The server shall support parameter routineStatus routineResult formatted according to Table 17.
Statement

The server shall support parameter routineStatus routineResult formatted according to Table 17.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0254 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0255This RoutineIdentifier value allows the client to start a routine which erases ECU internal non- volatile memory.
Statement

This RoutineIdentifier value allows the client to start a routine which erases ECU internal non- volatile memory.

NoneNoneNoneNoneRFQX-CVS123-2-0255 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0256The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested.
Statement

The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0256 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0257In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint.
Statement

In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint.

NoneNoneNoneNoneRFQX-CVS123-2-0257 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0258In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area.
Statement

In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area.

SSR-BOOT-002Secure software update and flash readiness — Bootloader and Application State HandlingAD-006componentRFQX-CVS123-2-0258 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0259prevents the scenario of erasing the copied bootloader while boot loader update and leaving the ECU without any bootloader.
Statement

prevents the scenario of erasing the copied bootloader while boot loader update and leaving the ECU without any bootloader.

NoneNoneNoneNoneRFQX-CVS123-2-0259 / 26hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0260When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see section Software and data identification): • If boot software (any part) is erased, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).
Statement

When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see section Software and data identification): • If boot software (any part) is erased, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0260 / 16hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0261The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e., the erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase.
Statement

The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e., the erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase.

SSR-SDT-001Secure Data Transfer / Data Security Container — Secure Data Transfer / Data Security ContainerAD-001componentRFQX-CVS123-2-0261 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0262The server shall support the routine request according to Table 18.
Statement

The server shall support the routine request according to Table 18.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0262 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0263The server shall support the routine positive response according to Table 19.
Statement

The server shall support the routine positive response according to Table 19.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0263 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-02648.3.4 Routine 0xFF00 Parameters 8.3.4.1 Parameter addressAndLengthFormatIdentifier
Statement

8.3.4 Routine 0xFF00 Parameters 8.3.4.1 Parameter addressAndLengthFormatIdentifier

NoneNoneNoneNoneRFQX-CVS123-2-0264 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0265The server shall support parameter addressAndLengthFormatIdentifier formatted according to Table 20.
Statement

The server shall support parameter addressAndLengthFormatIdentifier formatted according to Table 20.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0265 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0266E.g., 02, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements &
Statement

E.g., 02, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements &

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0266 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0267.
Statement

.

NoneNoneNoneNoneRFQX-CVS123-2-0267 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0268When the addressAndLengthFormatIdentifier is set to 0x01 the defined module to index mapping shall apply for the memoryStartAddress according to Table 21.
Statement

When the addressAndLengthFormatIdentifier is set to 0x01 the defined module to index mapping shall apply for the memoryStartAddress according to Table 21.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0268 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0269The server shall support parameter routineStatus routineResult formatted according to Table 22.
Statement

The server shall support parameter routineStatus routineResult formatted according to Table 22.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0269 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0270This RoutineIdentifier value allows the client to start a consistency check of the server.
Statement

This RoutineIdentifier value allows the client to start a consistency check of the server.

NoneNoneNoneNoneRFQX-CVS123-2-0270 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0271This RoutineIdentifier shall be able to execute independent from programming sequence
Statement

This RoutineIdentifier shall be able to execute independent from programming sequence

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS123-2-0271 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0272The client may opt to execute this routineIdentifier as a standalone procedure to check to perform a software consistency check.
Statement

The client may opt to execute this routineIdentifier as a standalone procedure to check to perform a software consistency check.

NoneNoneNoneNoneRFQX-CVS123-2-0272 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0273The server shall check whether the individual modules are complete and compatible with one another.
Statement

The server shall check whether the individual modules are complete and compatible with one another.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0273 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0274In addition, a check shall be made to determine whether the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data).
Statement

In addition, a check shall be made to determine whether the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data).

NoneNoneAD-001componentRFQX-CVS123-2-0274 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0275The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer.
Statement

The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0275 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0276The consistency check shall be carried out solely by the server.
Statement

The consistency check shall be carried out solely by the server.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0276 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0277The server shall verify the integrity of the software as a part of the consistency check.
Statement

The server shall verify the integrity of the software as a part of the consistency check.

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS123-2-0277 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0278The integrity information shall be supplied to the server before the software is updated.
Statement

The integrity information shall be supplied to the server before the software is updated.

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS123-2-0278 / 26hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0279The integrity check shall be carried out solely by the server.
Statement

The integrity check shall be carried out solely by the server.

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS123-2-0279 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0280Details over the integrity check can be found on chapter 9.2.
Statement

Details over the integrity check can be found on chapter 9.2.

NoneNoneNoneNoneRFQX-CVS123-2-0280 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0281The server shall support the routine request according to Table 23.
Statement

The server shall support the routine request according to Table 23.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0281 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0282The server shall support the routine positive response according to Table 24.
Statement

The server shall support the routine positive response according to Table 24.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0282 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-02838.4.4 Routine 0xFF01 Parameters 8.4.4.1 Parameter routineStatus routineResult
Statement

8.4.4 Routine 0xFF01 Parameters 8.4.4.1 Parameter routineStatus routineResult

NoneNoneNoneNoneRFQX-CVS123-2-0283 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0284The server shall support parameter routineStatus routineResult formatted according to Table 25.
Statement

The server shall support parameter routineStatus routineResult formatted according to Table 25.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0284 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0285Table 25: Routine 0xFF01 routineStatus routineResult Format Hex Description Cvt 0x00 correctResult M 0x01 incorrectResult - General Failure M 0x02 incorrectResult error SW – HW M 0x03 incorrectResult error SW – SW M 0x04 IncorrectResult One or more modules are not programmed or are incorrectly programmed M 0x05 incorrectResult One or more modules failed when verifying the integrity of the software M 0x06 – 0xFF Reserved M The server shall set routineResult as 0x00 (correctResult) if the integrity verification is valid, the software was successfully installed and the installed software are compatible between all software module and the software is compatible with the ECU hardware.
Statement

Table 25: Routine 0xFF01 routineStatus routineResult Format Hex Description Cvt 0x00 correctResult M 0x01 incorrectResult - General Failure M 0x02 incorrectResult error SW – HW M 0x03 incorrectResult error SW – SW M 0x04 IncorrectResult One or more modules are not programmed or are incorrectly programmed M 0x05 incorrectResult One or more modules failed when verifying the integrity of the software M 0x06 – 0xFF Reserved M The server shall set routineResult as 0x00 (correctResult) if the integrity verification is valid, the software was successfully installed and the installed software are compatible between all software module and the software is compatible with the ECU hardware.

SSR-DAI-005Security evidence and traceability — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS123-2-0285 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0286If the server set routineResult as 0x00 (CorrectResult) the server shall reject with NRC 0x24 the following diagnostic services and routines until a new SDSC is provided
Statement

If the server set routineResult as 0x00 (CorrectResult) the server shall reject with NRC 0x24 the following diagnostic services and routines until a new SDSC is provided

NoneNoneAD-007componentRFQX-CVS123-2-0286 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0287• Routine 0xFF00 Erase Memory
Statement

• Routine 0xFF00 Erase Memory

NoneNoneNoneNoneRFQX-CVS123-2-0287 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0288• Service 0x34 RequestDownload
Statement

• Service 0x34 RequestDownload

NoneNoneNoneNoneRFQX-CVS123-2-0288 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0289• Service 0x36 TransferData
Statement

• Service 0x36 TransferData

NoneNoneNoneNoneRFQX-CVS123-2-0289 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0290• Service 0x37 RequestTransferExit 8.4.4.2 Parameter routineResultProofLength
Statement

• Service 0x37 RequestTransferExit 8.4.4.2 Parameter routineResultProofLength

NoneNoneNoneNoneRFQX-CVS123-2-0290 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0291This parameter consist of the length of the routineResultProof parameter.
Statement

This parameter consist of the length of the routineResultProof parameter.

NoneNoneNoneNoneRFQX-CVS123-2-0291 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0292The server shall hash the receipt number with the routineStatus routineResult parameter, in this respective order.
Statement

The server shall hash the receipt number with the routineStatus routineResult parameter, in this respective order.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0292 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0293The receipt number is received as part of the EMP message whenever a SDSC is set, please refer to CVS34.
Statement

The receipt number is received as part of the EMP message whenever a SDSC is set, please refer to CVS34.

NoneNoneNoneNoneRFQX-CVS123-2-0293 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0294The hash algorithm shall be SHA512.
Statement

The hash algorithm shall be SHA512.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0294 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0295The server shall sign the hashed output using the receipt-keys.
Statement

The server shall sign the hashed output using the receipt-keys.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0295 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0296For information on receipt-keys, please refer to CVS34.
Statement

For information on receipt-keys, please refer to CVS34.

NoneNoneNoneNoneRFQX-CVS123-2-0296 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0297The server shall use ED25519 as signature algorithm.
Statement

The server shall use ED25519 as signature algorithm.

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS123-2-0297 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0298The server shall return in the parameter routineResultProof the signed hash.
Statement

The server shall return in the parameter routineResultProof the signed hash.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0298 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0299The client shall send the Servers routineStatus routineResult response to the backend.
Statement

The client shall send the Servers routineStatus routineResult response to the backend.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0299 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0300SDSC is transmitted via EMP, see chapter 9.
Statement

SDSC is transmitted via EMP, see chapter 9.

NoneNoneNoneNoneRFQX-CVS123-2-0300 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0301The SDSC content, including the reference hash used for software verification, is signed as part of the set request when transmitted over EMP.
Statement

The SDSC content, including the reference hash used for software verification, is signed as part of the set request when transmitted over EMP.

NoneNoneNoneNoneRFQX-CVS123-2-0301 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0302Once a SDSC has being accepted by the server, the server shall store in the NVM the receipt number sent over as part of the EMP request.
Statement

Once a SDSC has being accepted by the server, the server shall store in the NVM the receipt number sent over as part of the EMP request.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0302 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0303Once a SDSC has being accepted by the server, the server shall accept the following diagnostic services and routines: • Routine 0xFF00 Erase Memory
Statement

Once a SDSC has being accepted by the server, the server shall accept the following diagnostic services and routines: • Routine 0xFF00 Erase Memory

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS123-2-0303 / 29hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0304• Service 0x34 RequestDownload
Statement

• Service 0x34 RequestDownload

NoneNoneNoneNoneRFQX-CVS123-2-0304 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0305• Service 0x36 TransferData
Statement

• Service 0x36 TransferData

NoneNoneNoneNoneRFQX-CVS123-2-0305 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0306• Service 0x37 RequestTransferExit
Statement

• Service 0x37 RequestTransferExit

NoneNoneNoneNoneRFQX-CVS123-2-0306 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0307Negative Response
Statement

Negative Response

NoneNoneNoneNoneRFQX-CVS123-2-0307 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0308The server shall support the routine request according to Table 26.
Statement

The server shall support the routine request according to Table 26.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0308 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0309Table 26: Routine 0xCAFE Request Format Byte Description Cvt Hex #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0xCA #4 routineIdentifier (LSB) M 0xFE #5 … #n EMP Message M 0x00 – 0xFF 8.5.2 Positive Response The server shall support the routine positive response according to Table 27.
Statement

Table 26: Routine 0xCAFE Request Format Byte Description Cvt Hex #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0xCA #4 routineIdentifier (LSB) M 0xFE #5 … #n EMP Message M 0x00 – 0xFF 8.5.2 Positive Response The server shall support the routine positive response according to Table 27.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0309 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0310The server shall support the routine negative response according to CVS33.
Statement

The server shall support the routine negative response according to CVS33.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0310 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0311The server shall support the parameter EMP message according to CVS33.
Statement

The server shall support the parameter EMP message according to CVS33.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0311 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0312The information required for the server for verifying software integrity and optionally decrypt the transported data from a trusted source, is described in a Software Data Security Container (SDSC).
Statement

The information required for the server for verifying software integrity and optionally decrypt the transported data from a trusted source, is described in a Software Data Security Container (SDSC).

NoneNoneAD-007componentRFQX-CVS123-2-0312 / 56hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivity; evidence completenessNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0313The server shall implement SDSC structure as defined in CVS154.
Statement

The server shall implement SDSC structure as defined in CVS154.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0313 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0314SDSC supports verification entries, encryption entries and items as defined in DSC.
Statement

SDSC supports verification entries, encryption entries and items as defined in DSC.

NoneNoneNoneNoneRFQX-CVS123-2-0314 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0315For the context of SDSC, range is defined as: • Start = memory address offset to be verified/decrypted.
Statement

For the context of SDSC, range is defined as: • Start = memory address offset to be verified/decrypted.

NoneNoneNoneNoneRFQX-CVS123-2-0315 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0316The range start field shall be the memory address offset from the dataLocator field.
Statement

The range start field shall be the memory address offset from the dataLocator field.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS123-2-0316 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0317The range length field shall be the number of bytes to be verified.
Statement

The range length field shall be the number of bytes to be verified.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0317 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0318For the context of SDSC, dataLocator is defined as an identification the server uses to locate the software module.
Statement

For the context of SDSC, dataLocator is defined as an identification the server uses to locate the software module.

NoneNoneNoneNoneRFQX-CVS123-2-0318 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0319The supplier shall propose for each software module an identification to be used in dataLocator field in SDSC.
Statement

The supplier shall propose for each software module an identification to be used in dataLocator field in SDSC.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0319 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0320The vehicle manufacturer shall review and accept the proposals for every dataLocator.
Statement

The vehicle manufacturer shall review and accept the proposals for every dataLocator.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS123-2-0320 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0321The dataLocator field is used to provide to the server the means to identify which module the verification or encryption entries refer to.
Statement

The dataLocator field is used to provide to the server the means to identify which module the verification or encryption entries refer to.

NoneNoneNoneNoneRFQX-CVS123-2-0321 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0322The start address shall be used as an offset in the software module while the length can be utilized to know which areas of the software module are to be verified and/or decrypted.
Statement

The start address shall be used as an offset in the software module while the length can be utilized to know which areas of the software module are to be verified and/or decrypted.

NoneNoneAD-001componentRFQX-CVS123-2-0322 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0323Before accepting the SDSC as valid, the server shall perform the sanity check of the received SDSC as defined in CVS154.
Statement

Before accepting the SDSC as valid, the server shall perform the sanity check of the received SDSC as defined in CVS154.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0323 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0324In DSC sanity check, there is a specific area of application sanity check which depends on the context of the general DSC.
Statement

In DSC sanity check, there is a specific area of application sanity check which depends on the context of the general DSC.

NoneNoneNoneNoneRFQX-CVS123-2-0324 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0325If the sanity check returns fail/invalid, the server shall reject SDSC as described in CVS34.
Statement

If the sanity check returns fail/invalid, the server shall reject SDSC as described in CVS34.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0325 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0326The server shall validate each VerificationEntry found in the SDSC.
Statement

The server shall validate each VerificationEntry found in the SDSC.

SSR-VV-003Security evidence and traceability — Verification and ValidationAD-001componentRFQX-CVS123-2-0326 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0327The referenceHash defines the reference hash value to be used in the hash comparison.
Statement

The referenceHash defines the reference hash value to be used in the hash comparison.

NoneNoneNoneNoneRFQX-CVS123-2-0327 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0328Software hashes in the SDSC shall be verified by the server considering the ranges which are stated in the SDSC.
Statement

Software hashes in the SDSC shall be verified by the server considering the ranges which are stated in the SDSC.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0328 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0329The Ranges dictates the data range that the server shall begin, and end read from NVM for hashing.
Statement

The Ranges dictates the data range that the server shall begin, and end read from NVM for hashing.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS123-2-0329 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0330The Ranges can be one or several if there are gaps between memory areas which shall be excluded from the hash calculation for some reason.
Statement

The Ranges can be one or several if there are gaps between memory areas which shall be excluded from the hash calculation for some reason.

NoneNoneAD-006componentRFQX-CVS123-2-0330 / 56hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0331When hashing software, the whole memory range, including erased-only bytes of a memory module, shall be possible to include in the hash calculation.
Statement

When hashing software, the whole memory range, including erased-only bytes of a memory module, shall be possible to include in the hash calculation.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS123-2-0331 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0332Erased-only bytes are parts of the memory module that are not programmed with data.
Statement

Erased-only bytes are parts of the memory module that are not programmed with data.

NoneNoneNoneNoneRFQX-CVS123-2-0332 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0333The byte value of an erased data byte (typically FF or 00) depends on the MCU/Flash memory and shall be specified by the software supplier as an input for the hashing process.
Statement

The byte value of an erased data byte (typically FF or 00) depends on the MCU/Flash memory and shall be specified by the software supplier as an input for the hashing process.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS123-2-0333 / 29hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0334The server shall be able to verify that erased-only blocks covered in range of memory are erased.
Statement

The server shall be able to verify that erased-only blocks covered in range of memory are erased.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS123-2-0334 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0335When the server has verified all verificationEntries, a result OK/NOT_OK shall be returned.
Statement

When the server has verified all verificationEntries, a result OK/NOT_OK shall be returned.

SSR-VV-002Security evidence and traceability — Verification and ValidationAD-002componentRFQX-CVS123-2-0335 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0336If NOT_OK is returned, the server shall not accept the new software for execution.
Statement

If NOT_OK is returned, the server shall not accept the new software for execution.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0336 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0337If OK is returned, the server shall accept that installed software is valid in terms of integrity.
Statement

If OK is returned, the server shall accept that installed software is valid in terms of integrity.

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS123-2-0337 / 8hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0338The server may execute other checks to verify the software before concluding if the installed software shall be accepted.
Statement

The server may execute other checks to verify the software before concluding if the installed software shall be accepted.

NoneNoneAD-001componentRFQX-CVS123-2-0338 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0339For the received data, where a match is found in the EncryptionEntry of the DSC, the server shall initialize a cipher if not previously initialized.
Statement

For the received data, where a match is found in the EncryptionEntry of the DSC, the server shall initialize a cipher if not previously initialized.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS123-2-0339 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS123-2-0340An initialized data (i.e., cipher scheme) shall be kept active until no more received data matches the current EncryptionEntry.
Statement

An initialized data (i.e., cipher scheme) shall be kept active until no more received data matches the current EncryptionEntry.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0340 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0341The cipher shall be reinitialized for each new Encryption entry.
Statement

The cipher shall be reinitialized for each new Encryption entry.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0341 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0342According to best practise received data shall be decrypted “on the fly” before storing to NVM.
Statement

According to best practise received data shall be decrypted “on the fly” before storing to NVM.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS123-2-0342 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS123-2-0343Other methods shall be agreed upon with OEM.
Statement

Other methods shall be agreed upon with OEM.

NoneNoneAD-008componentRFQX-CVS123-2-0343 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS123-2-0344The received data to decrypt may only be parts of a software module and it will be based on the range defined.
Statement

The received data to decrypt may only be parts of a software module and it will be based on the range defined.

NoneNoneNoneNoneRFQX-CVS123-2-0344 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0345EncryptionEntries are not present if software is not encrypted.
Statement

EncryptionEntries are not present if software is not encrypted.

NoneNoneNoneNoneRFQX-CVS123-2-0345 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0346The Non-volatile server memory programming complete flow can be found in Annex B.
Statement

The Non-volatile server memory programming complete flow can be found in Annex B.

NoneNoneNoneNoneRFQX-CVS123-2-0346 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0347#008AFFFF #
Statement

#008AFFFF #

NoneNoneNoneNoneRFQX-CVS123-2-0347 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0348#00BFFFFF #008B0000 #0092FFFF Module hashData #00AFAAAA #00AFAAAB Figure 8 – Memory layout
Statement

#00BFFFFF #008B0000 #0092FFFF Module hashData #00AFAAAA #00AFAAAB Figure 8 – Memory layout

NoneNoneNoneNoneRFQX-CVS123-2-0348 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS123-2-0349Note that more than one Address field can be specified if there are one or more areas within a memory module which must be excluded in the hash due to some logical restrictions (e.g., boot writing internal data to such area during programming).
Statement

Note that more than one Address field can be specified if there are one or more areas within a memory module which must be excluded in the hash due to some logical restrictions (e.g., boot writing internal data to such area during programming).

NoneNoneAD-006componentRFQX-CVS123-2-0349 / 56hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0350#00BFFFFF #008B0000 #0092FFFF Module hashData #00AFAAAA #00AFAAAB When ECU recieves data that matches an address range in an EncryptionEntry (here in Module B), the server must decrypt the data received by TransferData request.
Statement

#00BFFFFF #008B0000 #0092FFFF Module hashData #00AFAAAA #00AFAAAB When ECU recieves data that matches an address range in an EncryptionEntry (here in Module B), the server must decrypt the data received by TransferData request.

SSR-SDT-002Secure Data Transfer / Data Security Container — Secure Data Transfer / Data Security ContainerAD-006componentRFQX-CVS123-2-0350 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS123-2-0351Module B is encrypted meaning that when the server receives data within a range (given as address and size in RequestDownload) the server must decrypt the data before storing it.
Statement

Module B is encrypted meaning that when the server receives data within a range (given as address and size in RequestDownload) the server must decrypt the data before storing it.

NoneNoneAD-002componentRFQX-CVS123-2-0351 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0001The User shall apply the latest version of this CVS124.
Statement

The User shall apply the latest version of this CVS124.

NoneNoneAD-008componentRFQX-CVS124-0001 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0002Foreword This CVS124 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.
Statement

Foreword This CVS124 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.

NoneNoneNoneNoneRFQX-CVS124-0002 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0003Any review of CVS124 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”.
Statement

Any review of CVS124 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”.

NoneNoneAD-003componentRFQX-CVS124-0003 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0004• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.
Statement

• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.

NoneNoneAD-002componentRFQX-CVS124-0004 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0005Terms
Statement

Table 1 – Definition of Terms Term Definition Shall This word, or the terms "Required" or "Must", means that the definition is an absolute requirement of the specification. Shall not This phrase, or the phrase "Must not", means that the definition is an absolute prohibition of the specification. Should This word, or the adjective “Recommended”, means that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications shall be understood and carefully weighed before choosing a different course. Should not This phrase, or the phrase “Not recommended”, means that there may exist valid reasons in particular circumstances when the particular behavior is acceptable or even useful, but the full implications should be understood and the case carefully weighed before implementing any behavior described with this label. May This word, or the adjective “Optional”, means that an item is truly optional. One vendor may choose to include the item because a particular marketplace requires it or because the vendor feels that it enhances the product while another vendor may omit the same item. An implementation which does not include a particular option shall be prepared to interoperate with another implementation which does include the option, though perhaps with reduced functionality. In the same vein an implementation which does include a particular option shall be prepared to interoperate with another implementation which does not include the option (except, of course, for the feature the option provides).

NoneNoneAD-002componentRFQX-CVS124-0005 / 18hNot importedStill Requires Customer DecisionP1 OPENboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0006Abbreviations
Statement

Table 2 – Abbreviated terms Abbreviation Description DID Data Identifier EnvCond Environment Condition FMI Failure Mode Indication Def Default diagnostic session DSIV Diagnostic Security Implementation Variant Project specific. Dependent of the security variant implemented in the diagnostic server. DTC Diagnostic Trouble Code ECU Electronic Control Unit Ext Extended diagnostic session UDS Unified Diagnostic Services CAN Controller Area Network

NoneNoneNoneNoneRFQX-CVS124-0006 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0007Shall not This phrase, or the phrase "Must not", means that the definition is an absolute prohibition of the specification.
Statement

Shall not This phrase, or the phrase "Must not", means that the definition is an absolute prohibition of the specification.

NoneNoneAD-008componentRFQX-CVS124-0007 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0008Should This word, or the adjective “Recommended”, means that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications shall be understood and carefully weighed before choosing a different course.
Statement

Should This word, or the adjective “Recommended”, means that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications shall be understood and carefully weighed before choosing a different course.

NoneNoneAD-008componentRFQX-CVS124-0008 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0009Should not This phrase, or the phrase “Not recommended”, means that there may exist valid reasons in particular circumstances when the particular behavior is acceptable or even useful, but the full implications should be understood and the case carefully weighed before implementing any behavior described with this label.
Statement

Should not This phrase, or the phrase “Not recommended”, means that there may exist valid reasons in particular circumstances when the particular behavior is acceptable or even useful, but the full implications should be understood and the case carefully weighed before implementing any behavior described with this label.

NoneNoneAD-008componentRFQX-CVS124-0009 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0010May This word, or the adjective “Optional”, means that an item is truly optional.
Statement

May This word, or the adjective “Optional”, means that an item is truly optional.

NoneNoneNoneNoneRFQX-CVS124-0010 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0011One vendor may choose to include the item because a particular marketplace requires it or because the vendor feels that it enhances the product while another vendor may omit the same item.
Statement

One vendor may choose to include the item because a particular marketplace requires it or because the vendor feels that it enhances the product while another vendor may omit the same item.

NoneNoneAD-002componentRFQX-CVS124-0011 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0012An implementation which does not include a particular option shall be prepared to interoperate with another implementation which does include the option, though perhaps with reduced functionality.
Statement

An implementation which does not include a particular option shall be prepared to interoperate with another implementation which does include the option, though perhaps with reduced functionality.

NoneNoneAD-008componentRFQX-CVS124-0012 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0013In the same vein an implementation which does include a particular option shall be prepared to interoperate with another implementation which does not include the option (except, of course, for the feature the option provides).
Statement

In the same vein an implementation which does include a particular option shall be prepared to interoperate with another implementation which does not include the option (except, of course, for the feature the option provides).

NoneNoneAD-008componentRFQX-CVS124-0013 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0014Conventions
Statement

Table 3 – Conventions Implementation Description M Mandatory Mandatory data marked as ‘M’ always shall be returned. If valid data is not needed for the use-case and system at hand, default values should be used. E Mandatory for ECUs which shall be compliant with OBD legislation Worldwide like ISO27145,J1979 etc C Conditional U User optional. Shall be agreed between the supplier and the vehicle manufacturer. - (dash) Not supported Table 4 – Definitions of terms Changing Description DIAG Diagnostics - The Data Identifier content can be changed by means of the UDS service 0x2E FLASH BOOT Boot loader module stored in flash memory FLASH APPL Application module stored in flash memory FLASH DATA Dataset download - The Data Identifier content is changed by a dataset download process as per document Harmonized programming (see /11/) SUPPLIER Supplier process - The Data Identifier content is changed at the supplier's facilities by the manufacturing process. INTERNAL ECU software - The Data Identifier content is determined by the server at runtime.

SSR-BOOT-001Secure software update and flash readiness — Bootloader and Application State HandlingAD-001componentRFQX-CVS124-0014 / 32hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0015If valid data is not needed for the use-case and system at hand, default values should be used.
Statement

If valid data is not needed for the use-case and system at hand, default values should be used.

NoneNoneAD-008componentRFQX-CVS124-0015 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0016E Mandatory for ECUs which shall be compliant with OBD legislation Worldwide like ISO27145,J1979 etc C Conditional U User optional.
Statement

E Mandatory for ECUs which shall be compliant with OBD legislation Worldwide like ISO27145,J1979 etc C Conditional U User optional.

NoneNoneAD-008componentRFQX-CVS124-0016 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0017Shall be agreed between the supplier and the vehicle manufacturer.
Statement

Shall be agreed between the supplier and the vehicle manufacturer.

NoneNoneAD-008componentRFQX-CVS124-0017 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0018The implementation of the client and the server shall be compliant with ISO 14229-1 with the
Statement

The implementation of the client and the server shall be compliant with ISO 14229-1 with the

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0018 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0019All deviations and extensions shall be agreed with the applicable vehicle manufacturer and shall be documented.
Statement

All deviations and extensions shall be agreed with the applicable vehicle manufacturer and shall be documented.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0019 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0020Table 5 -Data identifiers used at ECU identification DID Description/ Name Application Boot loader Changing Def Non- Def Def Ext Prg Ext 0xF180 bootSoftwareIdentificationDataIdentifier ● ● ● ● ● SUPPLIER 0xF181 applicationSoftwareIdentificationDataIdentifier ● ● ● ● ● SUPPLIER 0xF182 applicationDataIdentificationDataIdentifier ● ● ● ● ● SUPPLIER 0xF186 ActiveDiagnosticSessionDataIdentifier ● ● ● ● ● INTERNAL 0xF187 vehicleManufacturerSparePartNumberDataIdentifier ● ○ ● ○ ○ SUPPLIER 0xF188 vehicleManufacturerECUSoftwareNumberDataIdent ifier ● ● ● ● ● SUPPLIER 0xF189 vehicleManufacturerECUSoftwareVersionNumberD ataIdentifier ● ● ● ● ● SUPPLIER 0xF18A systemSupplierIdentifierDataIdentifier ● ● - - - SUPPLIER 0xF18B ECUManufacturingDateDataIdentifier ● ● ● ● ● SUPPLIER 0xF18C ECUSerialNumberDataIdentifier ● ● ● ● ● SUPPLIER 0xF190 VINDataIdentifier ● ○ ● ● ● DIAG 0xF191 vehicleManufacturerECUHardwareNumberDataIde ntifier ● ● ● ● ● SUPPLIER 0xF192 systemSupplierECUHardwareNumberDataIdentifier ● ● - - - SUPPLIER 0xF193 systemSupplierECUHardwareVersionNumberDataI dentifier ● ● - - - SUPPLIER 0xF194 systemSupplierECUSoftwareNumberDataIdentifier ● ● - - - SUPPLIER
Statement

Table 5 -Data identifiers used at ECU identification DID Description/ Name Application Boot loader Changing Def Non- Def Def Ext Prg Ext 0xF180 bootSoftwareIdentificationDataIdentifier ● ● ● ● ● SUPPLIER 0xF181 applicationSoftwareIdentificationDataIdentifier ● ● ● ● ● SUPPLIER 0xF182 applicationDataIdentificationDataIdentifier ● ● ● ● ● SUPPLIER 0xF186 ActiveDiagnosticSessionDataIdentifier ● ● ● ● ● INTERNAL 0xF187 vehicleManufacturerSparePartNumberDataIdentifier ● ○ ● ○ ○ SUPPLIER 0xF188 vehicleManufacturerECUSoftwareNumberDataIdent ifier ● ● ● ● ● SUPPLIER 0xF189 vehicleManufacturerECUSoftwareVersionNumberD ataIdentifier ● ● ● ● ● SUPPLIER 0xF18A systemSupplierIdentifierDataIdentifier ● ● - - - SUPPLIER 0xF18B ECUManufacturingDateDataIdentifier ● ● ● ● ● SUPPLIER 0xF18C ECUSerialNumberDataIdentifier ● ● ● ● ● SUPPLIER 0xF190 VINDataIdentifier ● ○ ● ● ● DIAG 0xF191 vehicleManufacturerECUHardwareNumberDataIde ntifier ● ● ● ● ● SUPPLIER 0xF192 systemSupplierECUHardwareNumberDataIdentifier ● ● - - - SUPPLIER 0xF193 systemSupplierECUHardwareVersionNumberDataI dentifier ● ● - - - SUPPLIER 0xF194 systemSupplierECUSoftwareNumberDataIdentifier ● ● - - - SUPPLIER

NoneNoneNoneNoneRFQX-CVS124-0020 / 26hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0021SUPPLIER in the Changing column means that the DID can be changed only at the supplier premises for non-programmable ECUs.
Statement

SUPPLIER in the Changing column means that the DID can be changed only at the supplier premises for non-programmable ECUs. Data identifier details.

NoneNoneNoneNoneRFQX-CVS124-0021 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0022The format in the DID description in the following tables is given in ODX base data types.
Statement

The format in the DID description in the following tables is given in ODX base data types.

NoneNoneNoneNoneRFQX-CVS124-0022 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0023Table 6 – Description of DID 0xF180 bootSoftwareIdentificationDataIdentifier 0xF180 Name : bootSoftwareIdentificationDataIdentifier Byte
Statement

Table 6 – Description of DID 0xF180 bootSoftwareIdentificationDataIdentifier 0xF180 Name : bootSoftwareIdentificationDataIdentifier Byte

NoneNoneNoneNoneRFQX-CVS124-0023 / 18hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0024This DID shall be stored under flash memory module in flash memory.
Statement

This DID shall be stored under flash memory module in flash memory.

SSR-UPD-004Secure software update and flash readiness — Software Update / FlashingAD-006componentRFQX-CVS124-0024 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0025Table 7 – Description of DID 0xF181 applicationSoftwareIdentificationDataIdentifier 0xF181 Name : applicationSoftwareIdentificationDataIdentifier Byte Data #1 numberOfModules 1-Byte-A_UINT32 M 0x01 0x02 – 0xFF 0x01 #2 : #14 Application software identifier #1: : M 0x7E 0x7E 0x20 : : : #n – 12 : #n Application software identifier #m: : C 0x7E 0x7E 0x20
Statement

Table 7 – Description of DID 0xF181 applicationSoftwareIdentificationDataIdentifier 0xF181 Name : applicationSoftwareIdentificationDataIdentifier Byte Data #1 numberOfModules 1-Byte-A_UINT32 M 0x01 0x02 – 0xFF 0x01 #2 : #14 Application software identifier #1: : M 0x7E 0x7E 0x20 : : : #n – 12 : #n Application software identifier #m: : C 0x7E 0x7E 0x20

NoneNoneNoneNoneRFQX-CVS124-0025 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-00265.2.1.3 DID 0xF182 applicationDataIdentificationDataIdentifier
Statement

5.2.1.3 DID 0xF182 applicationDataIdentificationDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0026 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0027Table 8 – Description of DID 0xF182 applicationDataIdentificationDataIdentifier 0xF182 Name: applicationDataIdentificationDataIdentifier Byte No Description Format Cvt Byte Value Default Data #1 numberOfModules 1-Byte-A_UINT32 M 0x01 0x02 – 0xFF 0x01 #2 : #14 Application data module part number #1: : 13 Bytes- M : M 0x7E .
Statement

Table 8 – Description of DID 0xF182 applicationDataIdentificationDataIdentifier 0xF182 Name: applicationDataIdentificationDataIdentifier Byte No Description Format Cvt Byte Value Default Data #1 numberOfModules 1-Byte-A_UINT32 M 0x01 0x02 – 0xFF 0x01 #2 : #14 Application data module part number #1: : 13 Bytes- M : M 0x7E .

NoneNoneNoneNoneRFQX-CVS124-0027 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0028This DID shall be stored under dataset module stored in flash memory.
Statement

This DID shall be stored under dataset module stored in flash memory.

SSR-UPD-004Secure software update and flash readiness — Software Update / FlashingAD-006componentRFQX-CVS124-0028 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0029Table 9 – Description of DID 0xF186 ActiveDiagnosticSessionDataIdentifier 0xF186 Name: ActiveDiagnosticSessionDataIdentifier Byte No Description Format Cvt Byte Value Default Data #1 Diagnostic session type 1-Byte-A_UINT32 M 0x00 – 0xFF 0x01
Statement

Table 9 – Description of DID 0xF186 ActiveDiagnosticSessionDataIdentifier 0xF186 Name: ActiveDiagnosticSessionDataIdentifier Byte No Description Format Cvt Byte Value Default Data #1 Diagnostic session type 1-Byte-A_UINT32 M 0x00 – 0xFF 0x01

NoneNoneNoneNoneRFQX-CVS124-0029 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0030Table 10 – Description of DID 0xF187 vehicleManufacturerSparePartNumberDataIdentifier 0xF187 Name: vehicleManufacturerSparePartNumberDataIdentifier Byte No Description Format Cvt Byte Value Default Data #1 : #13 Vehicle manufacturer sparepart number : G, M : M 0x7E : 0x7E 0x20
Statement

Table 10 – Description of DID 0xF187 vehicleManufacturerSparePartNumberDataIdentifier 0xF187 Name: vehicleManufacturerSparePartNumberDataIdentifier Byte No Description Format Cvt Byte Value Default Data #1 : #13 Vehicle manufacturer sparepart number : G, M : M 0x7E : 0x7E 0x20

NoneNoneNoneNoneRFQX-CVS124-0030 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0031This DID shall be stored under dataset module stored in flash memory.
Statement

This DID shall be stored under dataset module stored in flash memory.

SSR-UPD-004Secure software update and flash readiness — Software Update / FlashingAD-006componentRFQX-CVS124-0031 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0032Table 11 – Description of DID 0xF188 vehicleManufacturerECUSoftwareNumberDataIdentifier 0xF188 Name: vehicleManufacturerECUSoftwareNumberDataIdentifier Byte Data #1 : #13 Vehicle manufacturer ECU (server) software number : M : M : 0x20
Statement

Table 11 – Description of DID 0xF188 vehicleManufacturerECUSoftwareNumberDataIdentifier 0xF188 Name: vehicleManufacturerECUSoftwareNumberDataIdentifier Byte Data #1 : #13 Vehicle manufacturer ECU (server) software number : M : M : 0x20

NoneNoneNoneNoneRFQX-CVS124-0032 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-00335.2.1.7 DID 0xF189 vehicleManufacturerECUSoftwareVersionNumberDataIdentifier
Statement

5.2.1.7 DID 0xF189 vehicleManufacturerECUSoftwareVersionNumberDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0033 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0034Table 12 – Description of DID 0xF189 vehicleManufacturerECUSoftwareVersionNumberDataIdentifier 0xF189 Name: vehicleManufacturerECUSoftwareVersionNumberDataIdentifier Byte Data
Statement

Table 12 – Description of DID 0xF189 vehicleManufacturerECUSoftwareVersionNumberDataIdentifier 0xF189 Name: vehicleManufacturerECUSoftwareVersionNumberDataIdentifier Byte Data

NoneNoneNoneNoneRFQX-CVS124-0034 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-00355.2.1.8 DID 0xF18A systemSupplierIdentifierDataIdentifier
Statement

5.2.1.8 DID 0xF18A systemSupplierIdentifierDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0035 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0036Table 13 – Description of DID 0xF18A systemSupplierIdentifierDataIdentifier 0xF18A Name: systemSupplierIdentifierDataIdentifier Byte No Description Format Cvt Byte Value Default Data To be specifie d by the Content and format to be specified by the supplier Should be M : M : 5.2.1.9 DID 0xF18B ECUManufacturingDateDataIdentifier
Statement

Table 13 – Description of DID 0xF18A systemSupplierIdentifierDataIdentifier 0xF18A Name: systemSupplierIdentifierDataIdentifier Byte No Description Format Cvt Byte Value Default Data To be specifie d by the Content and format to be specified by the supplier Should be M : M : 5.2.1.9 DID 0xF18B ECUManufacturingDateDataIdentifier

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0036 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0037Table 14 – Description of DID 0xF18B ECUManufacturingDateDataIdentifier 0xF18B Name: ECUManufacturingDateDataIdentifier Byte Data #1 .
Statement

Table 14 – Description of DID 0xF18B ECUManufacturingDateDataIdentifier 0xF18B Name: ECUManufacturingDateDataIdentifier Byte Data #1 .

NoneNoneNoneNoneRFQX-CVS124-0037 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0038Table 15 – Description of DID 0xF18C ECUSerialNumberDataIdentifier 0xF18C Name: ECUSerialNumberDataIdentifier Byte Data
Statement

Table 15 – Description of DID 0xF18C ECUSerialNumberDataIdentifier 0xF18C Name: ECUSerialNumberDataIdentifier Byte Data

NoneNoneNoneNoneRFQX-CVS124-0038 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0039Minimum length shall be 8 bytes and the assigned value shall be unique for every unit provided by one supplier per project.
Statement

Minimum length shall be 8 bytes and the assigned value shall be unique for every unit provided by one supplier per project.

NoneNoneAD-008componentRFQX-CVS124-0039 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0040Table 16 – Description of DID 0xF190 VINDataIdentifier 0xF190 Name: VINDataIdentifier Byte Data #1 : #17 VIN number : Byte #17 17-Bytes- M : M : 0x30 .
Statement

Table 16 – Description of DID 0xF190 VINDataIdentifier 0xF190 Name: VINDataIdentifier Byte Data #1 : #17 VIN number : Byte #17 17-Bytes- M : M : 0x30 .

NoneNoneNoneNoneRFQX-CVS124-0040 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0041This identifier is used for follow up and quality check at production and service and for legal reasons if applicable.
Statement

This identifier is used for follow up and quality check at production and service and for legal reasons if applicable.

NoneNoneNoneNoneRFQX-CVS124-0041 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0042Table 17 – Description of DID 0xF191 vehicleManufacturerECUHardwareNumberDataIdentifier 0xF191 Name: vehicleManufacturerECUHardwareNumberDataIdentifier Byte Data
Statement

Table 17 – Description of DID 0xF191 vehicleManufacturerECUHardwareNumberDataIdentifier 0xF191 Name: vehicleManufacturerECUHardwareNumberDataIdentifier Byte Data

NoneNoneNoneNoneRFQX-CVS124-0042 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0043This DID shall be stored under flash memory module in flash memory.
Statement

This DID shall be stored under flash memory module in flash memory.

SSR-UPD-004Secure software update and flash readiness — Software Update / FlashingAD-006componentRFQX-CVS124-0043 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0044Table 18 – Description of DID 0xF192 systemSupplierECUHardwareNumberDataIdentifier 0xF192 Name: systemSupplierECUHardwareNumberDataIdentifier Byte Data To be specified by the External Supplier 5.2.1.14 DID 0xF193 systemSupplierECUHardwareVersionNumberDataIdentifier
Statement

Table 18 – Description of DID 0xF192 systemSupplierECUHardwareNumberDataIdentifier 0xF192 Name: systemSupplierECUHardwareNumberDataIdentifier Byte Data To be specified by the External Supplier 5.2.1.14 DID 0xF193 systemSupplierECUHardwareVersionNumberDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0044 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0045Table 19 – Description of DID 0xF193 systemSupplierECUHardwareVersionNumberDataIdentifier 0xF193 Name: systemSupplierECUHardwareVersionNumberDataIdentifier Byte Data To be specified by the External Supplier 5.2.1.15 DID 0xF194 systemSupplierECUSoftwareNumberDataIdentifier
Statement

Table 19 – Description of DID 0xF193 systemSupplierECUHardwareVersionNumberDataIdentifier 0xF193 Name: systemSupplierECUHardwareVersionNumberDataIdentifier Byte Data To be specified by the External Supplier 5.2.1.15 DID 0xF194 systemSupplierECUSoftwareNumberDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0045 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0046Table 20 – Description of DID 0xF194 systemSupplierECUSoftwareNumberDataIdentifier 0xF194 Name: systemSupplierECUSoftwareNumberDataIdentifier Byte No Description Format Cvt Byte Value Data To be specified by the External Supplier
Statement

Table 20 – Description of DID 0xF194 systemSupplierECUSoftwareNumberDataIdentifier 0xF194 Name: systemSupplierECUSoftwareNumberDataIdentifier Byte No Description Format Cvt Byte Value Data To be specified by the External Supplier

NoneNoneNoneNoneRFQX-CVS124-0046 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0047DID 0xF197 systemNameOrEngineTypeDataIdentifier
Statement

DID 0xF197 systemNameOrEngineTypeDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0047 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0048Table 21 – Description of DID 0xF195 systemSupplierECUSoftwareVersionNumberDataIdentifier 0xF195 Name: systemSupplierECUSoftwareVersionNumberDataIdentifier Byte Data To be specified by the External supplier 5.2.1.17 DID 0xF196 exhaustRegulationOrTypeApprovalNumberDataIdentifier
Statement

Table 21 – Description of DID 0xF195 systemSupplierECUSoftwareVersionNumberDataIdentifier 0xF195 Name: systemSupplierECUSoftwareVersionNumberDataIdentifier Byte Data To be specified by the External supplier 5.2.1.17 DID 0xF196 exhaustRegulationOrTypeApprovalNumberDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0048 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0049Table 22 – Description of DID 0xF196 exhaustRegulationOrTypeApprovalNumberDataIdentifier 0xF196 Name: exhaustRegulationOrTypeApprovalNumberDataIdentifier Cvt: E Byte Data #1 : #10 Exhaust regulation or type approval 10-Bytes- M : M : 0000000 000 5.2.1.18 DID 0xF197 systemNameOrEngineTypeDataIdentifier
Statement

Table 22 – Description of DID 0xF196 exhaustRegulationOrTypeApprovalNumberDataIdentifier 0xF196 Name: exhaustRegulationOrTypeApprovalNumberDataIdentifier Cvt: E Byte Data #1 : #10 Exhaust regulation or type approval 10-Bytes- M : M : 0000000 000 5.2.1.18 DID 0xF197 systemNameOrEngineTypeDataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0049 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0050Table 23 – Description of DID 0xF197 systemNameOrEngineTypeDataIdentifier 0xF197 Name: systemNameOrEngineTypeDataIdentifier Byte Data #1 : #22 System name or engine type 6-to-22-Bytes- G, M : C : 0x20 .
Statement

Table 23 – Description of DID 0xF197 systemNameOrEngineTypeDataIdentifier 0xF197 Name: systemNameOrEngineTypeDataIdentifier Byte Data #1 : #22 System name or engine type 6-to-22-Bytes- G, M : C : 0x20 .

NoneNoneNoneNoneRFQX-CVS124-0050 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0051The format should follow the pattern: Appl: <Diag.family> <Diag.generation> Boot: <Diag.family> <Diag.generation>_BOOT
Statement

The format should follow the pattern: Appl: <Diag.family> <Diag.generation> Boot: <Diag.family> <Diag.generation>_BOOT

NoneNoneAD-008componentRFQX-CVS124-0051 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0052DID 0xF198 SoftwareItemSemanticDataIdentifiers
Statement

DID 0xF198 SoftwareItemSemanticDataIdentifiers

NoneNoneNoneNoneRFQX-CVS124-0052 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0053Table 25 – Description of DID 0xF199 SoftwareAssemblySemanticDataIdentifier s 0xF199 Name: SoftwareAssemblySemanticDataIdentifiers Byte Data #1 : #3 numberOfModules(m) 3-Byte- A_UINT32 M 0x000001 – 0xFFFFFF 01
Statement

Table 25 – Description of DID 0xF199 SoftwareAssemblySemanticDataIdentifier s 0xF199 Name: SoftwareAssemblySemanticDataIdentifiers Byte Data #1 : #3 numberOfModules(m) 3-Byte- A_UINT32 M 0x000001 – 0xFFFFFF 01

NoneNoneNoneNoneRFQX-CVS124-0053 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0054Table 26 – Description of DID 0xF19A HardwareSemanticDataIdentifiers 0xF19A Name: HardwareSemanticDataIdentifiers Byte Data #1 : #3 numberOfModules(m) 3-Byte- A_UINT32 M 0x000001 – 0xFFFFFF 01 #4 : #n+3 HardwareSemantic Data Identifier #1: : byte #n* A_ASCIISTR ING, zero M 0x00, 0x20 – 0x7E : : : : : : : HardwareSemantic Data Identifier #m: : byte #q* A_ASCIISTR ING, zero C 0x00, 0x20 – 0x7E *depends on the SoftwareItemSemanticDataIdentifiers length.
Statement

Table 26 – Description of DID 0xF19A HardwareSemanticDataIdentifiers 0xF19A Name: HardwareSemanticDataIdentifiers Byte Data #1 : #3 numberOfModules(m) 3-Byte- A_UINT32 M 0x000001 – 0xFFFFFF 01 #4 : #n+3 HardwareSemantic Data Identifier #1: : byte #n* A_ASCIISTR ING, zero M 0x00, 0x20 – 0x7E : : : : : : : HardwareSemantic Data Identifier #m: : byte #q* A_ASCIISTR ING, zero C 0x00, 0x20 – 0x7E *depends on the SoftwareItemSemanticDataIdentifiers length.

NoneNoneNoneNoneRFQX-CVS124-0054 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0055Table 27 – Description of DID 0xF19D ECUInstallationDateDataIdentifier 0xF19D Name: ECUInstallationDateDataIdentifier Byte Data
Statement

Table 27 – Description of DID 0xF19D ECUInstallationDateDataIdentifier 0xF19D Name: ECUInstallationDateDataIdentifier Byte Data

NoneNoneNoneNoneRFQX-CVS124-0055 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0056Table 28 – Description of DID 0xF1A5 vehicleMannufacturerECUHardwareWithoutBootNumber 0xF1A5 Name: vehicleManufacturerECUHardwareWithoutBootNumber Byte No: Description Format Cvt Byte Value Default Data #1 : #13 vehicleManufactur er ECU Hardware Number Byte #2 : 13-Byte- M : M : Project 5.2.1.24 DID 0xF1A6 engineNumber
Statement

Table 28 – Description of DID 0xF1A5 vehicleMannufacturerECUHardwareWithoutBootNumber 0xF1A5 Name: vehicleManufacturerECUHardwareWithoutBootNumber Byte No: Description Format Cvt Byte Value Default Data #1 : #13 vehicleManufactur er ECU Hardware Number Byte #2 : 13-Byte- M : M : Project 5.2.1.24 DID 0xF1A6 engineNumber

NoneNoneNoneNoneRFQX-CVS124-0056 / 18hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0057Table 29 – Description of DID 0xF1A6 engineNumber 0xF1A6 Name: engineNumber Byte Data #1 : #14 Engine number 14-Bytes- A_ASCIISTRING MM : 0x20 C = Applicable only for TRATON standalone engine solutions
Statement

Table 29 – Description of DID 0xF1A6 engineNumber 0xF1A6 Name: engineNumber Byte Data #1 : #14 Engine number 14-Bytes- A_ASCIISTRING MM : 0x20 C = Applicable only for TRATON standalone engine solutions

NoneNoneNoneNoneRFQX-CVS124-0057 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0058This DID shall contain a snapshot of the mandatory lifetime ECU-runtime operational data
Statement

This DID shall contain a snapshot of the mandatory lifetime ECU-runtime operational data

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS124-0058 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0059Table 30 – Description of DID 0xF1A9 Lifetime ECU-runtime at software update stamp 0xF1A9 Name: lifetimeECUruntimeAtSoftwareUpdateStamp Byte No Description Format Cvt Byte Value Default Data #1 : #4 Lifetime ECU- runtime at software update stamp Unit: s A_UINT32 M : M : 0xFFFFFFFF C = mandatory for TRATON Standalone and External engines 5.2.1.26 DID 0xF1AA Mileage at software update stamp
Statement

Table 30 – Description of DID 0xF1A9 Lifetime ECU-runtime at software update stamp 0xF1A9 Name: lifetimeECUruntimeAtSoftwareUpdateStamp Byte No Description Format Cvt Byte Value Default Data #1 : #4 Lifetime ECU- runtime at software update stamp Unit: s A_UINT32 M : M : 0xFFFFFFFF C = mandatory for TRATON Standalone and External engines 5.2.1.26 DID 0xF1AA Mileage at software update stamp

NoneNoneNoneNoneRFQX-CVS124-0059 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0060This DID shall report a snapshot of the mileage of the vehicle as received on CAN or other ECU-external source at the first reception of the signal with a good signal status after a software update.
Statement

This DID shall report a snapshot of the mileage of the vehicle as received on CAN or other ECU-external source at the first reception of the signal with a good signal status after a software update.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS124-0060 / 26hNot importedNo linked clarificationNo P1 linkboot/update trust; evidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0061Table 31 – Description of DID 0xF1AA Mileage at software update stamp ID Description 0xF1AA Name: mileageAtSoftwareUpdateStamp Byte No Description Format Cvt Byte Value Default Data #1 : #4 Mileage at software update stamp Unit: km Formula: 0,005*X 4-Bytes- A_UINT32 M : M : 0xFFFFFFFF C = Mandatory for ECUs that store Operational data and have access to Vehicle milage information.
Statement

Table 31 – Description of DID 0xF1AA Mileage at software update stamp ID Description 0xF1AA Name: mileageAtSoftwareUpdateStamp Byte No Description Format Cvt Byte Value Default Data #1 : #4 Mileage at software update stamp Unit: km Formula: 0,005*X 4-Bytes- A_UINT32 M : M : 0xFFFFFFFF C = Mandatory for ECUs that store Operational data and have access to Vehicle milage information.

NoneNoneNoneNoneRFQX-CVS124-0061 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0062The current date as received on CAN or other ECU-external source at first reception of a valid signal after a software update.
Statement

The current date as received on CAN or other ECU-external source at first reception of a valid signal after a software update.

NoneNoneNoneNoneRFQX-CVS124-0062 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; evidence completenessMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0063Table 32 – Description of DID 0xF1AB Date at software update stamp 0xF1AB Name: dateAtSoftwareUpdateStamp Byte Data
Statement

Table 32 – Description of DID 0xF1AB Date at software update stamp 0xF1AB Name: dateAtSoftwareUpdateStamp Byte Data

NoneNoneNoneNoneRFQX-CVS124-0063 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0064Table 33 – Description of DID 0xF1AD activeECUSoftwareDataIdentifier 0xF1AD Name: activeECUSoftwareDataIdentifier Byte Data #1 : #2 Active ECU Software 2-Bytes- A_BYTEFIEL D M : M Boot loader: 0x0000 Application Software: 0x0002 No information: 0xFFFF Not applicabl e 5.2.1.29 DID 0xF1AF NodeUID
Statement

Table 33 – Description of DID 0xF1AD activeECUSoftwareDataIdentifier 0xF1AD Name: activeECUSoftwareDataIdentifier Byte Data #1 : #2 Active ECU Software 2-Bytes- A_BYTEFIEL D M : M Boot loader: 0x0000 Application Software: 0x0002 No information: 0xFFFF Not applicabl e 5.2.1.29 DID 0xF1AF NodeUID

NoneNoneNoneNoneRFQX-CVS124-0064 / 18hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0065Table 34 – Description of DID 0xF1AF NodeUID 0xF1AF Name: NodeUID Byte Data #1 : #8 NodeUID 8-Bytes- A_BYTEFIELD M : M : 0x00 : 0x00
Statement

Table 34 – Description of DID 0xF1AF NodeUID 0xF1AF Name: NodeUID Byte Data #1 : #8 NodeUID 8-Bytes- A_BYTEFIELD M : M : 0x00 : 0x00

NoneNoneNoneNoneRFQX-CVS124-0065 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0066This identifier is used to link a ECU HW to its specialized security attributes.
Statement

This identifier is used to link a ECU HW to its specialized security attributes.

NoneNoneNoneNoneRFQX-CVS124-0066 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0067The value to be stored is fetched from TRATON backend system in production.
Statement

The value to be stored is fetched from TRATON backend system in production.

NoneNoneNoneNoneRFQX-CVS124-0067 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0068Table 35 – Description of DID 0xF1B9 RBACCIdentifierNumber 0xF1B9 Name: RBACCIdentifierNumber Byte Data #1 : #16 RBACC Identifier Number 16-Bytes- A_BYTEFIELD M : M : 0x00 : 0x00
Statement

Table 35 – Description of DID 0xF1B9 RBACCIdentifierNumber 0xF1B9 Name: RBACCIdentifierNumber Byte Data #1 : #16 RBACC Identifier Number 16-Bytes- A_BYTEFIELD M : M : 0x00 : 0x00

NoneNoneNoneNoneRFQX-CVS124-0068 / 18hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0069Information on RBACC can be found in CVS151.
Statement

Information on RBACC can be found in CVS151.

NoneNoneNoneNoneRFQX-CVS124-0069 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0070Table 36 – Description of DID 0xF1BA RBACCStructureVersion 0xF1BA Name: RBACCStructureVersion Byte Data #1 : #2 RBACC Structure Version 2-Bytes- A_BYTEFIELD M : M : 0x00 : 0x00
Statement

Table 36 – Description of DID 0xF1BA RBACCStructureVersion 0xF1BA Name: RBACCStructureVersion Byte Data #1 : #2 RBACC Structure Version 2-Bytes- A_BYTEFIELD M : M : 0x00 : 0x00

NoneNoneNoneNoneRFQX-CVS124-0070 / 18hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0071Information on RBACC can be found in CVS151.
Statement

Information on RBACC can be found in CVS151.

NoneNoneNoneNoneRFQX-CVS124-0071 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0072Table 37 – Description of DID 0xF1D1 RootCertificateIdentifier 0xF1D1 Name: RootCertificateIdentifier Byte Data
Statement

Table 37 – Description of DID 0xF1D1 RootCertificateIdentifier 0xF1D1 Name: RootCertificateIdentifier Byte Data

NoneNoneNoneNoneRFQX-CVS124-0072 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredCOMPLETE
RFQX-CVS124-0073Table 38 – Description of DID 0xF1E1 vehicleManufacturerECUBootSoftwareNumber 0xF1E1 Name: vehicleManufacturerECUBootSoftwareNumber Byte No: Description Format Cvt Byte Value Default Data #1 : #13 vehicleManufacturer ECUBootSoftwareNu mber Byte #2 : 13-Byte- G, M : M : Project
Statement

Table 38 – Description of DID 0xF1E1 vehicleManufacturerECUBootSoftwareNumber 0xF1E1 Name: vehicleManufacturerECUBootSoftwareNumber Byte No: Description Format Cvt Byte Value Default Data #1 : #13 vehicleManufacturer ECUBootSoftwareNu mber Byte #2 : 13-Byte- G, M : M : Project

NoneNoneNoneNoneRFQX-CVS124-0073 / 18hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0074This DID shall be stored under flash memory module in flash memory.
Statement

This DID shall be stored under flash memory module in flash memory.

SSR-UPD-004Secure software update and flash readiness — Software Update / FlashingAD-006componentRFQX-CVS124-0074 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0075A default diagnostic session shall be supported.
Statement

A default diagnostic session shall be supported.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS124-0075 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0076The default diagnostic session is referred to as “defaultSession”.
Statement

The default diagnostic session is referred to as “defaultSession”.

NoneNoneNoneNoneRFQX-CVS124-0076 / 26hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0077A non-default diagnostic session referred to as “extendedDiagnosticSession” shall be supported.
Statement

A non-default diagnostic session referred to as “extendedDiagnosticSession” shall be supported.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS124-0077 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0078Diagnostic sessions not defined in this document shall be agreed with the vehicle manufacturer.
Statement

Diagnostic sessions not defined in this document shall be agreed with the vehicle manufacturer.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS124-0078 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0079Of a marked service, an execution shall be implemented for the specified session as perTable 39.
Statement

Of a marked service, an execution shall be implemented for the specified session as perTable 39.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0079 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0080Table 39 – Diagnostic service support Service according to ISO 14229-1 Addressin g mode Application Boot loader
Statement

Table 39 – Diagnostic service support Service according to ISO 14229-1 Addressin g mode Application Boot loader

NoneNoneNoneNoneRFQX-CVS124-0080 / 26hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0081In Table 39, bootloader sessions should only be applicable to Software updateable ECUs.
Statement

In Table 39, bootloader sessions should only be applicable to Software updateable ECUs.

NoneNoneAD-001componentRFQX-CVS124-0081 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0082The mapping of RoutineControl service routines to sessions shall be discussed and agreed with the vehicle manufacturer.
Statement

The mapping of RoutineControl service routines to sessions shall be discussed and agreed with the vehicle manufacturer.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0082 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0083The server shall implement support for RBAC (Role Based Access Control) based on CVS151.
Statement

The server shall implement support for RBAC (Role Based Access Control) based on CVS151.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS124-0083 / 18hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0084CVS31 and CVS32 requirements preconditions per service shall be defined by the RBAC Configuration file in the ECU.
Statement

CVS31 and CVS32 requirements preconditions per service shall be defined by the RBAC Configuration file in the ECU.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS124-0084 / 18hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0085Diagnostics safe state is the following conditions that needs be satisfied to ensure vehicle is not in operation while performing certain diagnostics services.
Statement

Diagnostics safe state is the following conditions that needs be satisfied to ensure vehicle is not in operation while performing certain diagnostics services.

NoneNoneNoneNoneRFQX-CVS124-0085 / 26hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0086The conditions that shall be checked are • Vehicle speed ~ 0 • Engine speed ~ 0 (for vehicles with IC engines) • High Voltage system disengaged ( for vehicles with high Voltage battery system) • Gear Box in neutral • Parking brake engaged Diagnostics safe state is not intended for ensuring the vehicle safety rather its conditions that are checked to prevent executing Diagnostics services during vehicle operation
Statement

The conditions that shall be checked are • Vehicle speed ~ 0 • Engine speed ~ 0 (for vehicles with IC engines) • High Voltage system disengaged ( for vehicles with high Voltage battery system) • Gear Box in neutral • Parking brake engaged Diagnostics safe state is not intended for ensuring the vehicle safety rather its conditions that are checked to prevent executing Diagnostics services during vehicle operation

NoneNoneAD-008componentRFQX-CVS124-0086 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0087Diagnostics safe state shall be checked before executing the diagnostics services as per Table 40.
Statement

Diagnostics safe state shall be checked before executing the diagnostics services as per Table 40.

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0087 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0088The server implementation shall comply with the following state diagram and the following state
Statement

The server implementation shall comply with the following state diagram and the following state

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0088 / 32hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0089The session transitions stated below shall be possible to request both physically or functionally
Statement

The session transitions stated below shall be possible to request both physically or functionally

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0089 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0090.
Statement

. Default transition for the start of the software in the server after power-up/wake-up.

NoneNoneNoneNoneRFQX-CVS124-0090 / 4hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0091Description of the individual transitions as per Figure 2 -State Diagram is explained from
Statement

Description of the individual transitions as per Figure 2 -State Diagram is explained from

NoneNoneNoneNoneRFQX-CVS124-0091 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0092to
Statement

to

NoneNoneNoneNoneRFQX-CVS124-0092 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0093.
Statement

.

NoneNoneNoneNoneRFQX-CVS124-0093 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0094.
Statement

. The initialization routine is started.

NoneNoneNoneNoneRFQX-CVS124-0094 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0095.
Statement

. If a valid application software is available in the server (applValid P1 == true) and there is no programming request (progRequest P2 == false), the server changes to the DefaultSession in the application software.

NoneNoneNoneNoneRFQX-CVS124-0095 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0096.
Statement

. If a programming request is active (progRequest P2 == true), the server activates the programming session in the bootloader module.

NoneNoneNoneNoneRFQX-CVS124-0096 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0097.
Statement

. If there is no programming request (progRequest P2 == false) and no valid application software is available (applValid P1 == false), the server changes to the DefaultSession in the boot loader.

NoneNoneNoneNoneRFQX-CVS124-0097 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0098.
Statement

. If the client posts a physical service request to change session from DefaultSession to ProgrammingSession in the application software, the server sends a negative response with NRC 0x7E (sub-functionNotSupportedInActiveSession). Applies to non-reprogrammable servers: If the client requests a change to the ProgrammingSession in the DefaultSession in the application software, the server

NoneNoneNoneNoneRFQX-CVS124-0098 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0099.
Statement

. If the client requests a change to the ExtendedSession in the DefaultSession in the application software, the session is changed.

NoneNoneNoneNoneRFQX-CVS124-0099 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0100.
Statement

. If the client does not send any requests during a time period defined by S3Server in the ExtendedSession in the application software, the server falls back into the DefaultSession in the application software.

NoneNoneNoneNoneRFQX-CVS124-0100 / 4hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0101.
Statement

. If the client requests a change to the DefaultSession in the ExtendedSession in the application software, the session is changed.

NoneNoneNoneNoneRFQX-CVS124-0101 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0102.
Statement

. If the client requests a change to the ProgrammingSession in the ExtendedSession in the application software, the server sets the progRequest flag to "true", so that after restarting it can be seen, that changing to the ProgrammingSession has been requested. If the SPRMIB was not set a positive response is sent from the application before the transition to Bootloader. The request is only sent physically.

NoneNoneNoneNoneRFQX-CVS124-0102 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0103.
Statement

. If the client requests a change to the ExtendedSession in ExtendedSession in the application software, the server accepts the request.

NoneNoneNoneNoneRFQX-CVS124-0103 / 4hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-01042.
Statement

2.

NoneNoneNoneNoneRFQX-CVS124-0104 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0105.
Statement

. If the client requests an ECUReset (0x11) with the sub-function HardReset (0x01) in the boot loader ExtendedSession or ProgrammingSession, the reset is performed.

NoneNoneNoneNoneRFQX-CVS124-0105 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0106.
Statement

. If the client requests a change to the DefaultSession in the boot loader ExtendedSession or ProgrammingSession, the reset is performed.

NoneNoneNoneNoneRFQX-CVS124-0106 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0107.
Statement

. If the client does not send any requests during a time period defined by S3Server in a Non-DefaultSession in the boot loader, the server performs a reset.

NoneNoneNoneNoneRFQX-CVS124-0107 / 4hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0108.
Statement

. If the client requests a change to the DefaultSession in the DefaultSession in the boot loader, the server accepts the request.

NoneNoneNoneNoneRFQX-CVS124-0108 / 4hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0109.
Statement

. If the client requests an ECUReset (0x11) with the sub-function HardReset (0x01) in the DefaultSession in the boot loader, the reset is performed.

NoneNoneNoneNoneRFQX-CVS124-0109 / 4hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0110.
Statement

. If the client requests the ExtendedSession in the DefaultSession in the boot loader, the session is changed.

NoneNoneNoneNoneRFQX-CVS124-0110 / 4hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0111.
Statement

. If the client posts a physical service request to change session from DefaultSession to ProgrammingSession in the boot loader, the server sends a negative response with NRC 0x7E (sub-functionNotSupportedInActiveSession).

NoneNoneNoneNoneRFQX-CVS124-0111 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0112.
Statement

. If the client requests the ExtendedSession in the ExtendedSession in the boot loader, the server accepts the request.

NoneNoneNoneNoneRFQX-CVS124-0112 / 4hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0113.
Statement

. If the client requests the ProgrammingSession in the ExtendedSession in the boot loader, the session is changed regardless of whether the programming preconditions are fulfilled or not. The request is only sent physically.

NoneNoneNoneNoneRFQX-CVS124-0113 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0114.
Statement

. If the client requests a change to the ProgrammingSession in ProgrammingSession in the boot loader, the server accepts the request. The request is only sent physically.

NoneNoneNoneNoneRFQX-CVS124-0114 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0115.
Statement

. If the client posts a physical service request to change session from ProgrammingSession to ExtendedSession in the boot loader, the server sends a negative response with NRC 0x7E (sub-functionNotSupportedInActiveSession).

NoneNoneNoneNoneRFQX-CVS124-0115 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0116.
Statement

. If the client requests the DefaultSession in the DefaultSession in the application, the server accepts the request.

NoneNoneNoneNoneRFQX-CVS124-0116 / 4hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-011712.
Statement

12.

NoneNoneNoneNoneRFQX-CVS124-0117 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0118.
Statement

. Applies to terminal 15 powered servers: If the client requests an ECUReset with the sub-function KeyOffOnReset (0x02) in the ExtendedSession in the application software, a restart is performed.

NoneNoneNoneNoneRFQX-CVS124-0118 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0119.
Statement

. Applies to terminal 15 powered servers: If the client requests an ECUReset with the sub-function KeyOffOnReset (0x02) in the DefaultSession in the application software, a restart is performed.

NoneNoneNoneNoneRFQX-CVS124-0119 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0120.
Statement

. If a server exchanges diagnostic messages with the client within the ExtendedSession and state terminal 15 ON, the following step is performed if there is a change to terminal 15 OFF and response in progress was finished: Return to DefaultSession after an already started response message has been completely sent to the client.

NoneNoneNoneNoneRFQX-CVS124-0120 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0121.
Statement

. If there is a state change from terminal 15 ON to terminal 15 OFF while a server exchanges diagnostic messages with the client within the DefaultSession, the server stops the communications with the client after sending the complete response to the last request.

NoneNoneNoneNoneRFQX-CVS124-0121 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0122.
Statement

. Applies to terminal 30 powered servers: If the client requests an ECUReset with the sub-function KeyOffOnReset (0x02) in the ExtendedSession in the application software, a change to the DefaultSession is performed.

NoneNoneNoneNoneRFQX-CVS124-0122 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0123.
Statement

. Applies to terminal 30 powered servers: If the client requests an ECUReset with the sub-function KeyOffOnReset (0x02) in the DefaultSession in the application software, the server accepts the request and remains in the DefaultSession.

NoneNoneNoneNoneRFQX-CVS124-0123 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0124.
Statement

. If the client requests an ECUReset (0x11) with the sub-function HardReset (0x01) in a DefaultSession in the application software, a restart is performed.

NoneNoneNoneNoneRFQX-CVS124-0124 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0125.
Statement

. If the client requests an ECUReset (0x11) with the sub-function HardReset (0x01) in the ExtendedSession in the application software a restart is performed.

NoneNoneNoneNoneRFQX-CVS124-0125 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0126.
Statement

. If the client requests an ECUReset (0x11) with the sub-function KeyOffOnReset (0x02) in the DefaultSession in the boot loader, the reset is performed.

NoneNoneNoneNoneRFQX-CVS124-0126 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; certificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0127.
Statement

. If the client requests an ECUReset (0x11) with the sub-function KeyOffOnReset (0x02) in a Non-DefaultSession in the boot loader, the reset is performed.

NoneNoneNoneNoneRFQX-CVS124-0127 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; certificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-012824.
Statement

24.

NoneNoneNoneNoneRFQX-CVS124-0128 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0129Project specific DID shall be added to ranges defined as system supplier specific in ISO 14229
Statement

Project specific DID shall be added to ranges defined as system supplier specific in ISO 14229

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0129 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0130Table 41 lists reserved ECU DIDs/DID ranges which are not used for identification and which shall only be implemented in agreement with the vehicle manufacturer.
Statement

Table 41 lists reserved ECU DIDs/DID ranges which are not used for identification and which shall only be implemented in agreement with the vehicle manufacturer.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS124-0130 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0131Table 41 – Data identifier (DID) ranges Byte value Description 0x0611-0x0620 Reserved for collective data identifiers 0xB000 – 0xB1FF Reserved for TRATON 0xCF00 – 0xCFFF TRATON data field identifiers 0xF010 disableDiagnosticClient 5.4.1 Integrity Validation Data DIDs (IVD-DIDs) Refer to VehSec_IVD_ECU for detailed requirements on Integrity Validation Data (IVD) for ECUs which need to be compliant to UNECE R156 regulation.
Statement

Table 41 – Data identifier (DID) ranges Byte value Description 0x0611-0x0620 Reserved for collective data identifiers 0xB000 – 0xB1FF Reserved for TRATON 0xCF00 – 0xCFFF TRATON data field identifiers 0xF010 disableDiagnosticClient 5.4.1 Integrity Validation Data DIDs (IVD-DIDs) Refer to VehSec_IVD_ECU for detailed requirements on Integrity Validation Data (IVD) for ECUs which need to be compliant to UNECE R156 regulation.

NoneNoneNoneNoneRFQX-CVS124-0131 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; diagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0132These ECUs shall implement the following DIDs according to Table 42.
Statement

These ECUs shall implement the following DIDs according to Table 42.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0132 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0133The SPRMIB shall be supported for services as specified in (ISO 14229-1).
Statement

The SPRMIB shall be supported for services as specified in (ISO 14229-1).

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0133 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0134Negative response codes specified in ISO 14229-1 Annex A.1 shall only be supported if explicitly specified by this specification or its normative references.
Statement

Negative response codes specified in ISO 14229-1 Annex A.1 shall only be supported if explicitly specified by this specification or its normative references.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0134 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0135Negative response code 0x22, conditionsNotCorrect , shall be used if a service request is denied due to insufficient rights according to the RBACC check.
Statement

Negative response code 0x22, conditionsNotCorrect , shall be used if a service request is denied due to insufficient rights according to the RBACC check.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS124-0135 / 18hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-01365.5.1.1.1 Request parameter diagnosticSessionType
Statement

5.5.1.1.1 Request parameter diagnosticSessionType

NoneNoneNoneNoneRFQX-CVS124-0136 / 26hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0137A DiagnosticSessionControl service request with parameter diagnosticSessionType set to ProgrammingSession shall be processed only if normal communication is currently switched off as a result of a previous call to the Communication Control service.
Statement

A DiagnosticSessionControl service request with parameter diagnosticSessionType set to ProgrammingSession shall be processed only if normal communication is currently switched off as a result of a previous call to the Communication Control service.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS124-0137 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0138The application shall respond with NRC 0x22 (conditionsNotCorrect) if communication has not been switched off.
Statement

The application shall respond with NRC 0x22 (conditionsNotCorrect) if communication has not been switched off.

NoneNoneAD-001componentRFQX-CVS124-0138 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0139Table 43 – Service 0x10 request parameter diagnosticSessionType description Hex (bit 6-0) Description Cvt 0x01 defaultSession M 0x02 ProgrammingSession M 0x03 extendedDiagnosticSession M
Statement

Table 43 – Service 0x10 request parameter diagnosticSessionType description Hex (bit 6-0) Description Cvt 0x01 defaultSession M 0x02 ProgrammingSession M 0x03 extendedDiagnosticSession M

NoneNoneNoneNoneRFQX-CVS124-0139 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0140Following an accepted request to switch to the ProgrammingSession, the application shall make all preparations to guarantee trouble-free programming operation.
Statement

Following an accepted request to switch to the ProgrammingSession, the application shall make all preparations to guarantee trouble-free programming operation.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS124-0140 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0141In this process, it shall end all routines and functions that influence programming and ensure that the server checked for safe state conditions at minimal.
Statement

In this process, it shall end all routines and functions that influence programming and ensure that the server checked for safe state conditions at minimal.

NoneNoneAD-002componentRFQX-CVS124-0141 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0142Before switching to programming session, the server shall ensure the applicable conditions as per Table 76 - Programming preconditions is checked to ensure the vehicle is in safe condition.
Statement

Before switching to programming session, the server shall ensure the applicable conditions as per Table 76 - Programming preconditions is checked to ensure the vehicle is in safe condition.

SSR-UPD-003Secure software update and flash readiness — Software Update / FlashingAD-002componentRFQX-CVS124-0142 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0143Its upto the ECU to include the conditions that are relevant for that particular ECU, but needs to be agreed with Vehicle Manufacturer.
Statement

Its upto the ECU to include the conditions that are relevant for that particular ECU, but needs to be agreed with Vehicle Manufacturer.

NoneNoneNoneNoneRFQX-CVS124-0143 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0144Positive response
Statement

Positive response

NoneNoneNoneNoneRFQX-CVS124-0144 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0145Positive response shall be sent before the actual switch in case switching to Programming session.
Statement

Positive response shall be sent before the actual switch in case switching to Programming session.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0145 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0146Response parameter diagnosticSessionType shall be as per ISO 14229-1.
Statement

Response parameter diagnosticSessionType shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0146 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0147Response parameter sessionParameterRecord shall be as per ISO 14229-1.
Statement

Response parameter sessionParameterRecord shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0147 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-01485.5.2 ECUReset (0x11) service
Statement

5.5.2 ECUReset (0x11) service

NoneNoneNoneNoneRFQX-CVS124-0148 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0149An ECUReset shall not be executed if the vehicle safety can be compromised.
Statement

An ECUReset shall not be executed if the vehicle safety can be compromised.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS124-0149 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0150ECU shall execute the reset only after sending a positive response to the ECU reset service
Statement

ECU shall execute the reset only after sending a positive response to the ECU reset service

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0150 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0151After a final positive response has been sent for ECUReset the server is not allowed to respond to any diagnostic service requests (except ECU identification) until it has restarted and been re- initialized.
Statement

After a final positive response has been sent for ECUReset the server is not allowed to respond to any diagnostic service requests (except ECU identification) until it has restarted and been re- initialized.

NoneNoneNoneNoneRFQX-CVS124-0151 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0152The server shall be available for ECU identification within one second after sending positive response message to an ECUReset request.
Statement

The server shall be available for ECU identification within one second after sending positive response message to an ECUReset request.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS124-0152 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0153After ECU reset, ECU shall be restarted and re-initialized within 2sec.
Statement

After ECU reset, ECU shall be restarted and re-initialized within 2sec.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS124-0153 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0154The maximum time it takes from the positive response is sent from the server until it responds to new requests shall be agreed with vehicle manufacturer and documented.
Statement

The maximum time it takes from the positive response is sent from the server until it responds to new requests shall be agreed with vehicle manufacturer and documented.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0154 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-01555.5.2.1.1 Request parameter resetType
Statement

5.5.2.1.1 Request parameter resetType

NoneNoneNoneNoneRFQX-CVS124-0155 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0156Table 44 – Service 0x11 request parameter resetType description Hex (bit 6-0) Description Cvt 0x01 hardReset M 0x02 keyOffOnReset C C = If the server is connected to the ignition key
Statement

Table 44 – Service 0x11 request parameter resetType description Hex (bit 6-0) Description Cvt 0x01 hardReset M 0x02 keyOffOnReset C C = If the server is connected to the ignition key

NoneNoneNoneNoneRFQX-CVS124-0156 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0157The ECUReset service with requestParameter value 0x01 (hardReset) shall simulate the power-on / start-up sequence performed after a server has been previously disconnected from its power supply (i.e.
Statement

The ECUReset service with requestParameter value 0x01 (hardReset) shall simulate the power-on / start-up sequence performed after a server has been previously disconnected from its power supply (i.e.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0157 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0158the disconnect from the battery shall not be simulated.
Statement

the disconnect from the battery shall not be simulated.

NoneNoneAD-008componentRFQX-CVS124-0158 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0159The implementation of hardReset shall first ensure that data corruption will not occur.
Statement

The implementation of hardReset shall first ensure that data corruption will not occur.

NoneNoneAD-008componentRFQX-CVS124-0159 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0160The ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall simulate the turning of the ignition key off and back on and shall ensure that the values of non-volatile memory locations are preserved and the volatile memory will be initialized.
Statement

The ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall simulate the turning of the ignition key off and back on and shall ensure that the values of non-volatile memory locations are preserved and the volatile memory will be initialized.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS124-0160 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0161The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that every server task is finished prior sending a positive response.
Statement

The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that every server task is finished prior sending a positive response.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0161 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0162The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that the volatile memory buffered data is stored into non volatile memory prior sending a positive response.
Statement

The implementation of ECUReset service with requestParameter value 0x02 (keyOffOnReset) shall ensure that the volatile memory buffered data is stored into non volatile memory prior sending a positive response.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0162 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0163The server shall send an ECUReset positive response message after the server tasks above are finished but before the server performs the actual resetType.
Statement

The server shall send an ECUReset positive response message after the server tasks above are finished but before the server performs the actual resetType.

NoneNoneAD-002componentRFQX-CVS124-0163 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0164Table 45 – Service 0x11 positive response parameter description 1 ECUReset Response SID M 2 resetType M
Statement

Table 45 – Service 0x11 positive response parameter description 1 ECUReset Response SID M 2 resetType M

NoneNoneNoneNoneRFQX-CVS124-0164 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0165Response parameter resetType shall be as per ISO 14229-1.
Statement

Response parameter resetType shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0165 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-01665.5.2.3.1 Supported negative response codes
Statement

5.5.2.3.1 Supported negative response codes

NoneNoneNoneNoneRFQX-CVS124-0166 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0167Table 46 – Service 0x11 negative response codes NRC Description and scenario 0x12 sub-functionNotSupported Refer to ISO 14229-1 for scenario.
Statement

Table 46 – Service 0x11 negative response codes NRC Description and scenario 0x12 sub-functionNotSupported Refer to ISO 14229-1 for scenario.

NoneNoneNoneNoneRFQX-CVS124-0167 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0168Servers involved in engine start shall not process CommunicationControl service requests until 2 seconds after terminal 15 goes active.
Statement

Servers involved in engine start shall not process CommunicationControl service requests until 2 seconds after terminal 15 goes active.

SSR-COM-006Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-001componentRFQX-CVS124-0168 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0169If a request is received before this time has passed the server shall respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) (and process the request and send a final response when 2 seconds have passed) or NRC 0x22 (conditionsNotCorrect).
Statement

If a request is received before this time has passed the server shall respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) (and process the request and send a final response when 2 seconds have passed) or NRC 0x22 (conditionsNotCorrect).

NoneNoneAD-002componentRFQX-CVS124-0169 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0170This requirement mitigates DOS (Denial Of Service) attacks
Statement

This requirement mitigates DOS (Denial Of Service) attacks

NoneNoneNoneNoneRFQX-CVS124-0170 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0171When receiving CommunicationControl service request, Gateway server applications shall ensure quieting down of network to ECUs without diagnostic server which are present in their sub-buses
Statement

When receiving CommunicationControl service request, Gateway server applications shall ensure quieting down of network to ECUs without diagnostic server which are present in their sub-buses

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS124-0171 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0172Safety conditions are project specific and shall be checked before accepting a request to disable communication.
Statement

Safety conditions are project specific and shall be checked before accepting a request to disable communication.

SSR-COM-002Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-008componentRFQX-CVS124-0172 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0173After receiving CommunicationControl service request, ECUs could still keep sending some networks messages/signals to keep a healthy vehicle system.
Statement

After receiving CommunicationControl service request, ECUs could still keep sending some networks messages/signals to keep a healthy vehicle system.

NoneNoneNoneNoneRFQX-CVS124-0173 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0174Negative response
Statement

Negative response

NoneNoneNoneNoneRFQX-CVS124-0174 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0175Communication control service should not only be used to improve the bandwidth situation during flashing /parametrisation but also for inhibiting systems in vehicle (like engine start) to ensure safety.
Statement

Communication control service should not only be used to improve the bandwidth situation during flashing /parametrisation but also for inhibiting systems in vehicle (like engine start) to ensure safety.

NoneNoneAD-001componentRFQX-CVS124-0175 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0176Table 47 – Service 0x28 request parameter description 1 CommunicationControl Request SID M 2 controlType M 3 communicationType M 5.5.3.1.1 Request parameter controlType
Statement

Table 47 – Service 0x28 request parameter description 1 CommunicationControl Request SID M 2 controlType M 3 communicationType M 5.5.3.1.1 Request parameter controlType

NoneNoneNoneNoneRFQX-CVS124-0176 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0177Table 48 – Service 0x28 request parameter controlType description Hex (bit 6-0) Description Cvt 0x00 enableRxAndTx M 0x01 enableRxAndDisableTx M 0x40 – 0x5F vehicleManufacturerSpecific U 5.5.3.1.2 Request parameter communicationType
Statement

Table 48 – Service 0x28 request parameter controlType description Hex (bit 6-0) Description Cvt 0x00 enableRxAndTx M 0x01 enableRxAndDisableTx M 0x40 – 0x5F vehicleManufacturerSpecific U 5.5.3.1.2 Request parameter communicationType

NoneNoneNoneNoneRFQX-CVS124-0177 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0178Table 49 – Service 0x28 request parameter communicationType description Bits Value (Hex) Description Cvt 0 -1 1 normalCommunicationMessages M 4 – 7 0 Disable / Enable specified communicationType M 5.5.3.2 Positive response
Statement

Table 49 – Service 0x28 request parameter communicationType description Bits Value (Hex) Description Cvt 0 -1 1 normalCommunicationMessages M 4 – 7 0 Disable / Enable specified communicationType M 5.5.3.2 Positive response

NoneNoneNoneNoneRFQX-CVS124-0178 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-01795.5.3.3 Negative response
Statement

5.5.3.3 Negative response

NoneNoneNoneNoneRFQX-CVS124-0179 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0180If the parameter suppressPosRespMsgIndicationBit = true in a functionally addressed request message, the service request shall not influence any ongoing physically addressed service
Statement

If the parameter suppressPosRespMsgIndicationBit = true in a functionally addressed request message, the service request shall not influence any ongoing physically addressed service

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0180 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0181A functionally addressed TesterPresent may arrive at any time during another request.
Statement

A functionally addressed TesterPresent may arrive at any time during another request.

NoneNoneNoneNoneRFQX-CVS124-0181 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0182Request format and parameter shall be as per ISO 14229-1.
Statement

Request format and parameter shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0182 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-01835.5.4.4 Negative response
Statement

5.5.4.4 Negative response

NoneNoneNoneNoneRFQX-CVS124-0183 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-01845.5.5 ControlDTCSetting (0x85) service
Statement

5.5.5 ControlDTCSetting (0x85) service

NoneNoneNoneNoneRFQX-CVS124-0184 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0185Servers shall reject a ControlDTCSetting service request (DTC setting type = off) with NRC 0x22 (conditionsNotCorrect) if programming preconditions are not satisfied.
Statement

Servers shall reject a ControlDTCSetting service request (DTC setting type = off) with NRC 0x22 (conditionsNotCorrect) if programming preconditions are not satisfied.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS124-0185 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0186The execution of this service in the application shall only impact the DTC setting - diagnostic tests for safety and degradations shall not be impacted (shall work as normal).
Statement

The execution of this service in the application shall only impact the DTC setting - diagnostic tests for safety and degradations shall not be impacted (shall work as normal).

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS124-0186 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0187Refer to ISO 14229-1 for request format.
Statement

Refer to ISO 14229-1 for request format.

NoneNoneNoneNoneRFQX-CVS124-0187 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0188Refer to ISO 14229-1 for request parameter DTCSettingType.
Statement

Refer to ISO 14229-1 for request parameter DTCSettingType.

NoneNoneNoneNoneRFQX-CVS124-0188 / 16hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0189Request parameter DTCSettingControlOptionRecord
Statement

Request parameter DTCSettingControlOptionRecord

NoneNoneNoneNoneRFQX-CVS124-0189 / 16hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0190Refer to ISO 14229-1 for positive response format and parameter.
Statement

Refer to ISO 14229-1 for positive response format and parameter.

NoneNoneNoneNoneRFQX-CVS124-0190 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0191Refer to ISO 14229-1 for negative response format and codes.
Statement

Refer to ISO 14229-1 for negative response format and codes.

NoneNoneNoneNoneRFQX-CVS124-0191 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0192The server shall be able to switch baud rate within one second.
Statement

The server shall be able to switch baud rate within one second.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0192 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0193The boot loader shall inherit the selected baud rate if the LinkControl service request was received when the server was executing in the application.
Statement

The boot loader shall inherit the selected baud rate if the LinkControl service request was received when the server was executing in the application.

SSR-BOOT-005Bootloader and Application State Handling — Bootloader and Application State HandlingAD-001componentRFQX-CVS124-0193 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0194Link Control (0x87) service is only applicable to CAN & CAN FD.
Statement

Link Control (0x87) service is only applicable to CAN & CAN FD.

NoneNoneNoneNoneRFQX-CVS124-0194 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0195Positive response shall be sent before the actual switch of the baud-rate takes place.
Statement

Positive response shall be sent before the actual switch of the baud-rate takes place.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0195 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0196Request
Statement

Request

NoneNoneNoneNoneRFQX-CVS124-0196 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0197Table 50 – Service 0x87 request parameter linkControlType description Byte Value Description Cvt 0x01 verifyModeTransitionWithFixedParameter M 0x03 transitionMode M 0x40-0x5F vehicleManufacturerSpecific U 5.5.6.2.1 Request parameter linkControlModeIdentifier
Statement

Table 50 – Service 0x87 request parameter linkControlType description Byte Value Description Cvt 0x01 verifyModeTransitionWithFixedParameter M 0x03 transitionMode M 0x40-0x5F vehicleManufacturerSpecific U 5.5.6.2.1 Request parameter linkControlModeIdentifier

NoneNoneNoneNoneRFQX-CVS124-0197 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0198Table 51 – Service 0x87 request parameter linkControlModeIdentifier description Byte Value Description Cvt 0x11 CAN250000Baud C 0x12 CAN500000Baud C 0x13 CAN1000000Baud C C = Baud rates shall be defined by the Project representative.
Statement

Table 51 – Service 0x87 request parameter linkControlModeIdentifier description Byte Value Description Cvt 0x11 CAN250000Baud C 0x12 CAN500000Baud C 0x13 CAN1000000Baud C C = Baud rates shall be defined by the Project representative.

SSR-COM-006Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-001componentRFQX-CVS124-0198 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-01995.5.6.4 Negative Response
Statement

5.5.6.4 Negative Response

NoneNoneNoneNoneRFQX-CVS124-0199 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02005.5.7 ReadDataByIdentifier (0x22) service 5.5.7.1 Request
Statement

5.5.7 ReadDataByIdentifier (0x22) service 5.5.7.1 Request

NoneNoneNoneNoneRFQX-CVS124-0200 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0201If ECU supports request containing more than one data identifier it shall be documented (like in CDD, ODX etc).
Statement

If ECU supports request containing more than one data identifier it shall be documented (like in CDD, ODX etc).

SSR-DIAG-005Diagnostic Services — Diagnostic ServicesAD-006componentRFQX-CVS124-0201 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0202DataIdentifier parameter definition shall be as per ISO 14229-1.
Statement

DataIdentifier parameter definition shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0202 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0203The data identifier ranges specified in Table 41 shall be followed.
Statement

The data identifier ranges specified in Table 41 shall be followed.

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0203 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0204Positive response
Statement

Positive response

NoneNoneNoneNoneRFQX-CVS124-0204 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02055.5.7.3 Negative response
Statement

5.5.7.3 Negative response

NoneNoneNoneNoneRFQX-CVS124-0205 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02065.5.8 WriteDataByIdentifier (0x2E) service
Statement

5.5.8 WriteDataByIdentifier (0x2E) service

NoneNoneNoneNoneRFQX-CVS124-0206 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0207The sequence of writing data records with service 0x2E WriteDataByIdentifier shall be independent of any specific order
Statement

The sequence of writing data records with service 0x2E WriteDataByIdentifier shall be independent of any specific order

SSR-DIAG-006Diagnostic Services — Diagnostic ServicesAD-001componentRFQX-CVS124-0207 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0208The range of a requested dataRecord value has to be checked by the server if the DID is safety relevant.
Statement

The range of a requested dataRecord value has to be checked by the server if the DID is safety relevant.

NoneNoneNoneNoneRFQX-CVS124-0208 / 16hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0209All changed data shall be valid and stored into non-volatile memory at the latest after an ECU Reset(0x11) subfunction 0x02 requested from client.
Statement

All changed data shall be valid and stored into non-volatile memory at the latest after an ECU Reset(0x11) subfunction 0x02 requested from client.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS124-0209 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0210If it is necessary to force an explicit transfer of buffered data into non-volatile memory then this shall be supported both with ECU-Reset Service subfunction 0x02 and ignition (IGN) key Off/On (power cycle).
Statement

If it is necessary to force an explicit transfer of buffered data into non-volatile memory then this shall be supported both with ECU-Reset Service subfunction 0x02 and ignition (IGN) key Off/On (power cycle).

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS124-0210 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0211Additional client requests which start copying RAM buffer data into non-volatile memory are not allowed.
Statement

Additional client requests which start copying RAM buffer data into non-volatile memory are not allowed.

NoneNoneNoneNoneRFQX-CVS124-0211 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0212If this action is necessary then it shall be integrated implicitly into ECU Reset (0x11) Service subfunction 0x02.
Statement

If this action is necessary then it shall be integrated implicitly into ECU Reset (0x11) Service subfunction 0x02.

NoneNoneAD-001componentRFQX-CVS124-0212 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0213Request format and parameter shall be as per ISO 14229-1.
Statement

Request format and parameter shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0213 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02145.5.9 ClearDiagnosticInformation (0x14) service 5.5.9.1 Request
Statement

5.5.9 ClearDiagnosticInformation (0x14) service 5.5.9.1 Request

NoneNoneNoneNoneRFQX-CVS124-0214 / 26hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-02155.5.9.1.1 Request parameter groupOfDTC
Statement

5.5.9.1.1 Request parameter groupOfDTC

NoneNoneNoneNoneRFQX-CVS124-0215 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0216groupOfDTC parameter definition shall be as per ISO 14229-1.
Statement

groupOfDTC parameter definition shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0216 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02175.5.9.3 Negative response
Statement

5.5.9.3 Negative response

NoneNoneNoneNoneRFQX-CVS124-0217 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02185.5.10 ReadDTCInformation (0x19) service 5.5.10.1 Request
Statement

5.5.10 ReadDTCInformation (0x19) service 5.5.10.1 Request

NoneNoneNoneNoneRFQX-CVS124-0218 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-02195.5.10.1.1 Request parameter reportType
Statement

5.5.10.1.1 Request parameter reportType

NoneNoneNoneNoneRFQX-CVS124-0219 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0220Table 52 – Service 0x19 request parameter reportType description 0x01 reportNumberOfDTCByStatusMask M 0x02 reportDTCByStatusMask M 0x03 reportDTCSnapshotIdentification M 0x04 reportDTCSnapshotRecordByDTCNumber M 0x06 reportDTCExtendedDataRecordByDTCNumber M 0x0F reportMirrorMemoryDTCByStatusMask U
Statement

Table 52 – Service 0x19 request parameter reportType description 0x01 reportNumberOfDTCByStatusMask M 0x02 reportDTCByStatusMask M 0x03 reportDTCSnapshotIdentification M 0x04 reportDTCSnapshotRecordByDTCNumber M 0x06 reportDTCExtendedDataRecordByDTCNumber M 0x0F reportMirrorMemoryDTCByStatusMask U

NoneNoneNoneNoneRFQX-CVS124-0220 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0221Legislated OBD relevant ECUs have to support legislated OBD standards.
Statement

Legislated OBD relevant ECUs have to support legislated OBD standards.

NoneNoneNoneNoneRFQX-CVS124-0221 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0222ReportNumberOfDTCByStatusMask parameter format shall be as per ISO 14229-1.
Statement

ReportNumberOfDTCByStatusMask parameter format shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0222 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0223DTCStatusMask parameter format shall be as per ISO 14229-1.
Statement

DTCStatusMask parameter format shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0223 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0224Table 53 – Service 0x19 request parameter DTCMaskRecord description Byte Description Cvt High Definition according to either ISO 15031-6, ISO 14229 vehicle- manufacturer-defined, SAE J1939-73 M Middle M Low M
Statement

Table 53 – Service 0x19 request parameter DTCMaskRecord description Byte Description Cvt High Definition according to either ISO 15031-6, ISO 14229 vehicle- manufacturer-defined, SAE J1939-73 M Middle M Low M

NoneNoneNoneNoneRFQX-CVS124-0224 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0225It shall be mandatory to utilize SPNs & FMIs according to SAE J1939.
Statement

It shall be mandatory to utilize SPNs & FMIs according to SAE J1939.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0225 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0226DTCSnapshotRecordNumber parameter format shall be as per ISO 14229-1.
Statement

DTCSnapshotRecordNumber parameter format shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0226 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0227Table 54 – Service 0x19 request parameter DTCExtDataRecordNumber description 0x00 Reserved by ISO/SAE M 0x11 ExtDataRecNum 1 M 0x14 ExtDataRecNum 4 M 0xFE All legislated OBD stored DTCExtendedData records E 0xFF All stored DTCExtendedData records M 5.5.10.1.7 Request parameter FunctionalGroupIdentifier
Statement

Table 54 – Service 0x19 request parameter DTCExtDataRecordNumber description 0x00 Reserved by ISO/SAE M 0x11 ExtDataRecNum 1 M 0x14 ExtDataRecNum 4 M 0xFE All legislated OBD stored DTCExtendedData records E 0xFF All stored DTCExtendedData records M 5.5.10.1.7 Request parameter FunctionalGroupIdentifier

NoneNoneNoneNoneRFQX-CVS124-0227 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0228Response parameter FunctionalGroupIdentifier shall be as per ISO 14229-1.
Statement

Response parameter FunctionalGroupIdentifier shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0228 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0229DTCSeverityMaskRecord parameter format shall be as per ISO 14229-1.
Statement

DTCSeverityMaskRecord parameter format shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0229 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0230DTCSeverityMask parameter format shall be as per ISO 14229-1.
Statement

DTCSeverityMask parameter format shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0230 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02315.5.10.2.1 Response parameter DTCStatusAvailabilityMask
Statement

5.5.10.2.1 Response parameter DTCStatusAvailabilityMask

NoneNoneNoneNoneRFQX-CVS124-0231 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0232Response parameter DTCStatusAvailabilityMask shall be as per ISO 14229-1.
Statement

Response parameter DTCStatusAvailabilityMask shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0232 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0233Response parameter DTCFormatIdentifier shall be as per ISO 14229-1.
Statement

Response parameter DTCFormatIdentifier shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0233 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0234Response parameter DTCCount shall be as per ISO 14229-1.
Statement

Response parameter DTCCount shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0234 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0235Response parameter DTCAndStatusRecord shall be as per ISO 14229-1.
Statement

Response parameter DTCAndStatusRecord shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0235 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0236Response parameter DTCRecord shall be as per ISO 14229-1.
Statement

Response parameter DTCRecord shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0236 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02375.5.10.2.6 Response parameter reportDTCSnapshotRecordByDTCNumber The snapshot data sub-function (0x04) shall have positive response message data and format as specified in Table 67.
Statement

5.5.10.2.6 Response parameter reportDTCSnapshotRecordByDTCNumber The snapshot data sub-function (0x04) shall have positive response message data and format as specified in Table 67.

NoneNoneAD-001componentRFQX-CVS124-0237 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0238Table 55 – Snapshot data sub-function (0x04) positive response message content and format Range tion #1 ReadDTCInformation Response SID = 0x59 M #2 reportType = [ reportDTCSnapshotRecordByDTCNumber ] = 0x04 M #3 : #6 DTCAndStatusRecord[] = [ Byte 1: DTCHighByte Byte 2: DTCMiddleByte Byte 3: DTCLowByte Byte 4: statusOfDTC 0xFF 0xFF 0xFF 0xFF M M M M #7 DTCSnapshotRecordNumber#1 This byte shall be set to value 0x01.
Statement

Table 55 – Snapshot data sub-function (0x04) positive response message content and format Range tion #1 ReadDTCInformation Response SID = 0x59 M #2 reportType = [ reportDTCSnapshotRecordByDTCNumber ] = 0x04 M #3 : #6 DTCAndStatusRecord[] = [ Byte 1: DTCHighByte Byte 2: DTCMiddleByte Byte 3: DTCLowByte Byte 4: statusOfDTC 0xFF 0xFF 0xFF 0xFF M M M M #7 DTCSnapshotRecordNumber#1 This byte shall be set to value 0x01.

SSR-DIAG-006Diagnostic Services — Diagnostic ServicesAD-001componentRFQX-CVS124-0238 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0239If a mechanic is working on the vehicle, the driveline shall report Not Ready and place the vehicle in the state PropulsionNotReady.
Statement

If a mechanic is working on the vehicle, the driveline shall report Not Ready and place the vehicle in the state PropulsionNotReady.

NoneNoneAD-008componentRFQX-CVS124-0239 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0240Range tion #54 ECU start-up and alive reasons Bits 0-3 (start-up reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6-0xE: Reserved 0xF: Not available Bits 4-7 (alive reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6: Stay alive 0x7-0xE: Reserved 0xF: Not available Note 1: While the reason for keeping the ECU alive may change during execution startup reason and alive reason are always identical at ECU startup.
Statement

Range tion #54 ECU start-up and alive reasons Bits 0-3 (start-up reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6-0xE: Reserved 0xF: Not available Bits 4-7 (alive reason): 0x0: Reserved 0x1: Primary wake-up (terminal 15 ON) 0x2: Secondary wake-up 0x3: Sub wake-up 1 0x4: Sub wake-up 2 0x5: Sub wake-up 3 0x6: Stay alive 0x7-0xE: Reserved 0xF: Not available Note 1: While the reason for keeping the ECU alive may change during execution startup reason and alive reason are always identical at ECU startup.

NoneNoneNoneNoneRFQX-CVS124-0240 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0241dependent depend ent depende nt U #65+N+M- #66+N+M dataIdentifier 0x0000 – #67+N+M +P Data required by law or regulations Signal dependent depend ent depende nt C1 #68+N+M +P DTCSnapshotRecordNumber#2 (Latest Snapshot captured) 0x02 M #69+N+M +P DTCSnapshotRecordNumberOfIdentifiers#2 0x00 : 0xFF M #70+N+M +P : #70+2*(N +M+P) See specification for DTCSnapshotRecord[]#1 This latest snapshot shall contain the same type of data and format as DTCSnapshotRecord[]#1.
Statement

dependent depend ent depende nt U #65+N+M- #66+N+M dataIdentifier 0x0000 – #67+N+M +P Data required by law or regulations Signal dependent depend ent depende nt C1 #68+N+M +P DTCSnapshotRecordNumber#2 (Latest Snapshot captured) 0x02 M #69+N+M +P DTCSnapshotRecordNumberOfIdentifiers#2 0x00 : 0xFF M #70+N+M +P : #70+2*(N +M+P) See specification for DTCSnapshotRecord[]#1 This latest snapshot shall contain the same type of data and format as DTCSnapshotRecord[]#1.

NoneNoneAD-005interfaceRFQX-CVS124-0241 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0242DTCSnapshotRecordNumber#1 & DTCSnapshotRecordNumber#2 shall correspond to first time DTC happened and latest time DTC happened correspondingly.
Statement

DTCSnapshotRecordNumber#1 & DTCSnapshotRecordNumber#2 shall correspond to first time DTC happened and latest time DTC happened correspondingly.

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0242 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0243Table 56 – Service 0x19 response parameter DTCExtDataRecordNumber description 0x00 Reserved by ISO/SAE M 0x11 ExtDataRecNum 1 M 0x14 ExtDataRecNum 4 M 0xFE All legislated OBD stored DTCExtendedData records E 0xFF All stored DTCExtendedData records M 5.5.10.2.8 Response parameter DTCExtDataRecord
Statement

Table 56 – Service 0x19 response parameter DTCExtDataRecordNumber description 0x00 Reserved by ISO/SAE M 0x11 ExtDataRecNum 1 M 0x14 ExtDataRecNum 4 M 0xFE All legislated OBD stored DTCExtendedData records E 0xFF All stored DTCExtendedData records M 5.5.10.2.8 Response parameter DTCExtDataRecord

NoneNoneNoneNoneRFQX-CVS124-0243 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0244The extended data sub-function (0x06) shall have the positive response message data and format specified in Table 68.
Statement

The extended data sub-function (0x06) shall have the positive response message data and format specified in Table 68.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0244 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0245Table 57 – Extended data sub-function (0x06) positive response message content and format Byte Description Range Resolu tion #1 ReadDTCInformation Response SID = 0x59 M #2 reportType = reportDTCExtDataRecordByDTCNumber 0x06 M #3 : #6 DTCAndStatusRecord[] = [ DTCHighByte DTCMiddleByte DTCLowByte statusOfDTC ] M #7 DTCExtDataRecordNumber#1 This byte shall be set to value 0x11.
Statement

Table 57 – Extended data sub-function (0x06) positive response message content and format Byte Description Range Resolu tion #1 ReadDTCInformation Response SID = 0x59 M #2 reportType = reportDTCExtDataRecordByDTCNumber 0x06 M #3 : #6 DTCAndStatusRecord[] = [ DTCHighByte DTCMiddleByte DTCLowByte statusOfDTC ] M #7 DTCExtDataRecordNumber#1 This byte shall be set to value 0x11.

NoneNoneAD-001componentRFQX-CVS124-0245 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0246Byte Description Range Resolu tion This byte shall be set to value 2 and is used to identify the response structure variant #9 Occurrence counter OCC, as described in section 5.7.2 [unsigned integer] 0..127 0 M #10 DTC priority 1 – Highest priority 2 - Second highest priority 3 – Lowest priority 255 – Unknown 1..3, 255 0xFF M #11..#16 Time/Date of the first DTC activation See Table 98 but without byte #7 and #8 M #17..#22 Time/Date of the latest DTC activation M #23..#26 ECU Operational hours at the first DTC activation [4-byte int, big endian] as described in section 5.7.5.2.
Statement

Byte Description Range Resolu tion This byte shall be set to value 2 and is used to identify the response structure variant #9 Occurrence counter OCC, as described in section 5.7.2 [unsigned integer] 0..127 0 M #10 DTC priority 1 – Highest priority 2 - Second highest priority 3 – Lowest priority 255 – Unknown 1..3, 255 0xFF M #11..#16 Time/Date of the first DTC activation See Table 98 but without byte #7 and #8 M #17..#22 Time/Date of the latest DTC activation M #23..#26 ECU Operational hours at the first DTC activation [4-byte int, big endian] as described in section 5.7.5.2.

NoneNoneAD-006componentRFQX-CVS124-0246 / 56hNot importedStill Requires Customer DecisionP1 OPENboundary ownershipMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0247For these ECUs these bytes shall contain default value 0xFF (all bytes).
Statement

For these ECUs these bytes shall contain default value 0xFF (all bytes).

NoneNoneAD-008componentRFQX-CVS124-0247 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0248Byte Description Range Resolu tion 0: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m #35..#38 Total vehicle distance at the latest DTC activation [4-byte int, big endian] in section 5.7.4.1 Not used for TRATON External engine and marine ECUsFor these ECUs these bytes shall contain default value 0xFF (all bytes).
Statement

Byte Description Range Resolu tion 0: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m #35..#38 Total vehicle distance at the latest DTC activation [4-byte int, big endian] in section 5.7.4.1 Not used for TRATON External engine and marine ECUsFor these ECUs these bytes shall contain default value 0xFF (all bytes).

NoneNoneAD-008componentRFQX-CVS124-0248 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-02490: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m 0xFFF FFFFF 5 m/bit 0xFF (all bytes) C #41+(2p+1) +1 DTCExtDataRecordNumber#4 This byte shall be set to value 0x14.
Statement

0: 0 m 1: 5 m (factor 5) … 4261412863: 21 307 064 315 m 0xFFF FFFFF 5 m/bit 0xFF (all bytes) C #41+(2p+1) +1 DTCExtDataRecordNumber#4 This byte shall be set to value 0x14.

NoneNoneAD-008componentRFQX-CVS124-0249 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0250Response parameter FunctionalGroupIdentifier shall be as per ISO 14229-1.
Statement

Response parameter FunctionalGroupIdentifier shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0250 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0251Response parameter DTCSeverityAvailabilityMask shall be as per ISO 14229-1.
Statement

Response parameter DTCSeverityAvailabilityMask shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0251 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0252Response parameter DTCAndSeverityRecord shall be as per ISO 14229-1.
Statement

Response parameter DTCAndSeverityRecord shall be as per ISO 14229-1.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0252 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02535.5.10.3.1 Supported negative response codes
Statement

5.5.10.3.1 Supported negative response codes

NoneNoneNoneNoneRFQX-CVS124-0253 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0254Negative response codes shall be as per ISO 14229-1.
Statement

Negative response codes shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0254 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02555.5.11.1.1 Request parameter dataIdentifier
Statement

5.5.11.1.1 Request parameter dataIdentifier

NoneNoneNoneNoneRFQX-CVS124-0255 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0256The data identifier ranges specified in ISO 14229-1 shall be followed.
Statement

The data identifier ranges specified in ISO 14229-1 shall be followed.

SSR-DIAG-004Diagnostic Services — Diagnostic ServicesAD-003componentRFQX-CVS124-0256 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0257Table 58 – Service 0x2F request parameter controlOptionRecord description 1 inputOutputControlParameter M 2 ..
Statement

Table 58 – Service 0x2F request parameter controlOptionRecord description 1 inputOutputControlParameter M 2 ..

NoneNoneNoneNoneRFQX-CVS124-0257 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0258Table 59 – Service 0x2F request parameter inputOutputControlParameter description 0x00 returnControlToECU Refer to ISO 14229-1 for parameter description.
Statement

Table 59 – Service 0x2F request parameter inputOutputControlParameter description 0x00 returnControlToECU Refer to ISO 14229-1 for parameter description.

NoneNoneNoneNoneRFQX-CVS124-0258 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0259ControlEnableMaskRecord parameter format shall be as per ISO 14229-1.
Statement

ControlEnableMaskRecord parameter format shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0259 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02605.5.11.3 Negative response
Statement

5.5.11.3 Negative response

NoneNoneNoneNoneRFQX-CVS124-0260 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02615.5.12 RoutineControl (0x31) service 5.5.12.1 Request
Statement

5.5.12 RoutineControl (0x31) service 5.5.12.1 Request

NoneNoneNoneNoneRFQX-CVS124-0261 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-02625.5.12.1.1 Request parameter RoutineControlType
Statement

5.5.12.1.1 Request parameter RoutineControlType

NoneNoneNoneNoneRFQX-CVS124-0262 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0263Table 60 – Service 0x31 request parameter RoutineControlType description 0x01 startRoutine M 0x02 stopRoutine C 0x03 requestRoutineResults C C = Mandatory for routines implemented according to Method “A”.
Statement

Table 60 – Service 0x31 request parameter RoutineControlType description 0x01 startRoutine M 0x02 stopRoutine C 0x03 requestRoutineResults C C = Mandatory for routines implemented according to Method “A”.

NoneNoneNoneNoneRFQX-CVS124-0263 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0264Request parameter routineIdentifier shall be as per ISO 14229-1.
Statement

Request parameter routineIdentifier shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0264 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0265The routine IDs as listed in Table 61 are reserved by TRATON and shall not be used by the system supplier.
Statement

The routine IDs as listed in Table 61 are reserved by TRATON and shall not be used by the system supplier.

NoneNoneAD-008componentRFQX-CVS124-0265 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0266Table 61 – Service 0x31 request parameter RoutineIdentifier description 0x02B2 0x02B3 0x02B4 ReadStatusOfDiagnosticEventCodes
Statement

Table 61 – Service 0x31 request parameter RoutineIdentifier description 0x02B2 0x02B3 0x02B4 ReadStatusOfDiagnosticEventCodes

NoneNoneNoneNoneRFQX-CVS124-0266 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0267Request parameter routineControlOptionRecord shall be as per ISO 14229-1.
Statement

Request parameter routineControlOptionRecord shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0267 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02685.5.12.3 Negative response
Statement

5.5.12.3 Negative response

NoneNoneNoneNoneRFQX-CVS124-0268 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02695.5.13 Request Download Service (0x34)
Statement

5.5.13 Request Download Service (0x34)

NoneNoneNoneNoneRFQX-CVS124-0269 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0270If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request.
Statement

If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall start erasing the memory area specified with the RequestDownload request.

SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageAD-006componentRFQX-CVS124-0270 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0271In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint.
Statement

In order to satisfy stability requirements, the erasing of the boot loader may require that the old boot loader is copied into another memory area before the boot loader memory is erased, see Annex A for an implementation hint.

NoneNoneNoneNoneRFQX-CVS124-0271 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0272If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).
Statement

If the most recent Erase Memory routine request in the current session was made with the addressAndLengthFormatIdentifier parameter set to value 0x00 the server shall reset the following identification DIDs to their default values: • If boot software download is requested, reset 0xF180, 0xF191 and 0xF187 to default values (some of the DIDs will be automatically erased as a consequence of erasing one or more modules).

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0272 / 16hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0273Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error.
Statement

Once the RequestDownload service has started, only services TesterPresent, ECUReset,TransferData and DiagnosticSessionControl shall be permitted until service RequestTransferExit has been called or until any of these services returns an error.

SSR-SDT-001Secure Data Transfer / Data Security Container — Secure Data Transfer / Data Security ContainerAD-001componentRFQX-CVS124-0273 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0274If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x12 (sub
Statement

If a non-permitted service is requested after the RequestDownload service has started and before RequestTransferExit has been called the server shall respond with NRC 0x12 (sub

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0274 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0275The server shall support service request formatted according to Table 62.
Statement

The server shall support service request formatted according to Table 62.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0275 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0276Table 63 – Service 0x34 request parameter dataFormatIdentifier description compressionMethod: 0x0: no compression 0x1 – 0x9: reserved for the supplier 0xA: vehicle manufacturer standard compression algorithm LZSS 0xB – 0xF: reserved for vehicle manufacturer M 0x0 – 0xF
Statement

Table 63 – Service 0x34 request parameter dataFormatIdentifier description compressionMethod: 0x0: no compression 0x1 – 0x9: reserved for the supplier 0xA: vehicle manufacturer standard compression algorithm LZSS 0xB – 0xF: reserved for vehicle manufacturer M 0x0 – 0xF

NoneNoneNoneNoneRFQX-CVS124-0276 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0277Table 64 – Service 0x34 request parameter addressAndLengthFormatIdentifier description 7 - 4 Length (number of bytes) of the memorySize parameter M 3,4 3 - 0 Length (number of bytes) of the memoryAddress parameter M 3, 4 5.5.13.4 Positive response
Statement

Table 64 – Service 0x34 request parameter addressAndLengthFormatIdentifier description 7 - 4 Length (number of bytes) of the memorySize parameter M 3,4 3 - 0 Length (number of bytes) of the memoryAddress parameter M 3, 4 5.5.13.4 Positive response

NoneNoneNoneNoneRFQX-CVS124-0277 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0278Table 65 – Positive response parameter description #1 RequestDownload Response SID M 0x74 #2 lengthFormatIdentifier M 0x20 #3..
Statement

Table 65 – Positive response parameter description #1 RequestDownload Response SID M 0x74 #2 lengthFormatIdentifier M 0x20 #3..

NoneNoneNoneNoneRFQX-CVS124-0278 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0279Table 66 – Service 0x34 response parameter lengthFormatIdentifier description 7 - 4 Length (number of bytes) of the maxNumberOfBlockLength parameter M 0x2 3 - 0 ISO reserved.
Statement

Table 66 – Service 0x34 response parameter lengthFormatIdentifier description 7 - 4 Length (number of bytes) of the maxNumberOfBlockLength parameter M 0x2 3 - 0 ISO reserved.

NoneNoneNoneNoneRFQX-CVS124-0279 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0280Table 67 – Service 0x35 request parameter description 1 RequestDownload Request SID M 2 dataFormatIdentifier M 3 addressAndLengthFormatIdentifier M 4 ..
Statement

Table 67 – Service 0x35 request parameter description 1 RequestDownload Request SID M 2 dataFormatIdentifier M 3 addressAndLengthFormatIdentifier M 4 .. (m-1)+4

NoneNoneNoneNoneRFQX-CVS124-0280 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0281Table 68 – Service 0x35 request parameter dataFormatIdentifier description Bytes Description Cvt Values compressionMethod: 0x0: no compression 0x1 – 0x9: reserved for the supplier 0xA: vehicle manufacturer standard compression algorithm LZSS 0xB – 0xF: reserved for vehicle manufacturer M 0x0 – 0xF encryptingMethod: 0x0: no encryption 0x1: encryption on DSC 0x2 -0x7 : reserved for vehicle manufacturer M 0x0 – 0x1
Statement

Table 68 – Service 0x35 request parameter dataFormatIdentifier description Bytes Description Cvt Values compressionMethod: 0x0: no compression 0x1 – 0x9: reserved for the supplier 0xA: vehicle manufacturer standard compression algorithm LZSS 0xB – 0xF: reserved for vehicle manufacturer M 0x0 – 0xF encryptingMethod: 0x0: no encryption 0x1: encryption on DSC 0x2 -0x7 : reserved for vehicle manufacturer M 0x0 – 0x1

NoneNoneNoneNoneRFQX-CVS124-0281 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0282Request
Statement

Request

NoneNoneNoneNoneRFQX-CVS124-0282 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0283Table 69 – Service 0x35 request parameter addressAndLengthFormatIdentifier description 7 - 4 Length (number of bytes) of the memorySize parameter M 3,4 3 - 0 Length (number of bytes) of the memoryAddress parameter M 3, 4 5.5.14.1.3 Request parameter memoryAddress
Statement

Table 69 – Service 0x35 request parameter addressAndLengthFormatIdentifier description 7 - 4 Length (number of bytes) of the memorySize parameter M 3,4 3 - 0 Length (number of bytes) of the memoryAddress parameter M 3, 4 5.5.14.1.3 Request parameter memoryAddress

NoneNoneNoneNoneRFQX-CVS124-0283 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0284MemoryAddress parameter definition shall be as per ISO 14229-1.
Statement

MemoryAddress parameter definition shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0284 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0285MemorySize parameter definition shall be as per ISO 14229-1.
Statement

MemorySize parameter definition shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0285 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02865.5.14.2.1 Response parameter lengthFormatIdentifier
Statement

5.5.14.2.1 Response parameter lengthFormatIdentifier

NoneNoneNoneNoneRFQX-CVS124-0286 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0287Table 70 – Service 0x35 response parameter lengthFormatIdentifier description 7 - 4 Length (number of bytes) of the maxNumberOfBlockLength parameter M 0x2 3 - 0 ISO reserved.
Statement

Table 70 – Service 0x35 response parameter lengthFormatIdentifier description 7 - 4 Length (number of bytes) of the maxNumberOfBlockLength parameter M 0x2 3 - 0 ISO reserved.

NoneNoneNoneNoneRFQX-CVS124-0287 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0288Refer to ISO 14229-1 for negative response format and codes shall be as per ISO 14229-1.
Statement

Refer to ISO 14229-1 for negative response format and codes shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0288 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0289MemoryAddress parameter definition shall be as per ISO 14229-1.
Statement

MemoryAddress parameter definition shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0289 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0290MemorySize parameter definition shall be as per ISO 14229-1.
Statement

MemorySize parameter definition shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0290 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02915.5.15.3 Negative response
Statement

5.5.15.3 Negative response

NoneNoneNoneNoneRFQX-CVS124-0291 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02925.5.15.3.1 Supported negative response codes
Statement

5.5.15.3.1 Supported negative response codes

NoneNoneNoneNoneRFQX-CVS124-0292 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02935.5.16 RequestTransferExit (0x37) service 5.5.16.1 Request
Statement

5.5.16 RequestTransferExit (0x37) service 5.5.16.1 Request

NoneNoneNoneNoneRFQX-CVS124-0293 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0294Table 71 – Service 0x37 request parameter description 1 RequestTransferExit Request SID M 5.5.16.1.1 Request parameter transferRequestParameterRecord
Statement

Table 71 – Service 0x37 request parameter description 1 RequestTransferExit Request SID M 5.5.16.1.1 Request parameter transferRequestParameterRecord

NoneNoneNoneNoneRFQX-CVS124-0294 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0295The transferRequestParameterRecord shall not be supported.
Statement

The transferRequestParameterRecord shall not be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0295 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0296Table 72 – Service 0x37 positive response parameter description 1 RequestTransferExit Response SID M
Statement

Table 72 – Service 0x37 positive response parameter description 1 RequestTransferExit Response SID M

NoneNoneNoneNoneRFQX-CVS124-0296 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0297The transferRequestParameterRecord shall not be supported.
Statement

The transferRequestParameterRecord shall not be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0297 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-02985.5.16.3.1 Supported negative response codes
Statement

5.5.16.3.1 Supported negative response codes

NoneNoneNoneNoneRFQX-CVS124-0298 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-02995.5.17 SecuredDataTransmission (0x84) service
Statement

5.5.17 SecuredDataTransmission (0x84) service

NoneNoneNoneNoneRFQX-CVS124-0299 / 16hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0300This service shall be used when transmitting data in a secured mode, see CVS32.
Statement

This service shall be used when transmitting data in a secured mode, see CVS32.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0300 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-03015.5.17.1.1 Request message data-parameter definition
Statement

5.5.17.1.1 Request message data-parameter definition

NoneNoneNoneNoneRFQX-CVS124-0301 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0302Data parameter definition shall be as per ISO 14229-1.
Statement

Data parameter definition shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0302 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0303Positive response shall be as per CVS32.
Statement

Positive response shall be as per CVS32.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0303 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0304Negative response shall be as per CVS32 5.5.17.3.1 Supported negative response codes
Statement

Negative response shall be as per CVS32 5.5.17.3.1 Supported negative response codes

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0304 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0305Negative response format shall be as per ISO 14229-1 5.5.18 Authentication (0x29) service
Statement

Negative response format shall be as per ISO 14229-1 5.5.18 Authentication (0x29) service

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS124-0305 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0306Authentication (0x29) service shall be used for authentication of client and server.
Statement

Authentication (0x29) service shall be used for authentication of client and server.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS124-0306 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0307The Authentication (0x29) service shall be implemented according to CVS31 .
Statement

The Authentication (0x29) service shall be implemented according to CVS31 .

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS124-0307 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0308Refer to CVS31 .
Statement

Refer to CVS31 .

NoneNoneNoneNoneRFQX-CVS124-0308 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0309Refer to CVS31 .
Statement

Refer to CVS31 .

NoneNoneNoneNoneRFQX-CVS124-0309 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0310Refer to CVS31 .
Statement

Refer to CVS31 .

NoneNoneNoneNoneRFQX-CVS124-0310 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-03115.5.18.4.1 Supported negative response codes
Statement

5.5.18.4.1 Supported negative response codes

NoneNoneNoneNoneRFQX-CVS124-0311 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0312Supported negative response codes shall be as per ISO 14229-1, especially the NRC range 0x50 – 0x5D according to Table 73.
Statement

Supported negative response codes shall be as per ISO 14229-1, especially the NRC range 0x50 – 0x5D according to Table 73.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0312 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0313For detailed error cases and the mapping to the corresponding NRCs the Authentication service implementation specification CVS31 shall be used.
Statement

For detailed error cases and the mapping to the corresponding NRCs the Authentication service implementation specification CVS31 shall be used.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0313 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-03145.5.19.2 Request Parameter modeOfOperation
Statement

5.5.19.2 Request Parameter modeOfOperation

NoneNoneNoneNoneRFQX-CVS124-0314 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0315Table 74 – Service 0x38 request parameter modeOfOperation description Byte value Description Cvt 0x00 ISO Reserved M 0x01 AddFile This value shall be used to add the file (download) defined in the filePathAndName parameter M 0x02 DeleteFile This value shall be used to delete the file defined in the filePathAndName parameter U 0x03 ReplaceFile This value shall be used to replace the file (download) defined in the filePathAndName parameter.
Statement

Table 74 – Service 0x38 request parameter modeOfOperation description Byte value Description Cvt 0x00 ISO Reserved M 0x01 AddFile This value shall be used to add the file (download) defined in the filePathAndName parameter M 0x02 DeleteFile This value shall be used to delete the file defined in the filePathAndName parameter U 0x03 ReplaceFile This value shall be used to replace the file (download) defined in the filePathAndName parameter.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0315 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0316If the file is not stored at the location the file shall be added.
Statement

If the file is not stored at the location the file shall be added.

NoneNoneAD-008componentRFQX-CVS124-0316 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0317M 0x04 ReadFile This value shall be used to read the file (upload) at the location defined by the filePathAndName parameter.
Statement

M 0x04 ReadFile This value shall be used to read the file (upload) at the location defined by the filePathAndName parameter.

NoneNoneAD-008componentRFQX-CVS124-0317 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0318U 0x05 ReadDir This value shall be used to read the directory defined in the filePathAndName parameter.
Statement

U 0x05 ReadDir This value shall be used to read the directory defined in the filePathAndName parameter.

NoneNoneAD-008componentRFQX-CVS124-0318 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0319U 0x06 ResumeFile This value shall be used to resume downloading the file defined in the filePathAndName parameter at the returned filePosition indicator.
Statement

U 0x06 ResumeFile This value shall be used to resume downloading the file defined in the filePathAndName parameter at the returned filePosition indicator.

NoneNoneAD-008componentRFQX-CVS124-0319 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0320The file specified in the filePathAndName shall already exist in the ECU’s file system.
Statement

The file specified in the filePathAndName shall already exist in the ECU’s file system.

NoneNoneAD-006componentRFQX-CVS124-0320 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0321Refer to ISO 14229-1 for parameter sub-function format shall be as per ISO 14229-1.
Statement

Refer to ISO 14229-1 for parameter sub-function format shall be as per ISO 14229-1.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0321 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0322Table 75 – Service 0x38 request parameter dataFormatIdentifier description compressionMethod: 0x0: no compression 0x1 – 0x9: reserved for the supplier 0xA: vehicle manufacturer standard compression algorithm LZSS 0xB – 0xF: reserved for vehicle manufacturer M 0x0 – 0xF encryptingMethod: 0x0: no encryption 0x1: encryption on DSC 0x2 -0x7 : reserved for vehicle manufacturer M 0x0 – 0x1 5.5.19.5 Positive response
Statement

Table 75 – Service 0x38 request parameter dataFormatIdentifier description compressionMethod: 0x0: no compression 0x1 – 0x9: reserved for the supplier 0xA: vehicle manufacturer standard compression algorithm LZSS 0xB – 0xF: reserved for vehicle manufacturer M 0x0 – 0xF encryptingMethod: 0x0: no encryption 0x1: encryption on DSC 0x2 -0x7 : reserved for vehicle manufacturer M 0x0 – 0x1 5.5.19.5 Positive response

NoneNoneNoneNoneRFQX-CVS124-0322 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-03235.5.19.6 Negative response
Statement

5.5.19.6 Negative response

NoneNoneNoneNoneRFQX-CVS124-0323 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-03245.5.19.7 Supported negative response codes
Statement

5.5.19.7 Supported negative response codes

NoneNoneNoneNoneRFQX-CVS124-0324 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0325Supported negative response codes shall be as per ISO 14229-1.
Statement

Supported negative response codes shall be as per ISO 14229-1.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0325 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0326This RoutineIdentifier enables the client to query the state of the programming preconditions in the server and applicable only for programmable ECUs.
Statement

This RoutineIdentifier enables the client to query the state of the programming preconditions in the server and applicable only for programmable ECUs.

NoneNoneNoneNoneRFQX-CVS124-0326 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0327The programming preconditions shall be agreed with the vehicle manufacturer.
Statement

The programming preconditions shall be agreed with the vehicle manufacturer. Preconditions to

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0327 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0328Preconditions to be discussed with the vehicle manufacturer shall include but not be limited to Diag safe state conditions.
Statement

Preconditions to be discussed with the vehicle manufacturer shall include but not be limited to Diag safe state conditions.

NoneNoneAD-008componentRFQX-CVS124-0328 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0329The decision on conditions of the programming precondition shall be based on minimum two independent sources of information.
Statement

The decision on conditions of the programming precondition shall be based on minimum two independent sources of information.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0329 / 26hNot importedNo linked clarificationNo P1 linkevidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0330If information is not available for checking a programming precondition the programming precondition shall be considered fulfilled.
Statement

If information is not available for checking a programming precondition the programming precondition shall be considered fulfilled.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0330 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0331If the ECU received the information related to any of the conditions during the same driving cycle then it shall use that information.
Statement

If the ECU received the information related to any of the conditions during the same driving cycle then it shall use that information.

NoneNoneAD-006componentRFQX-CVS124-0331 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0332This routine shall be supported in Extended session of both Application and Boot.
Statement

This routine shall be supported in Extended session of both Application and Boot.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0332 / 18hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0333Request parameter RoutineControlOptionRecord shall not be supported.
Statement

Request parameter RoutineControlOptionRecord shall not be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0333 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0334Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported.
Statement

Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0334 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0335Table 76 – RoutineControl (CheckProgrammingPreconditions) positive response format #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) checkProgrammingPreconditions [byte#1] M 0x22 #4 routineIdentifier (LSB) checkProgrammingPreconditions [byte#2] M 0x03 #5 routineStatus (byte#1) programmingPreconditionList [byte#1] U 0x00-0xFF #5+m-1 routineStatus (byte#m) programmingPreconditionList [byte#m] U 0x00-0xFF
Statement

Table 76 – RoutineControl (CheckProgrammingPreconditions) positive response format #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) checkProgrammingPreconditions [byte#1] M 0x22 #4 routineIdentifier (LSB) checkProgrammingPreconditions [byte#2] M 0x03 #5 routineStatus (byte#1) programmingPreconditionList [byte#1] U 0x00-0xFF #5+m-1 routineStatus (byte#m) programmingPreconditionList [byte#m] U 0x00-0xFF

NoneNoneNoneNoneRFQX-CVS124-0335 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0336Each routineStatus byte shall represent one not satisfied precondition according to Table 18 (see definition of “Satisfied programming precondition”).
Statement

Each routineStatus byte shall represent one not satisfied precondition according to Table 18 (see definition of “Satisfied programming precondition”).

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0336 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0337Which ones of the programming precondition codes in Table 18 that need to be supported shall
Statement

Which ones of the programming precondition codes in Table 18 that need to be supported shall

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0337 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0338If all preconditions are satisfied, no routineStatus byte shall be reported.
Statement

If all preconditions are satisfied, no routineStatus byte shall be reported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0338 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0339Programming preconditions that do not map to one of the entries in Table 77 shall be discussed with the vehicle manufacturer.
Statement

Programming preconditions that do not map to one of the entries in Table 77 shall be discussed with the vehicle manufacturer.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0339 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0340Table 77 – Programming preconditions Hex Description Origin 0x01 Engine speed is not zero Defined by the “manufacturers software initiative” (HIS) 0x02 Engine immobilizer is not released 0x03 Transmission input speed is not zero 0x04 Transmission output speed is not zero 0x05 Vehicle speed is not zero 0x06 Closed-loop control active 0x07 Ignition system off-on required 0x08 No programming voltage 0x09 Ignition (terminal 15) is not turned on 0x0A Supply voltage too low 0x0B Temperature too high 0x0C Temperature too low ..
Statement

Table 77 – Programming preconditions Hex Description Origin 0x01 Engine speed is not zero Defined by the “manufacturers software initiative” (HIS) 0x02 Engine immobilizer is not released 0x03 Transmission input speed is not zero 0x04 Transmission output speed is not zero 0x05 Vehicle speed is not zero 0x06 Closed-loop control active 0x07 Ignition system off-on required 0x08 No programming voltage 0x09 Ignition (terminal 15) is not turned on 0x0A Supply voltage too low 0x0B Temperature too high 0x0C Temperature too low ..

NoneNoneAD-001componentRFQX-CVS124-0340 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0341The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested.
Statement

The server shall respond with a positive response code without erasing memory if the specified memory area has already been completely erased (or is writable) at the time the service is requested.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0341 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0342In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint.
Statement

In order to satisfy stability requirements, the erasing of the boot loader may require that the current boot loader be copied into another non-volatile memory area before the boot loader memory is erased, see Annex A for an implementation hint.

NoneNoneNoneNoneRFQX-CVS124-0342 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0343In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area.
Statement

In case the non volatile memory area is currently hosting a bootloader copy, meaning there is an ongoing bootloader update procedure, the ECU shall ensure that this memory area shall not be erased until a valid bootloader is flashed in the bootloader memory area.

SSR-BOOT-002Secure software update and flash readiness — Bootloader and Application State HandlingAD-006componentRFQX-CVS124-0343 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0344SUV2_INFO 114 in CVS123 prevents the scenario of erasing the copied bootloader while boot loader update and leaving the ECU without any bootloader.
Statement

SUV2_INFO 114 in CVS123 prevents the scenario of erasing the copied bootloader while boot loader update and leaving the ECU without any bootloader.

NoneNoneNoneNoneRFQX-CVS124-0344 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0345When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see
Statement

When the addressAndLengthFormatIdentifier parameter is set to a value > 0x00 the server shall reset the following software and data identification DIDs to their default values (see

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0345 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0346The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e.
Statement

The erasing of memory shall not prevent the client from starting a data transfer using the TransferData (0x36) service, i.e.

SSR-SDT-001Secure Data Transfer / Data Security Container — Secure Data Transfer / Data Security ContainerAD-001componentRFQX-CVS124-0346 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0347the erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase.
Statement

the erasing of memory shall proceed in parallel with data transfer in case for ECUs implementing Automatic erase.

NoneNoneAD-006componentRFQX-CVS124-0347 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0348This routine shall be supported in Programming session.
Statement

This routine shall be supported in Programming session.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0348 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0349Table 78 – RoutineIdentifier 0xFF00 description #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0xFF #4 routineIdentifier (LSB) M 0x00 #5 addressAndLengthFormatIdentifier (XXXXYYYYb) XXXXb = number of bytes of memorySize parameter YYYYb = number of bytes of memoryStartAddress parameter.
Statement

Table 78 – RoutineIdentifier 0xFF00 description #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0xFF #4 routineIdentifier (LSB) M 0x00 #5 addressAndLengthFormatIdentifier (XXXXYYYYb) XXXXb = number of bytes of memorySize parameter YYYYb = number of bytes of memoryStartAddress parameter.

NoneNoneNoneNoneRFQX-CVS124-0349 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0350Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported 5.6.2.2 Request parameter addressAndLengthFormatIdentifier
Statement

Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported 5.6.2.2 Request parameter addressAndLengthFormatIdentifier

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0350 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0351Table 79 – Request parameter addressAndLengthFormatIdentifier values Byte Value Description Cvt 0x00 Automatic erase: Erase is performed by boot loader automatically when RequestDownload is received for each Flash sector in the module.
Statement

Table 79 – Request parameter addressAndLengthFormatIdentifier values Byte Value Description Cvt 0x00 Automatic erase: Erase is performed by boot loader automatically when RequestDownload is received for each Flash sector in the module.

NoneNoneNoneNoneRFQX-CVS124-0351 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-035202, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements & &
Statement

02, Module 2 (Application SW module) M 0x02 – 0xFF Physical memory range erase: Refer to ISO 14229-1 Table H1 M C = Mandatory if required to meet the performance requirements & &

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0352 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0353in CVS123.
Statement

in CVS123.

NoneNoneNoneNoneRFQX-CVS124-0353 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0354When the addressAndLengthFormatIdentifier is set to 0x01 the following defined module to index mapping shall apply for the memoryStartAddress: 1 – Boot loader 2 – Application 3 – Application Data 4 ...
Statement

When the addressAndLengthFormatIdentifier is set to 0x01 the following defined module to index mapping shall apply for the memoryStartAddress: 1 – Boot loader 2 – Application 3 – Application Data 4 ...

SSR-BOOT-005Bootloader and Application State Handling — Bootloader and Application State HandlingAD-001componentRFQX-CVS124-0354 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0355Table 80 – RoutineControl (EraseMemory) positive response format #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) eraseMemory [byte#1] M 0xFF #4 routineIdentifier (LSB) eraseMemory [byte#2] M 0x00 #5 routineStatus routineResult M 0x00-0xFF
Statement

Table 80 – RoutineControl (EraseMemory) positive response format #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) eraseMemory [byte#1] M 0xFF #4 routineIdentifier (LSB) eraseMemory [byte#2] M 0x00 #5 routineStatus routineResult M 0x00-0xFF

NoneNoneNoneNoneRFQX-CVS124-0355 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0356The routineResult byte values shall be as specified in Table 81.
Statement

The routineResult byte values shall be as specified in Table 81.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0356 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-03575.6.2.5 Message flow example(s) RoutineControl (EraseMemory) Example #1: Request: client → server
Statement

5.6.2.5 Message flow example(s) RoutineControl (EraseMemory) Example #1: Request: client → server

NoneNoneNoneNoneRFQX-CVS124-0357 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0358This is an example where the client requests to erase a module in the server memory by a given memoryStartAddress and memorySize.
Statement

This is an example where the client requests to erase a module in the server memory by a given memoryStartAddress and memorySize.

NoneNoneNoneNoneRFQX-CVS124-0358 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0359This example reports a failure when the erase operation is started, e.g.
Statement

This example reports a failure when the erase operation is started, e.g. memory failure.

NoneNoneNoneNoneRFQX-CVS124-0359 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0360This is an example where the client requests to erase a module with module index 3 in the server’s memory.
Statement

This is an example where the client requests to erase a module with module index 3 in the server’s memory.

NoneNoneNoneNoneRFQX-CVS124-0360 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0361The RoutineIdentifier may verify the authenticity of the received file package.
Statement

The RoutineIdentifier may verify the authenticity of the received file package. See CVS123 and

NoneNoneNoneNoneRFQX-CVS124-0361 / 18hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0362If authenticity verification is valid the server shall initiate all necessary steps for installation of the received file.
Statement

If authenticity verification is valid the server shall initiate all necessary steps for installation of the received file.

SSR-DAI-006Security evidence and traceability — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS124-0362 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0363The authenticity verification performed by the RoutineIdentifier 0x2401 Software Installation does not exempt the authenticity verification for RoutineIdentifier 0xFF01 – CheckProgrammingDependencies.
Statement

The authenticity verification performed by the RoutineIdentifier 0x2401 Software Installation does not exempt the authenticity verification for RoutineIdentifier 0xFF01 – CheckProgrammingDependencies.

NoneNoneNoneNoneRFQX-CVS124-0363 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0364The server shall send a response to RoutineIdentifier 0x2401 Software Installation without any further inputs from the client.
Statement

The server shall send a response to RoutineIdentifier 0x2401 Software Installation without any further inputs from the client.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS124-0364 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0365If authenticity verification fails the server shall send the positive response with AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) set to 0x02 (Authenticity Verification Failed) and SoftwareInstallationStatus bit 7-6 (InstallationStatus) set to 0x02 (Installation Failed).
Statement

If authenticity verification fails the server shall send the positive response with AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) set to 0x02 (Authenticity Verification Failed) and SoftwareInstallationStatus bit 7-6 (InstallationStatus) set to 0x02 (Installation Failed).

SSR-DAI-006Security evidence and traceability — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS124-0365 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0366This routine shall be supported in Programming session.
Statement

This routine shall be supported in Programming session.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0366 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0367Request parameter RoutineControlOptionRecord shall not be supported.
Statement

Request parameter RoutineControlOptionRecord shall not be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0367 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0368Positive responses to RoutineControl (Software Installation) service requests shall be formatted
Statement

Positive responses to RoutineControl (Software Installation) service requests shall be formatted

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0368 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0369Description Cvt Values #1 RoutineControl Request SID M 0x71 #2 routineControlType (requestRoutineResults) M 0x03 #3 routineIdentifier (MSB) M 0x24 #4 routineIdentifier (LSB) M 0x01 #5 AuthenticityVerificationStatus M 0x00 – 0xFF #6 SoftwareInstallationStatus M 0x00 – 0xFF #7 CompletionPercentage M 0x00 – 0x64 #8-#9 TimeRemaningEstimative M 0x0000 – 0xFFFF AuthenticityVerificationStatus shall be formatted according to Table 90.
Statement

Description Cvt Values #1 RoutineControl Request SID M 0x71 #2 routineControlType (requestRoutineResults) M 0x03 #3 routineIdentifier (MSB) M 0x24 #4 routineIdentifier (LSB) M 0x01 #5 AuthenticityVerificationStatus M 0x00 – 0xFF #6 SoftwareInstallationStatus M 0x00 – 0xFF #7 CompletionPercentage M 0x00 – 0x64 #8-#9 TimeRemaningEstimative M 0x0000 – 0xFFFF AuthenticityVerificationStatus shall be formatted according to Table 90.

SSR-DAI-007Security evidence and traceability — Data Authenticity and Integrity VerificationAD-008componentRFQX-CVS124-0369 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0370AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall remain as 0x0 (Software Authenticity Invalid) until the verification completes.
Statement

AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall remain as 0x0 (Software Authenticity Invalid) until the verification completes.

SSR-DAI-005Security evidence and traceability — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS124-0370 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0371If no authenticity verification will take place as part of RoutineIdentifier, the AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall be changed to 0x1 (Authenticity Verification Successful).
Statement

If no authenticity verification will take place as part of RoutineIdentifier, the AuthenticityVerificationStatus bit 7-6 (AuthenticityStatus) shall be changed to 0x1 (Authenticity Verification Successful).

SSR-DAI-007Security evidence and traceability — Data Authenticity and Integrity VerificationAD-008componentRFQX-CVS124-0371 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0372SoftwareInstallationStatus shall be formatted according to Table 91.
Statement

SoftwareInstallationStatus shall be formatted according to Table 91.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0372 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0373SoftwareInstallationStatus bit 7-6 (InstallationStatus) shall remain as 0x0 (Installation On-going) until the installation completes.
Statement

SoftwareInstallationStatus bit 7-6 (InstallationStatus) shall remain as 0x0 (Installation On-going) until the installation completes.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0373 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0374Table 91 – SoftwareInstallationStatus Bit Bit Name Bit Values Description 7-6 InstallationStatus 0x0: Installation On-going 0x1: Installation Successful 0x2: Installation Failed 5 - 3 InstallationFailureType 0x0: No Failures 0x1 – 0x7: Project Specific 2 ResetRequired 0x0: Reset not required 0x1: Reset required 1 - 0 Reserved Note: Shall be kept as 0x0 CompletionPercentage shall inform the progress percentage of the software has been installed in the partition memory area.
Statement

Table 91 – SoftwareInstallationStatus Bit Bit Name Bit Values Description 7-6 InstallationStatus 0x0: Installation On-going 0x1: Installation Successful 0x2: Installation Failed 5 - 3 InstallationFailureType 0x0: No Failures 0x1 – 0x7: Project Specific 2 ResetRequired 0x0: Reset not required 0x1: Reset required 1 - 0 Reserved Note: Shall be kept as 0x0 CompletionPercentage shall inform the progress percentage of the software has been installed in the partition memory area.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0374 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0375Information shall be provided in percentage.
Statement

Information shall be provided in percentage.

NoneNoneAD-008componentRFQX-CVS124-0375 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0376TimeRemaningEstimative shall inform the time estimative to complete the installation of the file.
Statement

TimeRemaningEstimative shall inform the time estimative to complete the installation of the file.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0376 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0377Information shall be provided in seconds.
Statement

Information shall be provided in seconds.

NoneNoneAD-008componentRFQX-CVS124-0377 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0378Implementation hint can be seen on Annex B.
Statement

Implementation hint can be seen on Annex B.

NoneNoneNoneNoneRFQX-CVS124-0378 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0379Whereas the result of the dependency check is returned as part of a positive response, a negative response code (NRC) shall be returned if the normal conditions according to (ISO 14229-1) (authentication, service request length, parameter range check etc) for performing the service are not correct.
Statement

Whereas the result of the dependency check is returned as part of a positive response, a negative response code (NRC) shall be returned if the normal conditions according to (ISO 14229-1) (authentication, service request length, parameter range check etc) for performing the service are not correct.

NoneNoneAD-001componentRFQX-CVS124-0379 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0380This RoutineIdentifier value allows the client to start a consistency check of the server and should be able to execute independent from programming sequence.
Statement

This RoutineIdentifier value allows the client to start a consistency check of the server and should be able to execute independent from programming sequence.

NoneNoneAD-002componentRFQX-CVS124-0380 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0381The server shall check whether or not the individual modules are complete and compatible with
Statement

The server shall check whether or not the individual modules are complete and compatible with

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0381 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0382In addition, a check shall be made to determine whether or not the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data).
Statement

In addition, a check shall be made to determine whether or not the software is compatible with the hardware version (e.g., variants of sensors/actuators) and other data structures (e.g., EEPROM data).

NoneNoneAD-001componentRFQX-CVS124-0382 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS124-0383The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer.
Statement

The method used to check compatibility/consistency shall be determined by the supplier in consultation with the vehicle manufacturer.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0383 / 8hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0384The consistency check shall be carried out solely by the server.
Statement

The consistency check shall be carried out solely by the server.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0384 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0385The server shall verify the authenticity and integrity of the software as a part of the consistency check.
Statement

The server shall verify the authenticity and integrity of the software as a part of the consistency check.

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS124-0385 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0386The authenticity and integrity information shall be supplied to the server before the software is updated.
Statement

The authenticity and integrity information shall be supplied to the server before the software is updated.

SSR-DAI-004Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-001componentRFQX-CVS124-0386 / 26hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0387The authenticity and integrity check shall be carried out solely by the server.
Statement

The authenticity and integrity check shall be carried out solely by the server.

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS124-0387 / 18hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0388This routine shall be supported in Programming session.
Statement

This routine shall be supported in Programming session.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0388 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0389The server shall support RoutineControl (CheckProgrammingDependencies) service request formatted according to Table 92.
Statement

The server shall support RoutineControl (CheckProgrammingDependencies) service request formatted according to Table 92.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS124-0389 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0390Table 92 – RoutineIdentifier 0xFF01 description Byte Description Cvt Hex #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0xFF #4 routineIdentifier (LSB) M 0x01 Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported.
Statement

Table 92 – RoutineIdentifier 0xFF01 description Byte Description Cvt Hex #1 RoutineControl Request SID M 0x31 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) M 0xFF #4 routineIdentifier (LSB) M 0x01 Request parameter routineControlType with value 0x03 (requestRoutineResults) shall not be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0390 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0391Positive responses to RoutineControl (CheckProgrammingDependencies) service requests shall be formatted according to Table 93.
Statement

Positive responses to RoutineControl (CheckProgrammingDependencies) service requests shall be formatted according to Table 93.

SSR-UPD-001Secure software update and flash readiness — Software Update / FlashingAD-001componentRFQX-CVS124-0391 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0392Table 93 – RoutineControl (CheckProgrammingDependencies) positive response format #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) checkProgrammingDependencies[byte#1] M 0xFF #4 routineIdentifier (LSB) checkProgrammingDependencies [byte#2] M 0x01 #5 routineStatus routineResult M 0x00-0xFF Parameter routineResult shall adopt one of the values specified in Table 94.
Statement

Table 93 – RoutineControl (CheckProgrammingDependencies) positive response format #1 RoutineControl Response SID M 0x71 #2 routineControlType (StartRoutine) M 0x01 #3 routineIdentifier (MSB) checkProgrammingDependencies[byte#1] M 0xFF #4 routineIdentifier (LSB) checkProgrammingDependencies [byte#2] M 0x01 #5 routineStatus routineResult M 0x00-0xFF Parameter routineResult shall adopt one of the values specified in Table 94.

SSR-UPD-002Secure software update and flash readiness — Software Update / FlashingAD-008componentRFQX-CVS124-0392 / 26hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0393Table 94 – CheckProgrammingDependencies routineStatusRecord results 0x00 correctResult M 0x01 incorrectResult M 0x02 incorrectResult error SW – HW M 0x03 incorrectResult error SW – SW M 0x04 IncorrectResult One or more modules are not programmed or are incorrectly programmed M 0x05 incorrectResult One or more modules failed when verifying the authenticity and integrity of the software M 0x06 – 0xFF Reserved 5.6.4.3 Negative response Whereas the result of the dependency check is returned as part of a positive response, a negative response code (NRC) shall be returned if the normal conditions according to (ISO 14229-1)(authentication, service request length, parameter range check etc) for performing the service are not correct.
Statement

Table 94 – CheckProgrammingDependencies routineStatusRecord results 0x00 correctResult M 0x01 incorrectResult M 0x02 incorrectResult error SW – HW M 0x03 incorrectResult error SW – SW M 0x04 IncorrectResult One or more modules are not programmed or are incorrectly programmed M 0x05 incorrectResult One or more modules failed when verifying the authenticity and integrity of the software M 0x06 – 0xFF Reserved 5.6.4.3 Negative response Whereas the result of the dependency check is returned as part of a positive response, a negative response code (NRC) shall be returned if the normal conditions according to (ISO 14229-1)(authentication, service request length, parameter range check etc) for performing the service are not correct.

NoneNoneAD-001componentRFQX-CVS124-0393 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0394This is an example where the client requests CheckProgrammingDependencies to finalize the validation after software download.
Statement

This is an example where the client requests CheckProgrammingDependencies to finalize the validation after software download.

NoneNoneNoneNoneRFQX-CVS124-0394 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0395The checksum was contained in the data stream programmed to the memory.
Statement

The checksum was contained in the data stream programmed to the memory.

NoneNoneNoneNoneRFQX-CVS124-0395 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0396Table 95 – Example: Request: client → server #1 RoutineControl Request SID 0x31 #2 routineControlType (StartRoutine) 0x01 #3 routineIdentifier byte#1 (checkProgrammingDependencies MSB) 0xFF #4 routineIdentifier byte#2 (checkProgrammingDependencies LSB) 0x01 Example: Positive response: server → client In this example the routine status indicates that the programming dependencies returned correct result.
Statement

Table 95 – Example: Request: client → server #1 RoutineControl Request SID 0x31 #2 routineControlType (StartRoutine) 0x01 #3 routineIdentifier byte#1 (checkProgrammingDependencies MSB) 0xFF #4 routineIdentifier byte#2 (checkProgrammingDependencies LSB) 0x01 Example: Positive response: server → client In this example the routine status indicates that the programming dependencies returned correct result.

NoneNoneNoneNoneRFQX-CVS124-0396 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS124-0397Table 96 – Positive response: server → client #1 RoutineControl Response SID 0x71 #2 routineControlType (StartRoutine) 0x01 #3 routineIdentifier byte#1 (checkProgrammingDependencies MSB) 0xFF #4 routineIdentifier byte#2 (checkProgrammingDependencies LSB) 0x01 #5 routineStatus (routineResult) 0x00 5.6.5 Routine 0xCAFE – EMP The request and response shall be implemented according to CVS33.
Statement

Table 96 – Positive response: server → client #1 RoutineControl Response SID 0x71 #2 routineControlType (StartRoutine) 0x01 #3 routineIdentifier byte#1 (checkProgrammingDependencies MSB) 0xFF #4 routineIdentifier byte#2 (checkProgrammingDependencies LSB) 0x01 #5 routineStatus (routineResult) 0x00 5.6.5 Routine 0xCAFE – EMP The request and response shall be implemented according to CVS33.

SSR-UPD-003Secure software update and flash readiness — Software Update / FlashingAD-002componentRFQX-CVS124-0397 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0398This routine shall be supported in all sessions of Application and Boot.
Statement

This routine shall be supported in all sessions of Application and Boot.

SSR-SYS-003System Function — System FunctionAD-001componentRFQX-CVS124-0398 / 18hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0399Table 97 – Fault memory DTC status bits description Bit Description Cvt 0 testFailed M 1 testFailedThisOperationCycle U 2 pendingDTC M 3 confirmedDTC M 4 testNotCompletedSinceLastClear E 5 testFailedSinceLastClear U 6 testNotCompletedThisOperationCycle M 7 warningIndicatorRequested M
Statement

Table 97 – Fault memory DTC status bits description Bit Description Cvt 0 testFailed M 1 testFailedThisOperationCycle U 2 pendingDTC M 3 confirmedDTC M 4 testNotCompletedSinceLastClear E 5 testFailedSinceLastClear U 6 testNotCompletedThisOperationCycle M 7 warningIndicatorRequested M

NoneNoneNoneNoneRFQX-CVS124-0399 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0400DTC status bits shall not make use of any vehicle manufacturer specific reset condition (e.g.
Statement

DTC status bits shall not make use of any vehicle manufacturer specific reset condition (e.g.

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0400 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0401The occurrence counter is used in DTCExtDataRecords, see section 5.5.10.2.8.
Statement

The occurrence counter is used in DTCExtDataRecords, see section 5.5.10.2.8.

NoneNoneNoneNoneRFQX-CVS124-0401 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0402The occurrence counter minimum value shall be zero (0).
Statement

The occurrence counter minimum value shall be zero (0).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0402 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0403The occurrence counter maximum value shall be 126.
Statement

The occurrence counter maximum value shall be 126.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0403 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0404The occurrence counter default value shall be zero (0).
Statement

The occurrence counter default value shall be zero (0).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0404 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0405The occurrence counter shall increment by one (1) only.
Statement

The occurrence counter shall increment by one (1) only.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0405 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0406The occurrence counter shall increment if it’s value is not at it’s maximum value already.
Statement

The occurrence counter shall increment if it’s value is not at it’s maximum value already.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0406 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0407The occurrence counter shall increment at a change of DTC status bits 0 testFailed and 3 confirmedDTC both from 0 to 1.
Statement

The occurrence counter shall increment at a change of DTC status bits 0 testFailed and 3 confirmedDTC both from 0 to 1.

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0407 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0408The occurrence counter shall increment at a change of DTC status bit 0 testFailed from 0 to 1,
Statement

The occurrence counter shall increment at a change of DTC status bit 0 testFailed from 0 to 1,

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0408 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0409The occurrence counter shall increment at a change of DTC status bit 3 confirmedDTC from 0 to 1, if bit 0 testFailed is 1 already.
Statement

The occurrence counter shall increment at a change of DTC status bit 3 confirmedDTC from 0 to 1, if bit 0 testFailed is 1 already.

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0409 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0410The occurrence counter value 127 shall be defined as "errors with the counter".
Statement

The occurrence counter value 127 shall be defined as "errors with the counter".

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0410 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0411The timestamp of occurrence is used at DTCExtDataRecords, see section 5.5.10.2.8.
Statement

The timestamp of occurrence is used at DTCExtDataRecords, see section 5.5.10.2.8.

NoneNoneNoneNoneRFQX-CVS124-0411 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0412The timestamp default value shall be a 0xFF in each data.
Statement

The timestamp default value shall be a 0xFF in each data.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0412 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0413The timestamp is presented in SAE J1939-71 format without local hour/minute offsets.
Statement

The timestamp is presented in SAE J1939-71 format without local hour/minute offsets.

NoneNoneNoneNoneRFQX-CVS124-0413 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0414In SAE J1939-71 section “PGN 65254 Time/Date”, the following format is specified: Table 98 – J1939-71 timestamp format Byte No Length Name Resolutio n Offset Note 1 1 byte Seconds 0.25 s/bit 0 2 1 byte Minutes 1 min/bit 0 3 1 byte Hours 1 hr/bit 0 4 1 byte Month 1 month/bit 0 Value 1 identifies January, value 2 identifies February and so on 5 1 byte Day 0.25 days/bit 0 Values 1,2,3 and 4 identifes first day of month, value 5,6,7,8 identifies second day of month and so on 6 1 byte Year 1 year/bit 1985 Value of 0 identifies year 1985, value of 1 identifes year 1986 and so on 7 1 byte Local minute offset 1 min/bit -125 Not used in DTC timestamps 8 1 byte Local hour offset 1 hr/bit -125 Not used in DTC timestamps
Statement

In SAE J1939-71 section “PGN 65254 Time/Date”, the following format is specified: Table 98 – J1939-71 timestamp format Byte No Length Name Resolutio n Offset Note 1 1 byte Seconds 0.25 s/bit 0 2 1 byte Minutes 1 min/bit 0 3 1 byte Hours 1 hr/bit 0 4 1 byte Month 1 month/bit 0 Value 1 identifies January, value 2 identifies February and so on 5 1 byte Day 0.25 days/bit 0 Values 1,2,3 and 4 identifes first day of month, value 5,6,7,8 identifies second day of month and so on 6 1 byte Year 1 year/bit 1985 Value of 0 identifies year 1985, value of 1 identifes year 1986 and so on 7 1 byte Local minute offset 1 min/bit -125 Not used in DTC timestamps 8 1 byte Local hour offset 1 hr/bit -125 Not used in DTC timestamps

NoneNoneNoneNoneRFQX-CVS124-0414 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0415The latest occurrence shall be updated at a change of DTC status bits 0 (testFailed) and 3
Statement

The latest occurrence shall be updated at a change of DTC status bits 0 (testFailed) and 3

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0415 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0416The latest occurrence shall be updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already.
Statement

The latest occurrence shall be updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already.

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0416 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0417If occurrence counter is set to 1, the timestamp of the latest occurrence shall be set to 0xFF.
Statement

If occurrence counter is set to 1, the timestamp of the latest occurrence shall be set to 0xFF.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0417 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0418The first occurrence shall be updated at the first change of DTC status bits 0 (testFailed) and 3 5.7.4 Vehicle distance at occurrence
Statement

The first occurrence shall be updated at the first change of DTC status bits 0 (testFailed) and 3 5.7.4 Vehicle distance at occurrence

SSR-DIAG-003Diagnostic Services — Diagnostic ServicesAD-008componentRFQX-CVS124-0418 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0419The total vehicle distance at occurrence is used in DTCExtDataRecords, see section 5.5.10.2.8.
Statement

The total vehicle distance at occurrence is used in DTCExtDataRecords, see section 5.5.10.2.8.

NoneNoneNoneNoneRFQX-CVS124-0419 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0420The vehicle distance shall be represented by a four byte integer, big endian, with five meter per bit (5m/bit).
Statement

The vehicle distance shall be represented by a four byte integer, big endian, with five meter per bit (5m/bit).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0420 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0421If all sources of vehicle distance information present no current data, the distance information shall be set to 0xFF at all bytes.
Statement

If all sources of vehicle distance information present no current data, the distance information shall be set to 0xFF at all bytes.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0421 / 8hNot importedNo linked clarificationNo P1 linkevidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0422The latest distance value is updated at a change of DTC status bits 0 (testFailed) and 3
Statement

The latest distance value is updated at a change of DTC status bits 0 (testFailed) and 3

NoneNoneNoneNoneRFQX-CVS124-0422 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0423The latest distance value is updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already.
Statement

The latest distance value is updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already.

NoneNoneNoneNoneRFQX-CVS124-0423 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0424The first distance value is updated at the first change of DTC status bits 0 (testFailed) and 3
Statement

The first distance value is updated at the first change of DTC status bits 0 (testFailed) and 3

NoneNoneNoneNoneRFQX-CVS124-0424 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0425The operational hours at occurrence is used at DTCExtDataRecords, see section 5.5.10.2.8.
Statement

The operational hours at occurrence is used at DTCExtDataRecords, see section 5.5.10.2.8.

NoneNoneNoneNoneRFQX-CVS124-0425 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0426The operational hours are presented by a four byte integer, big endian, with , half second per bit (0,5s/bit).
Statement

The operational hours are presented by a four byte integer, big endian, with , half second per bit (0,5s/bit).

NoneNoneNoneNoneRFQX-CVS124-0426 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0427If all sources of operational hours information present no current data, the operational hours information shall be set to 0xFF at all bytes.
Statement

If all sources of operational hours information present no current data, the operational hours information shall be set to 0xFF at all bytes.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0427 / 8hNot importedNo linked clarificationNo P1 linkevidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0428The latest operational hours value is updated at a change of DTC status bits 0 (testFailed) and 3 (confirmedDTC) both from 0 to 1.
Statement

The latest operational hours value is updated at a change of DTC status bits 0 (testFailed) and 3 (confirmedDTC) both from 0 to 1.

NoneNoneNoneNoneRFQX-CVS124-0428 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0429The latest operational hours value is updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already.
Statement

The latest operational hours value is updated at a change of DTC status bit 0 (testFailed) from 0 to 1, if bit 3 (confirmedDTC) is 1 already.

NoneNoneNoneNoneRFQX-CVS124-0429 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0430The first operational hours value is updated at the first change of DTC status bits 0 (testFailed) and 3 (confirmedDTC) both from 0 to 1.
Statement

The first operational hours value is updated at the first change of DTC status bits 0 (testFailed) and 3 (confirmedDTC) both from 0 to 1.

NoneNoneNoneNoneRFQX-CVS124-0430 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0431The server shall be available for complete diagnostic communication within two seconds after a power on.
Statement

The server shall be available for complete diagnostic communication within two seconds after a power on.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS124-0431 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0432If diagnostic data is not available in time the ECU should respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) for maximum allowed time.
Statement

If diagnostic data is not available in time the ECU should respond with NRC 0x78 (requestCorrectlyReceived-ResponsePending) for maximum allowed time.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS124-0432 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0433for Linux based systems still running in boot, the server should indicate with DID 0xF1AD that it is running in boot.
Statement

for Linux based systems still running in boot, the server should indicate with DID 0xF1AD that it is running in boot.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS124-0433 / 56hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0434For P2Server, the minimum value shall be 0 ms, a maximum value shall be 50 ms.
Statement

For P2Server, the minimum value shall be 0 ms, a maximum value shall be 50 ms.

SSR-TOOL-004Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-008componentRFQX-CVS124-0434 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0435For P2Client, a value of 150 ms shall be used.
Statement

For P2Client, a value of 150 ms shall be used.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS124-0435 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0436For P2*Server, the minimum value shall be 0ms, the maximum value shall be 4000ms.
Statement

For P2*Server, the minimum value shall be 0ms, the maximum value shall be 4000ms.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS124-0436 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0437For P2*Client, the value estimation given in ISO 14229-2 shall be used.
Statement

For P2*Client, the value estimation given in ISO 14229-2 shall be used.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS124-0437 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS124-0438The value for P4_Server_max shall be maximum 30 seconds.
Statement

The value for P4_Server_max shall be maximum 30 seconds.

SSR-TOOL-004Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-008componentRFQX-CVS124-0438 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0439The system supplier shall document the implemented value for P4_Server_max.
Statement

The system supplier shall document the implemented value for P4_Server_max.

SSR-TOOL-004Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-008componentRFQX-CVS124-0439 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS124-0440F197 structure added
Statement

F197 structure added

NoneNoneNoneNoneRFQX-CVS124-0440 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0441F198 Request and response format
Statement

F198 Request and response format

NoneNoneNoneNoneRFQX-CVS124-0441 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0442F199 Request and response format
Statement

F199 Request and response format

NoneNoneNoneNoneRFQX-CVS124-0442 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0443F19A Request and response format
Statement

F19A Request and response format

NoneNoneNoneNoneRFQX-CVS124-0443 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0444NRC for RBACC check failures
Statement

NRC for RBACC check failures

NoneNoneNoneNoneRFQX-CVS124-0444 / 5hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0445,
Statement

,

NoneNoneNoneNoneRFQX-CVS124-0445 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0446,
Statement

,

NoneNoneNoneNoneRFQX-CVS124-0446 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0447,
Statement

,

NoneNoneNoneNoneRFQX-CVS124-0447 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0448,
Statement

,

NoneNoneNoneNoneRFQX-CVS124-0448 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0449,
Statement

,

NoneNoneNoneNoneRFQX-CVS124-0449 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0450,
Statement

,

NoneNoneNoneNoneRFQX-CVS124-0450 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0451Requirements, Request and response formats for the ControlDTCSetting(0x85) added.
Statement

Requirements, Request and response formats for the ControlDTCSetting(0x85) added.

NoneNoneNoneNoneRFQX-CVS124-0451 / 16hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0452Added semantic Identifier DIDs, changed the NodeUID DID to INTERNAL
Statement

Added semantic Identifier DIDs, changed the NodeUID DID to INTERNAL

NoneNoneNoneNoneRFQX-CVS124-0452 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0453Change in the length of NodeUID(0xF1AF)
Statement

Change in the length of NodeUID(0xF1AF)

NoneNoneNoneNoneRFQX-CVS124-0453 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0454Change in the retrieval method for NodeUID(0xF1AF)
Statement

Change in the retrieval method for NodeUID(0xF1AF)

NoneNoneNoneNoneRFQX-CVS124-0454 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-04550xF1B9 RBACCIdentifierNumber is changed to Mandatory
Statement

0xF1B9 RBACCIdentifierNumber is changed to Mandatory

NoneNoneNoneNoneRFQX-CVS124-0455 / 18hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-04560xF1BA RBACCStructureVersion,bit-length changed
Statement

0xF1BA RBACCStructureVersion,bit-length changed

NoneNoneNoneNoneRFQX-CVS124-0456 / 18hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0457Changes for service (0x84) and (0x31)
Statement

Changes for service (0x84) and (0x31)

NoneNoneNoneNoneRFQX-CVS124-0457 / 18hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS124-0458Updated the document references
Statement

Updated the document references

NoneNoneNoneNoneRFQX-CVS124-0458 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-04590XCAFE and 0xFF02 are updated to Mandatory
Statement

0XCAFE and 0xFF02 are updated to Mandatory

NoneNoneNoneNoneRFQX-CVS124-0459 / 26hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS124-0460Modifcations on the bit values and new bit added
Statement

Modifcations on the bit values and new bit added

NoneNoneNoneNoneRFQX-CVS124-0460 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-04610x05 is changed to Mandatory 6 Normative references: Updated the referenced documents and versions Removed Requirements and infos
Statement

0x05 is changed to Mandatory 6 Normative references: Updated the referenced documents and versions Removed Requirements and infos

NoneNoneNoneNoneRFQX-CVS124-0461 / 26hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS124-0462(0x86) service removed
Statement

(0x86) service removed

NoneNoneNoneNoneRFQX-CVS124-0462 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0463,
Statement

,

NoneNoneNoneNoneRFQX-CVS124-0463 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-0464Removed the reserved DID ranges and 0xF1C1
Statement

Removed the reserved DID ranges and 0xF1C1

NoneNoneNoneNoneRFQX-CVS124-0464 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS124-04650xF19E ODXFileDataIdentifier is removed 2024-10 First issue
Statement

0xF19E ODXFileDataIdentifier is removed 2024-10 First issue

NoneNoneNoneNoneRFQX-CVS124-0465 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0001RBAC for diagnostics Foreword This Commercial Vehicle Standard (“CVS151”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.
Statement

RBAC for diagnostics Foreword This Commercial Vehicle Standard (“CVS151”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.

NoneNoneNoneNoneRFQX-CVS151-0001 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0002Any review of this CVS151 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.
Statement

Any review of this CVS151 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.

NoneNoneAD-003componentRFQX-CVS151-0002 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS151-0003The User shall apply the latest version of this CVS151.
Statement

The User shall apply the latest version of this CVS151.

NoneNoneAD-008componentRFQX-CVS151-0003 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS151-00041 Scope Concepts such as secure-update (CVS37) requires Role Based Access Control (RBAC) for diagnostics (UDS).
Statement

1 Scope Concepts such as secure-update (CVS37) requires Role Based Access Control (RBAC) for diagnostics (UDS).

NoneNoneAD-007componentRFQX-CVS151-0004 / 56hNot importedNo linked clarificationNo P1 linkboundary ownership; boot/update trust; diagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS151-00053 Technical content 3.1 Overview Server/ECUClient/tester UDS Authorize OK/NOTOK UDS request Is the request allowed, based on the client's access rights i.e., compare the client's role/s against the RBACCOK/NOTOK Figure 1 – Overview Figure 1 shows a highlevel view of the RBAC concept.
Statement

3 Technical content 3.1 Overview Server/ECUClient/tester UDS Authorize OK/NOTOK UDS request Is the request allowed, based on the client's access rights i.e., compare the client's role/s against the RBACCOK/NOTOK Figure 1 – Overview Figure 1 shows a highlevel view of the RBAC concept.

NoneNoneNoneNoneRFQX-CVS151-0005 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0006Before a client can execute diagnostics services that are under RBAC, the client must perform some type of authorization procedure towards the server/ECU.
Statement

Before a client can execute diagnostics services that are under RBAC, the client must perform some type of authorization procedure towards the server/ECU.

NoneNoneAD-006componentRFQX-CVS151-0006 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS151-0007The RBAC logic is typically part of the ECU application- and boot-software.
Statement

The RBAC logic is typically part of the ECU application- and boot-software.

NoneNoneNoneNoneRFQX-CVS151-0007 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0008The RBACC is typically injected into the ECU during production, using a secure protocol.
Statement

The RBACC is typically injected into the ECU during production, using a secure protocol.

NoneNoneNoneNoneRFQX-CVS151-0008 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0009As previously mentioned, each ECU (supporting RBAC) will be programmed with an RBACC, RBAC Configuration, containing the rules to drive the RBAC logic.
Statement

As previously mentioned, each ECU (supporting RBAC) will be programmed with an RBACC, RBAC Configuration, containing the rules to drive the RBAC logic.

NoneNoneNoneNoneRFQX-CVS151-0009 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0010The RBACC contains one or several role-configurations (see Figure 2 for a visual representation).
Statement

The RBACC contains one or several role-configurations (see Figure 2 for a visual representation).

NoneNoneNoneNoneRFQX-CVS151-0010 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0011Each RBACC shall only contain one role-configuration per each supported role.
Statement

Each RBACC shall only contain one role-configuration per each supported role.

SSR-RBAC-005Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-008componentRFQX-CVS151-0011 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0012The Role field (in the RBACC) can be seen as a key in a dictionary, which means, two role- configurations cannot contain the same Role value.
Statement

The Role field (in the RBACC) can be seen as a key in a dictionary, which means, two role- configurations cannot contain the same Role value.

NoneNoneNoneNoneRFQX-CVS151-0012 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0013A role-configuration, in its turn, contains one or many rules (see Figure 2 for a visual representation).
Statement

A role-configuration, in its turn, contains one or many rules (see Figure 2 for a visual representation).

NoneNoneNoneNoneRFQX-CVS151-0013 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0014If conflicting/overlapping rules are found within a role-configuration, the server shall enforce that deny rule takes precedence over the allow rule.
Statement

If conflicting/overlapping rules are found within a role-configuration, the server shall enforce that deny rule takes precedence over the allow rule.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0014 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0015Each rule can be of either DENY or ALLOW type.
Statement

Each rule can be of either DENY or ALLOW type.

NoneNoneNoneNoneRFQX-CVS151-0015 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0016If a matching allow/deny rule is found and all the rule settings are fulfilled, the server shall accept/deny the request.
Statement

If a matching allow/deny rule is found and all the rule settings are fulfilled, the server shall accept/deny the request.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0016 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0017Considering all the rule setting fulfilled, for matching rules of allow type the server will accept the request and for matching rules of deny type the server will deny the request.
Statement

Considering all the rule setting fulfilled, for matching rules of allow type the server will accept the request and for matching rules of deny type the server will deny the request.

NoneNoneNoneNoneRFQX-CVS151-0017 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0018If a matching rule is found and not all the rule settings are fulfilled, the server shall consider the request rejected for that rule.
Statement

If a matching rule is found and not all the rule settings are fulfilled, the server shall consider the request rejected for that rule.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0018 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0019The server shall deny a request if no matching rule is found on RBACC.
Statement

The server shall deny a request if no matching rule is found on RBACC.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0019 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0020All RBACC ALLOW rules have a setting that dictates if a request, matching the rule, must be 14229-1:2020).
Statement

All RBACC ALLOW rules have a setting that dictates if a request, matching the rule, must be 14229-1:2020).

NoneNoneAD-008componentRFQX-CVS151-0020 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS151-0021Examples of rules within a single role and their expected behaviour: Example 1: A rule in the RBACC states that a role can execute ReadDataByIdentifier 0x22 (see ISO-14229-1:2020) with Confidentiality off.
Statement

Examples of rules within a single role and their expected behaviour: Example 1: A rule in the RBACC states that a role can execute ReadDataByIdentifier 0x22 (see ISO-14229-1:2020) with Confidentiality off.

NoneNoneNoneNoneRFQX-CVS151-0021 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0022The RBAC logic is based on an implicit deny principle; meaning, if the RBACC does not explicitly state that a diagnostic request is allowed or denied, then the request is implicitly denied.
Statement

The RBAC logic is based on an implicit deny principle; meaning, if the RBACC does not explicitly state that a diagnostic request is allowed or denied, then the request is implicitly denied.

NoneNoneNoneNoneRFQX-CVS151-0022 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0023The server shall evaluate each role-configuration independently from each other.
Statement

The server shall evaluate each role-configuration independently from each other.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0023 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0024If conflicting/overlapping rules are found among multiple role-configuration, the server accepts the request as long within one role-configuration the request is allowed.
Statement

If conflicting/overlapping rules are found among multiple role-configuration, the server accepts the request as long within one role-configuration the request is allowed.

NoneNoneNoneNoneRFQX-CVS151-0024 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0025Examples of two roles with overlapping rules and their expected behaviour: Example 5: The RBACC contains two roles with rules that states how the role can execute ReadDataByIdentifier 0x22 (see ISO-14229-1:2020).
Statement

Examples of two roles with overlapping rules and their expected behaviour: Example 5: The RBACC contains two roles with rules that states how the role can execute ReadDataByIdentifier 0x22 (see ISO-14229-1:2020).

NoneNoneNoneNoneRFQX-CVS151-0025 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0026If a client/tester has been assigned several roles (i.e., several role-configurations in the RBACC are applicable for the client/tester), and at least one of the applicable role-configuration explicitly allows a particular request, then the request is allowed, regardless of if another applicable role-configuration explicitly denies it.
Statement

If a client/tester has been assigned several roles (i.e., several role-configurations in the RBACC are applicable for the client/tester), and at least one of the applicable role-configuration explicitly allows a particular request, then the request is allowed, regardless of if another applicable role-configuration explicitly denies it.

NoneNoneNoneNoneRFQX-CVS151-0026 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0027See Annex B for a more detailed example of RBACC.
Statement

See Annex B for a more detailed example of RBACC.

NoneNoneNoneNoneRFQX-CVS151-0027 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0028The server shall require that requests are authenticated for allow rules, using e.g., SecuredDataTransmission 0x84 (see CVS31, ISO-14229-1:2020).
Statement

The server shall require that requests are authenticated for allow rules, using e.g., SecuredDataTransmission 0x84 (see CVS31, ISO-14229-1:2020).

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0028 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0029Allow rules defined in role 0 are an exception to this requirement, see 3.13.
Statement

Allow rules defined in role 0 are an exception to this requirement, see 3.13.

NoneNoneNoneNoneRFQX-CVS151-0029 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0030The server and client shall define the RBACC as per the following ASN.1 definition: RBACC ::= SEQUENCE { version OCTET STRING (SIZE(2)), rbacc-id OCTET STRING (SIZE(16)), role-configurations SEQUENCE (SIZE(0..MAX)) OF Role-configuration } Role-configuration ::= SEQUENCE { role INTEGER(0..MAX), pattern-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), pattern-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), did-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), did-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)) }
Statement

The server and client shall define the RBACC as per the following ASN.1 definition: RBACC ::= SEQUENCE { version OCTET STRING (SIZE(2)), rbacc-id OCTET STRING (SIZE(16)), role-configurations SEQUENCE (SIZE(0..MAX)) OF Role-configuration } Role-configuration ::= SEQUENCE { role INTEGER(0..MAX), pattern-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), pattern-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), did-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), did-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)) }

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0030 / 19hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0031The version specifies the structure of RBACC.
Statement

The version specifies the structure of RBACC.

NoneNoneNoneNoneRFQX-CVS151-0031 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0032The server shall support in the version field two octets.
Statement

The server shall support in the version field two octets.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0032 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0033The server shall support major version value 3 and minor version value 0.
Statement

The server shall support major version value 3 and minor version value 0.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0033 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0034If other versions shall be supported is out of the scope of this document and shall be agreed upon between projects in Traton.
Statement

If other versions shall be supported is out of the scope of this document and shall be agreed upon between projects in Traton.

NoneNoneAD-008componentRFQX-CVS151-0034 / 24hNot importedNo linked clarificationNo P1 linkboundary ownershipNo closure evidence requiredCOMPLETE
RFQX-CVS151-0035Before RBACC is stored, the server shall verify that the server supports the structure indicated in the version number.
Statement

Before RBACC is stored, the server shall verify that the server supports the structure indicated in the version number.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0035 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0036If the version number does not comply with the server implementation, the server shall reject storing the data.
Statement

If the version number does not comply with the server implementation, the server shall reject storing the data.

NoneNoneAD-002componentRFQX-CVS151-0036 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS151-0037The server shall report the currently stored RBACC’s version via diagnostics.
Statement

The server shall report the currently stored RBACC’s version via diagnostics.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0037 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0038See RBACStructureVersion definition in CVS124.
Statement

See RBACStructureVersion definition in CVS124.

NoneNoneNoneNoneRFQX-CVS151-0038 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0039This field identifies the RBACC using 16 octets.
Statement

This field identifies the RBACC using 16 octets.

NoneNoneNoneNoneRFQX-CVS151-0039 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0040The server shall support 16 octets in the rbacc-id field.
Statement

The server shall support 16 octets in the rbacc-id field.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0040 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0041The server shall report the currently stored RBACC’s rbacc-id via diagnostics.
Statement

The server shall report the currently stored RBACC’s rbacc-id via diagnostics.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0041 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0042See RBACIdentifierNumber definition in CVS124.
Statement

See RBACIdentifierNumber definition in CVS124.

NoneNoneNoneNoneRFQX-CVS151-0042 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0043A 32-bit unsigned integer that represents one role.
Statement

A 32-bit unsigned integer that represents one role.

NoneNoneNoneNoneRFQX-CVS151-0043 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0044The server shall support role-configurations using 32-bit unsigned integer.
Statement

The server shall support role-configurations using 32-bit unsigned integer.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0044 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0045The server shall support for every entry in the pattern-rules one octet for the pattern rule settings followed by the diagnostic pattern of variable length.
Statement

The server shall support for every entry in the pattern-rules one octet for the pattern rule settings followed by the diagnostic pattern of variable length.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS151-0045 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0046The diagnostic pattern identifies the diagnostic request.
Statement

The diagnostic pattern identifies the diagnostic request.

NoneNoneNoneNoneRFQX-CVS151-0046 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0047This type of rule can be used to create rules for all types of diagnostic requests.
Statement

This type of rule can be used to create rules for all types of diagnostic requests.

NoneNoneNoneNoneRFQX-CVS151-0047 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0048The server shall support the pattern-rule setting according to Table 1.
Statement

The server shall support the pattern-rule setting according to Table 1.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0048 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0049Table 1 – Pattern Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.
Statement

Table 1 – Pattern Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.

NoneNoneAD-002componentRFQX-CVS151-0049 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS151-0050The server shall support for every entry in the did-rules one octet which represents the did-rule settings followed by two octets that represent the DID.
Statement

The server shall support for every entry in the did-rules one octet which represents the did-rule settings followed by two octets that represent the DID.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0050 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0051The byte order for DID shall be big endian.
Statement

The byte order for DID shall be big endian.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS151-0051 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS151-0052This type of rule can be used to create rules for all types of diagnostic requests that makes use of DIDs e.g., ReadDataByIdentifier, WriteDataByIdentifier, DynamicallyDefineDataIdentifier (see ISO 14429-1:2020) etc.
Statement

This type of rule can be used to create rules for all types of diagnostic requests that makes use of DIDs e.g., ReadDataByIdentifier, WriteDataByIdentifier, DynamicallyDefineDataIdentifier (see ISO 14429-1:2020) etc.

NoneNoneNoneNoneRFQX-CVS151-0052 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0053The server shall support the did-rule setting according to Table 2.
Statement

The server shall support the did-rule setting according to Table 2.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0053 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0054Table 2 – DID Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.
Statement

Table 2 – DID Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.

NoneNoneAD-002componentRFQX-CVS151-0054 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS151-00554 Read 0 == This rule is not applicable when the DID is being read 1 == This rule is applicable when the DID is being read 5 Write 0 == This rule is not applicable when the DID is being written 1 == This rule is applicable when the DID is being written 6 IO-control 0 == This rule is not applicable when the DID is being used for IO-control 1 == This rule is applicable when the DID is being used for IO-control 7 N/A Reserved for future use 3.9 rid-rules The server shall support for every entry in the rid-rules one octet which represents the rid-rule settings followed by two octets that represent the RID.
Statement

4 Read 0 == This rule is not applicable when the DID is being read 1 == This rule is applicable when the DID is being read 5 Write 0 == This rule is not applicable when the DID is being written 1 == This rule is applicable when the DID is being written 6 IO-control 0 == This rule is not applicable when the DID is being used for IO-control 1 == This rule is applicable when the DID is being used for IO-control 7 N/A Reserved for future use 3.9 rid-rules The server shall support for every entry in the rid-rules one octet which represents the rid-rule settings followed by two octets that represent the RID.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0055 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0056This type of rule can be used to create rules for all types of diagnostic requests that makes use of RIDs.
Statement

This type of rule can be used to create rules for all types of diagnostic requests that makes use of RIDs.

NoneNoneNoneNoneRFQX-CVS151-0056 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0057The server shall support the rid-rule setting according to Table 3.
Statement

The server shall support the rid-rule setting according to Table 3.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0057 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0058Table 3 – RID Rule Setting Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.
Statement

Table 3 – RID Rule Setting Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.

NoneNoneAD-002componentRFQX-CVS151-0058 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS151-00594 Start 0 == This rule is not applicable when the RID is being started 1 == This rule is applicable when the RID is being started 5 Stop 0 == This rule is not applicable when the RID is being stopped 1 == This rule is applicable when the RID is being stopped 6 Read-results 0 == This rule is not applicable when the RID results are being read 1 == This rule is applicable when the RID results are being read 7 N/A Reserved for future use 3.10 Extending the Role Based Access Control Configuration using a certificate It is possible to extend the rules (in the RBACC), by including an extension in the user’s/client’s certificate (when certificate-based authorization is being used).
Statement

4 Start 0 == This rule is not applicable when the RID is being started 1 == This rule is applicable when the RID is being started 5 Stop 0 == This rule is not applicable when the RID is being stopped 1 == This rule is applicable when the RID is being stopped 6 Read-results 0 == This rule is not applicable when the RID results are being read 1 == This rule is applicable when the RID results are being read 7 N/A Reserved for future use 3.10 Extending the Role Based Access Control Configuration using a certificate It is possible to extend the rules (in the RBACC), by including an extension in the user’s/client’s certificate (when certificate-based authorization is being used).

NoneNoneNoneNoneRFQX-CVS151-0059 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0060If conflicting/overlapping rules are found between the client certificate D-RBACC extension and any rules in the RBAC-configuration in the RBACC, the server shall enforce the rules in the client certificate D-RBACC extension.
Statement

If conflicting/overlapping rules are found between the client certificate D-RBACC extension and any rules in the RBAC-configuration in the RBACC, the server shall enforce the rules in the client certificate D-RBACC extension.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS151-0060 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0061A snippet from https://datatracker.ietf.org/doc/html/rfc5280#section-4.1 that specifies the layout of a certificate extension.
Statement

A snippet from https://datatracker.ietf.org/doc/html/rfc5280#section-4.1 that specifies the layout of a certificate extension.

NoneNoneNoneNoneRFQX-CVS151-0061 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0062The server shall interpret the extnValue (see snipped above) as of one instance of a RBACC (see 3.3).
Statement

The server shall interpret the extnValue (see snipped above) as of one instance of a RBACC (see 3.3).

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0062 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0063Inside the extnValue (see snipped above) is one instance of a RBACC (see 3.3).
Statement

Inside the extnValue (see snipped above) is one instance of a RBACC (see 3.3).

NoneNoneNoneNoneRFQX-CVS151-0063 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0064This feature can be particularly useful if you want to create a custom rule-set (which does not map to a role-configuration in the RBACC) for a client/tester without assigning him/her a specific role.
Statement

This feature can be particularly useful if you want to create a custom rule-set (which does not map to a role-configuration in the RBACC) for a client/tester without assigning him/her a specific role.

NoneNoneNoneNoneRFQX-CVS151-0064 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0065It can also be useful if you want to add or remove access rights from a client/tester, that needs access to one or several roles, but should not have access to everything (or should have more access) specified for the assigned roles.
Statement

It can also be useful if you want to add or remove access rights from a client/tester, that needs access to one or several roles, but should not have access to everything (or should have more access) specified for the assigned roles.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS151-0065 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0066The server shall exert the RBACC roles based on the ECU-diagnostics-Role extension on the client’s certificate.
Statement

The server shall exert the RBACC roles based on the ECU-diagnostics-Role extension on the client’s certificate.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS151-0066 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0067Figure 3 shows the interaction between the diagnostics server and the RBAC enforcer logic.
Statement

Figure 3 shows the interaction between the diagnostics server and the RBAC enforcer logic.

NoneNoneNoneNoneRFQX-CVS151-0067 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0068The server shall implement RBAC internal logic as per Figure 4.
Statement

The server shall implement RBAC internal logic as per Figure 4.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS151-0068 / 19hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0069As previously stated and as show in Figure 4, deny rules takes precedence over allow rules.
Statement

As previously stated and as show in Figure 4, deny rules takes precedence over allow rules.

NoneNoneNoneNoneRFQX-CVS151-0069 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0070The RBAC logic starts the process of finding out if the client has a certificate (that extends the RBAC, see 3.10) and/or any exerted roles.
Statement

The RBAC logic starts the process of finding out if the client has a certificate (that extends the RBAC, see 3.10) and/or any exerted roles.

NoneNoneNoneNoneRFQX-CVS151-0070 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0071The server shall implement RBAC pattern rule evaluation logic as per Figure 5.
Statement

The server shall implement RBAC pattern rule evaluation logic as per Figure 5.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS151-0071 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0072The “request.conditions COMPLIES_WITH rule.settings” refers to evaluate if the request conditions fulfils the expected rule settings.
Statement

The “request.conditions COMPLIES_WITH rule.settings” refers to evaluate if the request conditions fulfils the expected rule settings.

NoneNoneNoneNoneRFQX-CVS151-0072 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0073E.g: For the evaluate pattern the rule setting Confidentiality is set to 0x01 (Confidentiality is required).
Statement

E.g: For the evaluate pattern the rule setting Confidentiality is set to 0x01 (Confidentiality is required).

NoneNoneAD-008componentRFQX-CVS151-0073 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS151-0074The server shall implement RBAC did rule evaluate as per Figure 6.
Statement

The server shall implement RBAC did rule evaluate as per Figure 6.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0074 / 19hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0075The server shall implement RBAC rid rule evaluate as per Figure 7.
Statement

The server shall implement RBAC rid rule evaluate as per Figure 7.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0075 / 19hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0076In Figure 8, the RBAC complete rule evaluation logic is described.
Statement

In Figure 8, the RBAC complete rule evaluation logic is described.

NoneNoneNoneNoneRFQX-CVS151-0076 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0077The role-configuration containing Role 0 is special, it specifies rules that apply to all clients (regardless of whether the client has been assigned a diagnostics role or not).
Statement

The role-configuration containing Role 0 is special, it specifies rules that apply to all clients (regardless of whether the client has been assigned a diagnostics role or not).

NoneNoneNoneNoneRFQX-CVS151-0077 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0078Meaning, role 0 is particularly useful for defining services, DIDs and RIDs that should be available to all clients/users, regardless of their diagnostics role and/or authorization/authentication status.
Statement

Meaning, role 0 is particularly useful for defining services, DIDs and RIDs that should be available to all clients/users, regardless of their diagnostics role and/or authorization/authentication status.

SSR-RBAC-005Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-008componentRFQX-CVS151-0078 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0079The server shall allow requests that are contained in role 0 rules regardless of the client authentication state.
Statement

The server shall allow requests that are contained in role 0 rules regardless of the client authentication state.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0079 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0080The server shall allow request that are contained in role 0 rule regardless if the request is data authenticated e.g over e.g., SecuredDataTransmission 0x84 (See CVS31, ISO 14229-1:2020).
Statement

The server shall allow request that are contained in role 0 rule regardless if the request is data authenticated e.g over e.g., SecuredDataTransmission 0x84 (See CVS31, ISO 14229-1:2020).

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0080 / 19hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0081The server shall allow request that are contained in role 0 rule regardless of the value of Confidentiality field setting.
Statement

The server shall allow request that are contained in role 0 rule regardless of the value of Confidentiality field setting.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS151-0081 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0082This means that in role 0 encryption is never required.
Statement

This means that in role 0 encryption is never required.

NoneNoneAD-008componentRFQX-CVS151-0082 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS151-0083The server shall always allow reception of UDS authenticate 0x29 requests regardless of the RBACC settings.
Statement

The server shall always allow reception of UDS authenticate 0x29 requests regardless of the RBACC settings.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS151-0083 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0084For 0x29 requests a corresponding matching rule in the RBACC is not required for the server to accept the request.
Statement

For 0x29 requests a corresponding matching rule in the RBACC is not required for the server to accept the request.

NoneNoneAD-002componentRFQX-CVS151-0084 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS151-0085The server shall evaluate the reported internal service using the RBACC rules whenever it receives a UDS Service 0x84 requests.
Statement

The server shall evaluate the reported internal service using the RBACC rules whenever it receives a UDS Service 0x84 requests.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS151-0085 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0086The server shall always allow reception of UDS SecuredDataTransmission 0x84 requests regardless of the RBACC settings.
Statement

The server shall always allow reception of UDS SecuredDataTransmission 0x84 requests regardless of the RBACC settings.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0086 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0087For 0x84 requests a corresponding matching rule in the RBACC is not required for the server to accept the 0x84 request but the server must find a corresponding matching rule for the internal request contained in the 0x84 prior to execute it.
Statement

For 0x84 requests a corresponding matching rule in the RBACC is not required for the server to accept the 0x84 request but the server must find a corresponding matching rule for the internal request contained in the 0x84 prior to execute it.

NoneNoneAD-002componentRFQX-CVS151-0087 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS151-0088The server shall always allow reception of UDS TesterPresent 0x3E requests regardless of the RBACC settings.
Statement

The server shall always allow reception of UDS TesterPresent 0x3E requests regardless of the RBACC settings.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS151-0088 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS151-0089For 0x3E requests a corresponding matching rule in the RBACC is not required for the server to accept the request.
Statement

For 0x3E requests a corresponding matching rule in the RBACC is not required for the server to accept the request.

NoneNoneAD-002componentRFQX-CVS151-0089 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS151-0090Refreshing the S3 timer (see CVS124), e.g., using TesterPresent (0x3E) (see CVS37), is always possible to do outside the secure channel and regardless of the settings in the RBACC role configuration.
Statement

Refreshing the S3 timer (see CVS124), e.g., using TesterPresent (0x3E) (see CVS37), is always possible to do outside the secure channel and regardless of the settings in the RBACC role configuration.

NoneNoneNoneNoneRFQX-CVS151-0090 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS151-0091Annex D DynamicallyDefineDataIdentifier When this service is being used, each DID included in the request must be evaluated against the rules that are applicable for the client (the rules in the client’s certificate and in the RBACC).
Statement

Annex D DynamicallyDefineDataIdentifier When this service is being used, each DID included in the request must be evaluated against the rules that are applicable for the client (the rules in the client’s certificate and in the RBACC).

NoneNoneAD-007componentRFQX-CVS151-0091 / 56hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposureNo closure evidence requiredCOMPLETE
RFQX-CVS151-0092The client must have read access for all included DIDs and have access to the service themselves.
Statement

The client must have read access for all included DIDs and have access to the service themselves.

NoneNoneAD-001componentRFQX-CVS151-0092 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS151-0093When the client is performing the actual read operation (ReadDataByIdentifier [7]), the conditions and rules for all DIDs, aliased by the dynamically defined identifier, must be met, otherwise the request shall be rejected with an appropriate NRC.
Statement

When the client is performing the actual read operation (ReadDataByIdentifier [7]), the conditions and rules for all DIDs, aliased by the dynamically defined identifier, must be met, otherwise the request shall be rejected with an appropriate NRC.

NoneNoneAD-008componentRFQX-CVS151-0093 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS151-0094Since reading of DIDs can be allowed by either a pattern-rule (starting with 22 [7]) and/or a DID-rule, both the pattern-rules and the DID-rules must be parsed when evaluating each DID.
Statement

Since reading of DIDs can be allowed by either a pattern-rule (starting with 22 [7]) and/or a DID-rule, both the pattern-rules and the DID-rules must be parsed when evaluating each DID.

NoneNoneAD-005interfaceRFQX-CVS151-0094 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS154-0001Data Security Container base definition Foreword This Commercial Vehicle Standard (“CVS154”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.
Statement

Data Security Container base definition Foreword This Commercial Vehicle Standard (“CVS154”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.

NoneNoneNoneNoneRFQX-CVS154-0001 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0002Any review of this CVS154 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.
Statement

Any review of this CVS154 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.

NoneNoneAD-003componentRFQX-CVS154-0002 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS154-0003The User shall apply the latest version of this CVS154.
Statement

The User shall apply the latest version of this CVS154.

NoneNoneAD-008componentRFQX-CVS154-0003 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS154-0004This document shall be used accompanied with these specifications.
Statement

This document shall be used accompanied with these specifications.

NoneNoneAD-008componentRFQX-CVS154-0004 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS154-0005See further chapter 3.2 DSC ASN.1 definition for element types.
Statement

See further chapter 3.2 DSC ASN.1 definition for element types.

NoneNoneNoneNoneRFQX-CVS154-0005 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0006The DSC is divided in a metadata header block and three configuration blocks as shown in Figure 2 verificationEntries[..] encryptionEntries[..] itemEntries[..] id version Metadata Figure 2 – DSC structure
Statement

The DSC is divided in a metadata header block and three configuration blocks as shown in Figure 2 verificationEntries[..] encryptionEntries[..] itemEntries[..] id version Metadata Figure 2 – DSC structure

NoneNoneNoneNoneRFQX-CVS154-0006 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0007• version: specifies a version of the DSC structure, namely the DSC ASN.1 definition and its elements within the DSC instance.
Statement

• version: specifies a version of the DSC structure, namely the DSC ASN.1 definition and its elements within the DSC instance.

NoneNoneNoneNoneRFQX-CVS154-0007 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0008The server shall support a DSC Metadata block containing version and id fields.
Statement

The server shall support a DSC Metadata block containing version and id fields.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0008 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0009The server shall support the Major and Minor version as specified in 3.2.
Statement

The server shall support the Major and Minor version as specified in 3.2.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0009 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0010The server shall support a DSC containing verificationEntries.
Statement

The server shall support a DSC containing verificationEntries.

SSR-VV-002Security evidence and traceability — Verification and ValidationAD-002componentRFQX-CVS154-0010 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0011The server shall support a DSC containing encryptionEntries.
Statement

The server shall support a DSC containing encryptionEntries.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0011 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0012The server shall support a DSC containing itemEntries.
Statement

The server shall support a DSC containing itemEntries.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0012 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0013The server shall expect an ASN.1 SEQUENCE tag with length zero for verificationEntries that contains no VerificationEntry items in a DSC transmitted by the client.
Statement

The server shall expect an ASN.1 SEQUENCE tag with length zero for verificationEntries that contains no VerificationEntry items in a DSC transmitted by the client.

SSR-VV-002Security evidence and traceability — Verification and ValidationAD-002componentRFQX-CVS154-0013 / 16hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0014The server shall expect an ASN.1 SEQUENCE tag with length zero for encryptionEntries that contains no EncryptionEntry items in a DSC transmitted by the client.
Statement

The server shall expect an ASN.1 SEQUENCE tag with length zero for encryptionEntries that contains no EncryptionEntry items in a DSC transmitted by the client.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0014 / 16hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0015The server shall expect an ASN.1 SEQUENCE tag with length zero for ItemEntries that contains no items in a DSC transmitted by the client.
Statement

The server shall expect an ASN.1 SEQUENCE tag with length zero for ItemEntries that contains no items in a DSC transmitted by the client.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0015 / 16hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0016The server shall support an empty DSC containing only Metadata (version and id) and the empty sequences for verificationEntries, encryptionEntries and ItemEntries.
Statement

The server shall support an empty DSC containing only Metadata (version and id) and the empty sequences for verificationEntries, encryptionEntries and ItemEntries.

SSR-VV-002Security evidence and traceability — Verification and ValidationAD-002componentRFQX-CVS154-0016 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0017An empty DSC issued by client means that in addition to Metadata, the syntax must be correct in accordance with Annex B.
Statement

An empty DSC issued by client means that in addition to Metadata, the syntax must be correct in accordance with Annex B.

NoneNoneAD-008componentRFQX-CVS154-0017 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS154-0018A DSC containing only version and id states that verification and encryption is not to be performed by the server, although the server shall have the support.
Statement

A DSC containing only version and id states that verification and encryption is not to be performed by the server, although the server shall have the support.

NoneNoneAD-002componentRFQX-CVS154-0018 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS154-0019The VerificationEntry is of ASN.1 type CHOICE, where the choice stipulates the verification strategy for a piece of data.
Statement

The VerificationEntry is of ASN.1 type CHOICE, where the choice stipulates the verification strategy for a piece of data.

NoneNoneNoneNoneRFQX-CVS154-0019 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0020See 3.2 for the context-specific tag number for the VerificationEntry choices.
Statement

See 3.2 for the context-specific tag number for the VerificationEntry choices.

NoneNoneNoneNoneRFQX-CVS154-0020 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0021VerificationEntry hashCmp states that a hash comparison shall be used to verify the data.
Statement

VerificationEntry hashCmp states that a hash comparison shall be used to verify the data.

SSR-VV-001Security evidence and traceability — Verification and ValidationAD-008componentRFQX-CVS154-0021 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0022When the server is instructed to verify the programmed data, in general the following actions are taken by the server.
Statement

When the server is instructed to verify the programmed data, in general the following actions are taken by the server.

NoneNoneNoneNoneRFQX-CVS154-0022 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0023However, the instance specification may state specialized actions: • Server processes each VerificationEntry one by one.
Statement

However, the instance specification may state specialized actions: • Server processes each VerificationEntry one by one.

NoneNoneNoneNoneRFQX-CVS154-0023 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0024Definition of hashCmp fields: Refer to Figure 3 for type definitions of each field.
Statement

Definition of hashCmp fields: Refer to Figure 3 for type definitions of each field.

NoneNoneNoneNoneRFQX-CVS154-0024 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0025• hashAlgorithm: States which HashAlgorithm (see RFC 6234) shall be used for hashing the data to verify.
Statement

• hashAlgorithm: States which HashAlgorithm (see RFC 6234) shall be used for hashing the data to verify.

NoneNoneAD-008componentRFQX-CVS154-0025 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS154-0026• dataRanges: sequence of Range items - Range: Information on which data chunks that shall be verified.
Statement

• dataRanges: sequence of Range items - Range: Information on which data chunks that shall be verified.

NoneNoneAD-008componentRFQX-CVS154-0026 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS154-0027The server shall support the SHA512 HashAlgorithm as referred in 3.2 ASN1 definition.
Statement

The server shall support the SHA512 HashAlgorithm as referred in 3.2 ASN1 definition.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0027 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0028The encryptionEntry is of ASN.1 type CHOICE stipulating the decryption strategy for a piece of data.
Statement

The encryptionEntry is of ASN.1 type CHOICE stipulating the decryption strategy for a piece of data.

NoneNoneNoneNoneRFQX-CVS154-0028 / 8hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0029For crypto agility reasons, both of the choices shall be supported by the server.
Statement

For crypto agility reasons, both of the choices shall be supported by the server.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0029 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0030See 3.2 for the context-specific tag number for the EncryptionEntry choices.
Statement

See 3.2 for the context-specific tag number for the EncryptionEntry choices.

NoneNoneNoneNoneRFQX-CVS154-0030 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0031The initial counter value shall be set to 0 (zero).
Statement

The initial counter value shall be set to 0 (zero).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS154-0031 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS154-0032Range: Information on which data chunks that shall be decrypted.
Statement

Range: Information on which data chunks that shall be decrypted.

NoneNoneAD-008componentRFQX-CVS154-0032 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS154-0033An ItemEntry is of ASN.1 type CHOICE, where the choice stipulates the type of item the ItemEntry holds.
Statement

An ItemEntry is of ASN.1 type CHOICE, where the choice stipulates the type of item the ItemEntry holds.

NoneNoneNoneNoneRFQX-CVS154-0033 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS154-0034The structure version for this document release shall be: Major ‘04’ and Minor ‘00’
Statement

The structure version for this document release shall be: Major ‘04’ and Minor ‘00’

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS154-0034 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS154-0035The server shall have support for the ASN.1 contents as defined: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }
Statement

The server shall have support for the ASN.1 contents as defined: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }

NoneNoneAD-002componentRFQX-CVS154-0035 / 19hNot importedStill Requires Customer DecisionP1 OPENboundary ownership; certificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCESECURITY REVIEW OPEN
RFQX-CVS154-0036Upon reception of a DSC to the server, before the DSC is stored in NVM, the DSC shall be semantically verified by parsing all its content.
Statement

Upon reception of a DSC to the server, before the DSC is stored in NVM, the DSC shall be semantically verified by parsing all its content.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS154-0036 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0037The length of the version field shall be verified.
Statement

The length of the version field shall be verified.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS154-0037 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS154-0038The version shall be verified with the servers supported Major and Minor version of the DSC logic for compliancy.
Statement

The version shall be verified with the servers supported Major and Minor version of the DSC logic for compliancy.

SSR-TOOL-003Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-001componentRFQX-CVS154-0038 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0039The length of the id field shall be verified.
Statement

The length of the id field shall be verified.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS154-0039 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS154-0040The hashAlgorithm shall be supported by the server.
Statement

The hashAlgorithm shall be supported by the server.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0040 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0041The length of every referenceHash shall be consistent with the output size of the hash algorithm specified in the hashAlgorithm.
Statement

The length of every referenceHash shall be consistent with the output size of the hash algorithm specified in the hashAlgorithm.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS154-0041 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS154-0042The verification of servers support of specified dataRanges in the VerificationEntry, shall be stated for the DSC instance.
Statement

The verification of servers support of specified dataRanges in the VerificationEntry, shall be stated for the DSC instance.

NoneNoneAD-008componentRFQX-CVS154-0042 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS154-0043The EncryptionEntry algorithm shall be supported by the server.
Statement

The EncryptionEntry algorithm shall be supported by the server.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0043 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0044The length of key and iv shall be verified accordingly to the algorithm stipulated in EncryptionEntry.
Statement

The length of key and iv shall be verified accordingly to the algorithm stipulated in EncryptionEntry.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS154-0044 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0045The verification of servers support of specified dataRanges in the EncryptionEntry, shall be stated for the DSC instance.
Statement

The verification of servers support of specified dataRanges in the EncryptionEntry, shall be stated for the DSC instance.

NoneNoneAD-008componentRFQX-CVS154-0045 / 56hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS154-0046If the DSC instance is rejected by the server (see Annex A) when transmitted with EMP, an error code shall be returned to the client.
Statement

If the DSC instance is rejected by the server (see Annex A) when transmitted with EMP, an error code shall be returned to the client.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS154-0046 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS154-0047The sequence tags for verificationEntries, encryptionEntries and itemEntries are required but empty (zero length).
Statement

The sequence tags for verificationEntries, encryptionEntries and itemEntries are required but empty (zero length).

NoneNoneAD-008componentRFQX-CVS154-0047 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0001The User shall apply the latest version of this CVS31.
Statement

The User shall apply the latest version of this CVS31.

NoneNoneAD-008componentRFQX-CVS31-0001 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0002Foreword This CVS31 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.
Statement

Foreword This CVS31 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.

NoneNoneNoneNoneRFQX-CVS31-0002 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0003Any review of CVS31 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”.
Statement

Any review of CVS31 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”.

NoneNoneAD-003componentRFQX-CVS31-0003 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0004The whole standard has been reworked and shall be read in its entirety.
Statement

The whole standard has been reworked and shall be read in its entirety.

NoneNoneAD-008componentRFQX-CVS31-0004 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0005• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.
Statement

• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.

NoneNoneAD-002componentRFQX-CVS31-0005 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0006Summary
Statement

The purpose of this document is to clarify vehicle manufacture specific extensions and exceptions to the Authentication 0x29 service specified in ISO 14229-1:2020. CVS150 Cryptographic Specification CVS32 SecuredDataTransmis sion 0x84 CVS151 RBAC CVS33 Entity Management Protocol (EMP) CVS31 Authenticate 0x29 CVS124 Traton Specification on Unified diagnostic services (UDS) CVS30 X.509 Specification CVS34 EMP – Basic Entities Figure 1 – Overview of relation between specifications The following documents are normative and indispensable for the application of this document: • Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) • ISO 14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements Whenever a requirement in this specification or the Traton Specification on Unified diagnostic Services (UDS) requirements (CVS124) is non-compliant with one or more requirements in ISO 14229-1:2020 the requirements in this specification and (CVS124) take precedence. Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer. It is the vehicle manufacturer that decides if a deviation can be accepted or not. Multiple security concepts are available in the Authentication (ISO 14229-1:2020) service, however, only APCE (ISO 14229-1:2020) is supported by the concept described in this document, see Figure 2.

SSR-RBAC-001Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-007componentRFQX-CVS31-0006 / 29hNot importedStill Requires Customer DecisionP1 OPENboundary ownership; certificate/key handling; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCESECURITY REVIEW OPEN
RFQX-CVS31-0007Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer.
Statement

Any deviations from this specification shall be documented and must be reviewed by the vehicle manufacturer.

NoneNoneAD-008componentRFQX-CVS31-0007 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0008Shall be agreed between the supplier and the vehicle manufacturer.
Statement

Shall be agreed between the supplier and the vehicle manufacturer.

NoneNoneAD-008componentRFQX-CVS31-0008 / 24hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0009It contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response.
Statement

It contains the information required for the server to verify the client’s subsequent request and to generate the corresponding response.

NoneNoneAD-002componentRFQX-CVS31-0009 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0010It contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses.
Statement

It contains the information required for the server to maintain continuous authenticated communication with the client and to generate authenticated responses.

NoneNoneAD-002componentRFQX-CVS31-0010 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0011This section of the document describes vehicle manufacturer specific requirements regarding the behaviour and content of the subFunctions (ISO 14229-1:2020) found in Table 4.
Statement

This section of the document describes vehicle manufacturer specific requirements regarding the behaviour and content of the subFunctions (ISO 14229-1:2020) found in Table 4.

NoneNoneNoneNoneRFQX-CVS31-0011 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0012The server shall only support subfunctions in Table 4.
Statement

The server shall only support subfunctions in Table 4.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0012 / 21hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0013In this document, each subFunction (ISO 14229-1:2020) is described in its own sub-section.
Statement

In this document, each subFunction (ISO 14229-1:2020) is described in its own sub-section.

NoneNoneNoneNoneRFQX-CVS31-0013 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0014The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message.
Statement

The server shall not accept an application-layer service 0x29 request when it is received inside an SDT (service 0x84) protected message.

SSR-RBAC-006Secure communication and freshness protection — Secure Diagnostics / RBACAD-001componentRFQX-CVS31-0014 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0015If such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response.
Statement

If such an encapsulated 0x29 request is detected, the server shall return application-layer NRC 0x39, provided as a correctly formatted SDT positive response.

NoneNoneAD-001componentRFQX-CVS31-0015 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0016The request for verifyCertificateBidirectional subfunction shall be formatted according to
Statement

The request for verifyCertificateBidirectional subfunction shall be formatted according to

SSR-KEY-002Key and Certificate Handling — Key and Certificate HandlingAD-008componentRFQX-CVS31-0016 / 32hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0017Table 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running.
Statement

Table 5 – verifyCertificateBidirectional Request Field Description Type/Value Cvt Included in proofOfOwnershipServer Authentication Request SID Service ID for Authentication service request 0x29 M Yes verifyCertificateBidirectional] Initiate Authentication by verifying the Certificate and generating a Proof of Ownership from the server 0x02 M Yes communicationConfiguration NOT USED 0x00 M Yes lengthOfCertificateClient Length parameter for certificateClient uint16 M Yes certificateClient The Certificate to verify uint8[] M Yes lengthOfChallengeClient Length parameter for challengeClient uint16 M Yes challengeClient See 3.1.1.1 uint8[] M Yes Upon reception of a verifyCertificateBidirectional request, the server shall determine whether the Authentication delay timer is currently running.

SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS31-0017 / 26hNot importedNo linked clarificationNo P1 linkboundary ownership; certificate/key handling; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0018For details on Authentication delay timer, refer to chapter 4.8.
Statement

For details on Authentication delay timer, refer to chapter 4.8.

NoneNoneNoneNoneRFQX-CVS31-0018 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0019If upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request.
Statement

If upon reception of verifyCertificateBidirectional request the Authentication delay timer is expired, the server shall continue to process the verifyCertificateBidirectional request.

SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingAD-002componentRFQX-CVS31-0019 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0020The column “Included in proofOfOwnershipServer”, present in several message-definition tables, indicates whether the corresponding field shall be covered by the proofOfOwnershipServer signature computed by the server and included in its response.
Statement

The column “Included in proofOfOwnershipServer”, present in several message-definition tables, indicates whether the corresponding field shall be covered by the proofOfOwnershipServer signature computed by the server and included in its response.

NoneNoneAD-002componentRFQX-CVS31-0020 / 56hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0021If the server verifies the client certificate as valid, the server shall create the requested client authentication pending state.
Statement

If the server verifies the client certificate as valid, the server shall create the requested client authentication pending state.

SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS31-0021 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0022If an authentication pending state already exists, the server shall replace the existing
Statement

If an authentication pending state already exists, the server shall replace the existing

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0022 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0023For details in how to validate a client certificate, refer to chapter 4.1.
Statement

For details in how to validate a client certificate, refer to chapter 4.1.

NoneNoneNoneNoneRFQX-CVS31-0023 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0024This field shall consists of 32 octets.
Statement

This field shall consists of 32 octets.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0024 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0025The challengeClient (ISO 14229-1:2020) shall be generated using a CRNG.
Statement

The challengeClient (ISO 14229-1:2020) shall be generated using a CRNG.

SSR-SYS-002System Function — System FunctionAD-003componentRFQX-CVS31-0025 / 10hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0026The expected range values of lengthOfCertificateClient shall be from 0x00C8 to 0x0800.
Statement

The expected range values of lengthOfCertificateClient shall be from 0x00C8 to 0x0800.

SSR-KEY-002Key and Certificate Handling — Key and Certificate HandlingAD-008componentRFQX-CVS31-0026 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0027The server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request.
Statement

The server shall verify the value of lengthOfCertificateClient upon reception of verifyCertificateBidirectional request.

SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingAD-002componentRFQX-CVS31-0027 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0028If the lengthOfCertificateClient value is not within the expected range, the server shall send negative response code 0x13 (incorrectMessageLengthOrInvalidFormat).
Statement

If the lengthOfCertificateClient value is not within the expected range, the server shall send negative response code 0x13 (incorrectMessageLengthOrInvalidFormat).

SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingAD-002componentRFQX-CVS31-0028 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0029The response for verifyCertificateBidirectional subfunction shall be formatted according to Table 6.
Statement

The response for verifyCertificateBidirectional subfunction shall be formatted according to Table 6.

SSR-KEY-002Key and Certificate Handling — Key and Certificate HandlingAD-008componentRFQX-CVS31-0029 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0030Upon positively responding, the server shall start the Authentication completion timer.
Statement

Upon positively responding, the server shall start the Authentication completion timer.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0030 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0031The challengeServer field shall consists of 32 octets generated using a CRNG.
Statement

The challengeServer field shall consists of 32 octets generated using a CRNG.

SSR-TOOL-004Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-008componentRFQX-CVS31-0031 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0032This field consists of a signature that proves to the client that the server has access to the private key of the provided certificateServer (ISO 14229-1:2020).
Statement

This field consists of a signature that proves to the client that the server has access to the private key of the provided certificateServer (ISO 14229-1:2020). Additionally, the field proves that the same message sent by the client has been received by the server and vice-versa.

NoneNoneNoneNoneRFQX-CVS31-0032 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0033The proof/signature shall be generated according to the pseudo code below.
Statement

The proof/signature shall be generated according to the pseudo code below.

SSR-DAI-008Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-008componentRFQX-CVS31-0033 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0034For obvious reasons, the proofOfOwnershipServer in the VerifyCertificates is not included, in the “concatenation” (see pseudo code above) when the signature/proof is being calculated.
Statement

For obvious reasons, the proofOfOwnershipServer in the VerifyCertificates is not included, in the “concatenation” (see pseudo code above) when the signature/proof is being calculated.

NoneNoneNoneNoneRFQX-CVS31-0034 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0035This field provides the client with the necessary server-side data for the chosen key-exchange scheme/algorithm.
Statement

This field provides the client with the necessary server-side data for the chosen key-exchange scheme/algorithm.

NoneNoneNoneNoneRFQX-CVS31-0035 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0036If upon reception of verifyCertificateBidirectional request the Authentication delay timer is running, the server shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x37, indicating requiredTimeDelayNotExpired.
Statement

If upon reception of verifyCertificateBidirectional request the Authentication delay timer is running, the server shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x37, indicating requiredTimeDelayNotExpired.

SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingAD-002componentRFQX-CVS31-0036 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0037If the server verifies the client certificate as invalid, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x10, indicating generalReject.
Statement

If the server verifies the client certificate as invalid, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x10, indicating generalReject.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0037 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0038If the server fails or cannot determine that the authentication pending state was stored, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
Statement

If the server fails or cannot determine that the authentication pending state was stored, it shall respond to the verifyCertificateBidirectional request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingAD-002componentRFQX-CVS31-0038 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivity; evidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0039This subfunction (ISO 14229-1:2020) serves several purposes – it proves to the server that the client owns the private key of the provided certificateClient (ISO 14229-1:2020).
Statement

This subfunction (ISO 14229-1:2020) serves several purposes – it proves to the server that the client owns the private key of the provided certificateClient (ISO 14229-1:2020).

NoneNoneNoneNoneRFQX-CVS31-0039 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0040The request for proofOfOwnership subfunction shall be defined according to Table 7.
Statement

The request for proofOfOwnership subfunction shall be defined according to Table 7.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0040 / 18hNot importedNo linked clarificationNo P1 linkboundary ownershipNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0041If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.
Statement

If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS31-0041 / 26hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0042Table 7 – proofOfOwnership Request Field Description Type/Value Cvt Included in proofOfOwnershipClient Authentication Request SID Service ID for 0x29 M Yes proofOfOwnership] Verify the Proof of Ownership from the client 0x03 M Yes lengthOfProofOfOwnershipClient This field indicates the length (in octets) of the proofOfOwnershipClient field proofOfOwnershipClient See 3.2.1.1 uint8[] M No lengthOfEphemeralPublicKey Client Length parameter for ephemeralPublicKey Client ephemeralPublicKeyClient See 3.2.1.2 uint16 M Yes The server shall verify whether any existing authentication pending state corresponds to the client submitting the proofOfOwnership request.
Statement

Table 7 – proofOfOwnership Request Field Description Type/Value Cvt Included in proofOfOwnershipClient Authentication Request SID Service ID for 0x29 M Yes proofOfOwnership] Verify the Proof of Ownership from the client 0x03 M Yes lengthOfProofOfOwnershipClient This field indicates the length (in octets) of the proofOfOwnershipClient field proofOfOwnershipClient See 3.2.1.1 uint8[] M No lengthOfEphemeralPublicKey Client Length parameter for ephemeralPublicKey Client ephemeralPublicKeyClient See 3.2.1.2 uint16 M Yes The server shall verify whether any existing authentication pending state corresponds to the client submitting the proofOfOwnership request.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS31-0042 / 26hNot importedNo linked clarificationNo P1 linkboundary ownership; certificate/key handling; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0043If an existing authentication pending state is found, the server shall verify if the Authentication completion timer is currently running.
Statement

If an existing authentication pending state is found, the server shall verify if the Authentication completion timer is currently running.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0043 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0044For details on Authentication completion timer, refer to chapter 4.9.
Statement

For details on Authentication completion timer, refer to chapter 4.9.

NoneNoneNoneNoneRFQX-CVS31-0044 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0045If the Authentication completion timer is currently running, the server shall continue to process the client’s proofOfOwnership request.
Statement

If the Authentication completion timer is currently running, the server shall continue to process the client’s proofOfOwnership request.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0045 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0046If the client proofOfOwnership signature verification fails, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.
Statement

If the client proofOfOwnership signature verification fails, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.

SSR-DAI-006Security evidence and traceability — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS31-0046 / 26hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0047If the server fails or cannot determine that the authentication state was stored, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.
Statement

If the server fails or cannot determine that the authentication state was stored, the server shall delete the authentication pending state connected to the client submitting the proofOfOwnership request.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS31-0047 / 26hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0048If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.
Statement

If the client’s proofOfOwnership signature is successfully verified, the server shall establish a new authentication state for the client.

SSR-DAI-003Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS31-0048 / 26hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0049If an active authentication state already exists, the server shall replace the existing state with the newly established one.
Statement

If an active authentication state already exists, the server shall replace the existing state with the newly established one.

NoneNoneAD-002componentRFQX-CVS31-0049 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0050The field proofOfOwnershipClient is a signature that proves to the server that the client has access to the private key of the certificateClient (ISO 14229-1:2020).
Statement

The field proofOfOwnershipClient is a signature that proves to the server that the client has access to the private key of the certificateClient (ISO 14229-1:2020).

NoneNoneNoneNoneRFQX-CVS31-0050 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0051The proofOfOwnershipClient shall be generated according to the pseudo code below.
Statement

The proofOfOwnershipClient shall be generated according to the pseudo code below.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0051 / 21hNot importedNo linked clarificationNo P1 linkboundary ownershipNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0052The reason for the concatenation, is to ensure that the full communication (all sent and received requests and responses) has integrity.
Statement

The reason for the concatenation, is to ensure that the full communication (all sent and received requests and responses) has integrity.

NoneNoneNoneNoneRFQX-CVS31-0052 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0053This field provides the server with the necessary client-side data for the chosen key-exchange scheme/algorithm.
Statement

This field provides the server with the necessary client-side data for the chosen key-exchange scheme/algorithm.

NoneNoneNoneNoneRFQX-CVS31-0053 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0054The response for proofOfOwnership subfunction shall be according to Table 8.
Statement

The response for proofOfOwnership subfunction shall be according to Table 8.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0054 / 21hNot importedNo linked clarificationNo P1 linkboundary ownershipNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0055The sessionKeyInfo includes a signature that proves to the client that the server has accepted the proofOfOwnership (ISO 14229-1:2020).
Statement

The sessionKeyInfo includes a signature that proves to the client that the server has accepted the proofOfOwnership (ISO 14229-1:2020).

NoneNoneNoneNoneRFQX-CVS31-0055 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0056The signature shall be generated according to the pseudo code below.
Statement

The signature shall be generated according to the pseudo code below.

SSR-DAI-008Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-008componentRFQX-CVS31-0056 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0057For obvious reasons, the sessionKeyInfo in the ProofOfOwnershipres is not included, in the “concatenation” (see pseudo code above) when the signature is being calculated.
Statement

For obvious reasons, the sessionKeyInfo in the ProofOfOwnershipres is not included, in the “concatenation” (see pseudo code above) when the signature is being calculated.

NoneNoneNoneNoneRFQX-CVS31-0057 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0058If the server determines that the client does not have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.
Statement

If the server determines that the client does not have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0058 / 26hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0059If the server determines that the client have an existing authentication pending state and the Authentication completion timer is expired, the server shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.
Statement

If the server determines that the client have an existing authentication pending state and the Authentication completion timer is expired, the server shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x24, indicating requestSequenceError.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0059 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0060If the server cannot determine if the client does have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
Statement

If the server cannot determine if the client does have an existing authentication pending state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS31-0060 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivity; evidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0061If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server determines that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x10, indicating generalReject.
Statement

If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server determines that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x10, indicating generalReject.

SSR-DAI-006Security evidence and traceability — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS31-0061 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0062If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server cannot determine that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
Statement

If the server is trying to delete the authentication pending state as consequence of the client proofOfOwnership signature verification failure, and the server cannot determine that the authentication pending state was deleted, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

SSR-DAI-006Security evidence and traceability — Data Authenticity and Integrity VerificationAD-002componentRFQX-CVS31-0062 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivity; evidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0063If the server is deleting the authentication pending state as consequence of failure to store the authentication state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.
Statement

If the server is deleting the authentication pending state as consequence of failure to store the authentication state, it shall respond to the proofOfOwnership request with a Negative Response Code (NRC) 0x94, indicating ResourceTemporarilyNotAvailable.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0063 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivity; evidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0064This chapter specifies the behaviour of the deAuthenticate subfunction.
Statement

This chapter specifies the behaviour of the deAuthenticate subfunction.

NoneNoneNoneNoneRFQX-CVS31-0064 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0065The request for deAuthenticate subfunction shall be formatted according to Table 9.
Statement

The request for deAuthenticate subfunction shall be formatted according to Table 9.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0065 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0066Table 9 – deAuthenticate request message layout Field Description Type/Value Cvt Authentication Request SID Service ID for 0x29 M SubFunction = [AuthenticationTask = deAuthenticate] Subfunction for request to leave the authenticated state 0x00 M 3.3.2 Response The response for deAuthenticate subfunction shall be formatted according to Table 10.
Statement

Table 9 – deAuthenticate request message layout Field Description Type/Value Cvt Authentication Request SID Service ID for 0x29 M SubFunction = [AuthenticationTask = deAuthenticate] Subfunction for request to leave the authenticated state 0x00 M 3.3.2 Response The response for deAuthenticate subfunction shall be formatted according to Table 10.

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS31-0066 / 26hNot importedNo linked clarificationNo P1 linkdiagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0067The server shall delete/invalidate the client’s authentication prior to positively responding to the deAuthenticate request.
Statement

The server shall delete/invalidate the client’s authentication prior to positively responding to the deAuthenticate request.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0067 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0068If the server determines that the client is not currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x24, indicating a requestSequenceError.
Statement

If the server determines that the client is not currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x24, indicating a requestSequenceError.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0068 / 18hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0069The server only responds NRC 0x24 in the case that it can confirm that there is no authentication state connected to the client requesting to deAuthenticate.
Statement

The server only responds NRC 0x24 in the case that it can confirm that there is no authentication state connected to the client requesting to deAuthenticate.

NoneNoneNoneNoneRFQX-CVS31-0069 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0070If the server cannot determine that the client is currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x94, indicating a ResourceTemporarilyNotAvailable.
Statement

If the server cannot determine that the client is currently authenticated, it shall respond to the deAuthenticate request with a Negative Response Code (NRC) 0x94, indicating a ResourceTemporarilyNotAvailable.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS31-0070 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivity; evidence completenessNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0071If the server is unable to delete the client's authentication state or cannot verify its presence, it shall respond to the deAuthenticate request with Negative Response Code (NRC) 0x94,
Statement

If the server is unable to delete the client's authentication state or cannot verify its presence, it shall respond to the deAuthenticate request with Negative Response Code (NRC) 0x94,

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS31-0071 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0072If the server is unable to delete the client’s authentication state or cannot retrieve it due to internal errors, the server responds NRC 0x94.This informs the client that the authentication state may still exist on the server.
Statement

If the server is unable to delete the client’s authentication state or cannot retrieve it due to internal errors, the server responds NRC 0x94.This informs the client that the authentication state may still exist on the server.

NoneNoneNoneNoneRFQX-CVS31-0072 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0073The signature algorithm used throughout the authentication process shall be ED25519.
Statement

The signature algorithm used throughout the authentication process shall be ED25519.

SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS31-0073 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0074The client shall use the private key corresponding to the client certificate to generate the signatures.
Statement

The client shall use the private key corresponding to the client certificate to generate the signatures.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0074 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0075The server shall use the private key corresponding to the server certificate to generate the signatures.
Statement

The server shall use the private key corresponding to the server certificate to generate the signatures.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0075 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0076The signature algorithm in the client, server and authentication CA certificates are ED25519 (1.3.101.112).
Statement

The signature algorithm in the client, server and authentication CA certificates are ED25519 (1.3.101.112).

NoneNoneNoneNoneRFQX-CVS31-0076 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0077The format and the structure of the certificates shall be based on (CVS30).
Statement

The format and the structure of the certificates shall be based on (CVS30).

SSR-KEY-002Key and Certificate Handling — Key and Certificate HandlingAD-008componentRFQX-CVS31-0077 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0078The server shall reject a received client’s certificate, sent using the verifyCertificateBidirectional subFunction, if it matches the server’s own certificate.
Statement

The server shall reject a received client’s certificate, sent using the verifyCertificateBidirectional subFunction, if it matches the server’s own certificate.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0078 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0079It should not be possible to “unlock” the server using its own key/certificate.
Statement

It should not be possible to “unlock” the server using its own key/certificate.

NoneNoneAD-007componentRFQX-CVS31-0079 / 56hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0080The server shall verify the client certificate, sent using the verifyCertificateBidirectional subFunction, according to Figure 3.
Statement

The server shall verify the client certificate, sent using the verifyCertificateBidirectional subFunction, according to Figure 3.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0080 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0081The server shall verify the Signature of the Client certificate using the AUTH-CA EMP entity public key.
Statement

The server shall verify the Signature of the Client certificate using the AUTH-CA EMP entity public key.

SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS31-0081 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0082• Check if the NodeUID of the server is present in the NodeUIDs extension.
Statement

• Check if the NodeUID of the server is present in the NodeUIDs extension.

NoneNoneNoneNoneRFQX-CVS31-0082 / 19hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0083• If the server NodeUID is not found in the NodeUID extension, the server shall reject the certificate and generate NRC 0x10 (generalReject).
Statement

• If the server NodeUID is not found in the NodeUID extension, the server shall reject the certificate and generate NRC 0x10 (generalReject).

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0083 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0084If the NodeUID extension is not detected, the operation shall continue as in
Statement

If the NodeUID extension is not detected, the operation shall continue as in

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0084 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0085A certificate without NodeUID extension implies that the certificate is applicable for any NodeUID.
Statement

A certificate without NodeUID extension implies that the certificate is applicable for any NodeUID.

NoneNoneNoneNoneRFQX-CVS31-0085 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0086The maximum number of elements in the list (number of ids) is limited by the maximum size of the certificate.
Statement

The maximum number of elements in the list (number of ids) is limited by the maximum size of the certificate.

NoneNoneNoneNoneRFQX-CVS31-0086 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0087For the length of NodeUID see (CVS124).
Statement

For the length of NodeUID see (CVS124).

NoneNoneNoneNoneRFQX-CVS31-0087 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0088The ECU-Diagnostic role extension shall be included in the client certificate.
Statement

The ECU-Diagnostic role extension shall be included in the client certificate.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0088 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0089The roles shall correspond to a bit pattern-octet string.
Statement

The roles shall correspond to a bit pattern-octet string.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0089 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0090The interpretation of the roles should follow as the example below: • Role 1 -> 0000 0000 0000 0000 0000 0000 0000 0001 – 00 00 00 01 • Role 32 -> 1000 0000 0000 0000 0000 0000 0000 0000 – 80 00 00 00 • Role 2 and 4 -> 0000 0000 0000 0000 0000 0000 0000 1010 – 00 00 00 0A.
Statement

The interpretation of the roles should follow as the example below: • Role 1 -> 0000 0000 0000 0000 0000 0000 0000 0001 – 00 00 00 01 • Role 32 -> 1000 0000 0000 0000 0000 0000 0000 0000 – 80 00 00 00 • Role 2 and 4 -> 0000 0000 0000 0000 0000 0000 0000 1010 – 00 00 00 0A.

NoneNoneAD-008componentRFQX-CVS31-0090 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0091The D-RBACC extension defines client-specific rules that override the role-based access control configuration in the server.
Statement

The D-RBACC extension defines client-specific rules that override the role-based access control configuration in the server.

NoneNoneNoneNoneRFQX-CVS31-0091 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0092While the ECU-Diagnostic Role extension specifies the roles assigned to a client, the D-RBACC extension may both grant additional permissions and restrict permissions beyond those derived from the client’s roles.
Statement

While the ECU-Diagnostic Role extension specifies the roles assigned to a client, the D-RBACC extension may both grant additional permissions and restrict permissions beyond those derived from the client’s roles.

NoneNoneNoneNoneRFQX-CVS31-0092 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0093If D-RBACC extension is detected, the server shall overrule the RBACC with the D-RBACC permissions.
Statement

If D-RBACC extension is detected, the server shall overrule the RBACC with the D-RBACC permissions.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS31-0093 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0094This means that if D-RBACC logic denies/permits certain access, the server shall deny/permit the access regardless of what RBACC logic permits/denies.
Statement

This means that if D-RBACC logic denies/permits certain access, the server shall deny/permit the access regardless of what RBACC logic permits/denies.

NoneNoneAD-001componentRFQX-CVS31-0094 / 56hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0095• The server shall validate the D-RBACC by parsing all its content.
Statement

• The server shall validate the D-RBACC by parsing all its content. If content is invalid,

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS31-0095 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0096If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.
Statement

If content is invalid, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.

NoneNoneAD-007componentRFQX-CVS31-0096 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0097• Parsing means that the server tries to decode the DER encoded D-RBACC structure, which includes checking the decoded results against the server’s supported/known ASN.1 definition.
Statement

• Parsing means that the server tries to decode the DER encoded D-RBACC structure, which includes checking the decoded results against the server’s supported/known ASN.1 definition.

NoneNoneNoneNoneRFQX-CVS31-0097 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0098• The server shall verify that the D-RBACC version provided by the client is compatible with the server’s supported D-RBACC version.
Statement

• The server shall verify that the D-RBACC version provided by the client is compatible with the server’s supported D-RBACC version.

SSR-RBAC-003Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-002componentRFQX-CVS31-0098 / 16hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0099If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.
Statement

If non-compliant, the certificate is invalid and the server shall return a Negative Response Code (NRC) 0x10, indicating generalReject.

NoneNoneAD-007componentRFQX-CVS31-0099 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS31-0100The basicConstraints extension CA field shall be False.
Statement

The basicConstraints extension CA field shall be False.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0100 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0101The Key Usage extension (RFC 5280) shall be included in the client certificate.
Statement

The Key Usage extension (RFC 5280) shall be included in the client certificate.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0101 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0102The Key Usage extension shall contain DigitalSignature.
Statement

The Key Usage extension shall contain DigitalSignature.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0102 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0103The Extended Key Usage extension (RFC 5280) shall be included in the client certificate.
Statement

The Extended Key Usage extension (RFC 5280) shall be included in the client certificate.

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0103 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0104The extension ExtendedKeyUsage shall contain clientAuth (1.3.6.1.5.5.7.3.2).
Statement

The extension ExtendedKeyUsage shall contain clientAuth (1.3.6.1.5.5.7.3.2).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0104 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0105The extension SignatureAlgorithm shall contain ED25519 (1.3.101.112).
Statement

The extension SignatureAlgorithm shall contain ED25519 (1.3.101.112).

SSR-DAI-008Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationAD-008componentRFQX-CVS31-0105 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0106The server shall validate the certificate so that: 𝑛𝑜𝑡𝐵𝑒𝑓𝑜𝑟𝑒 ≤ 𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒-𝑡𝑖𝑚𝑒 ≤ 𝑛𝑜𝑡𝐴𝑓𝑡𝑒𝑟
Statement

The server shall validate the certificate so that: 𝑛𝑜𝑡𝐵𝑒𝑓𝑜𝑟𝑒 ≤ 𝐶𝑒𝑟𝑡𝑖𝑓𝑖𝑐𝑎𝑡𝑒-𝑡𝑖𝑚𝑒 ≤ 𝑛𝑜𝑡𝐴𝑓𝑡𝑒𝑟

SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingAD-007componentRFQX-CVS31-0106 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0107The notBefore and notAfter are received as fields in the certificate while Certificate-Time is the EMP entity defined in CVS34.
Statement

The notBefore and notAfter are received as fields in the certificate while Certificate-Time is the EMP entity defined in CVS34.

NoneNoneNoneNoneRFQX-CVS31-0107 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0108• The server is reset (i.e server is power cycled).
Statement

• The server is reset (i.e server is power cycled).

NoneNoneNoneNoneRFQX-CVS31-0108 / 4hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0109State-keeping
Statement

State-keeping

NoneNoneNoneNoneRFQX-CVS31-0109 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0110• Power failure.
Statement

• Power failure.

NoneNoneNoneNoneRFQX-CVS31-0110 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0111If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication pending state.
Statement

If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication pending state.

SSR-DIAG-006Diagnostic Services — Diagnostic ServicesAD-001componentRFQX-CVS31-0111 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0112If a request to reset (e.g service 0x11) is received over the service 0x84 (securedDataTransmission) it permits the server to respond before the sessionKey is locked/invalidated.
Statement

If a request to reset (e.g service 0x11) is received over the service 0x84 (securedDataTransmission) it permits the server to respond before the sessionKey is locked/invalidated.

NoneNoneNoneNoneRFQX-CVS31-0112 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0113If a client and server have successfully completed the authentication process, the server shall invalidate the authentication state in the event of: • The server is reset (i.e server is power cycled).
Statement

If a client and server have successfully completed the authentication process, the server shall invalidate the authentication state in the event of: • The server is reset (i.e server is power cycled).

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0113 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0114• Power failure.
Statement

• Power failure.

NoneNoneNoneNoneRFQX-CVS31-0114 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0115• Successful deAuthenticate (see 3.3) subFunction (ISO 14229-1:2020).
Statement

• Successful deAuthenticate (see 3.3) subFunction (ISO 14229-1:2020).

NoneNoneNoneNoneRFQX-CVS31-0115 / 4hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0116• A new successful authentication is established.
Statement

• A new successful authentication is established.

NoneNoneNoneNoneRFQX-CVS31-0116 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0117• By passive de-authentication, see 4.7.
Statement

• By passive de-authentication, see 4.7.

NoneNoneNoneNoneRFQX-CVS31-0117 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0118Authentication state invalidated by the server implies that any unlocked services and sessionKey is locked/invalidated.
Statement

Authentication state invalidated by the server implies that any unlocked services and sessionKey is locked/invalidated.

NoneNoneNoneNoneRFQX-CVS31-0118 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0119If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication state.
Statement

If a server reset is triggered by a client request (e.g., UDS service 0x11), the server shall send the corresponding response before invalidating the authentication state.

SSR-DIAG-006Diagnostic Services — Diagnostic ServicesAD-001componentRFQX-CVS31-0119 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0120The server’s authentication pending state shall contain the minimum of (non-exhaustive list): • Client address that issued the authentication request.
Statement

The server’s authentication pending state shall contain the minimum of (non-exhaustive list): • Client address that issued the authentication request.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0120 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0121• Authentication completion timer.
Statement

• Authentication completion timer.

NoneNoneNoneNoneRFQX-CVS31-0121 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0122• Client’s certificate public key
Statement

• Client’s certificate public key

NoneNoneNoneNoneRFQX-CVS31-0122 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredCOMPLETE
RFQX-CVS31-0123• Client D-RBACC, if provided in the client’s certificate
Statement

• Client D-RBACC, if provided in the client’s certificate

NoneNoneNoneNoneRFQX-CVS31-0123 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0124• Server ephemeral private key
Statement

• Server ephemeral private key

NoneNoneNoneNoneRFQX-CVS31-0124 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0125• H0 hash value
Statement

• H0 hash value

NoneNoneNoneNoneRFQX-CVS31-0125 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0126The server ephemeral private key is the pair of the public key (ephemeralPublicKeyServer) sent as verifyCertificateBidirectional response.
Statement

The server ephemeral private key is the pair of the public key (ephemeralPublicKeyServer) sent as verifyCertificateBidirectional response.

NoneNoneNoneNoneRFQX-CVS31-0126 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0127H0 hash value is calculated as part of proofOfOwnershipServer in verifyCertificateBidirectional response.
Statement

H0 hash value is calculated as part of proofOfOwnershipServer in verifyCertificateBidirectional response.

NoneNoneNoneNoneRFQX-CVS31-0127 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0128The server’s authentication state shall contain the minimum of (non-exhaustive list): • SessionKey.
Statement

The server’s authentication state shall contain the minimum of (non-exhaustive list): • SessionKey.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0128 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0129• A3 Timer for passive de-authentication information.
Statement

• A3 Timer for passive de-authentication information.

NoneNoneNoneNoneRFQX-CVS31-0129 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0130• Client address that issued the authentication request.
Statement

• Client address that issued the authentication request.

NoneNoneNoneNoneRFQX-CVS31-0130 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0131• Client roles (ECU diagnostic Role extension in client’s certificate)
Statement

• Client roles (ECU diagnostic Role extension in client’s certificate)

NoneNoneNoneNoneRFQX-CVS31-0131 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0132• Client D-RBACC, if provided in the client’s certificate
Statement

• Client D-RBACC, if provided in the client’s certificate

NoneNoneNoneNoneRFQX-CVS31-0132 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0133The server shall support only one authentication state.
Statement

The server shall support only one authentication state.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0133 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0134The server shall support only one authentication pending state.
Statement

The server shall support only one authentication pending state.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0134 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0135The ephemeralPublicKeyClient in the proofOfOwnership-request (from the client) and the ephemeralPublicKeyClient in the verifyCertificate-response (from the server) consists of a Curve25519 [RFC 7748] public key.
Statement

The ephemeralPublicKeyClient in the proofOfOwnership-request (from the client) and the ephemeralPublicKeyClient in the verifyCertificate-response (from the server) consists of a Curve25519 [RFC 7748] public key.

NoneNoneNoneNoneRFQX-CVS31-0135 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0136An overview of the key-exchange process is shown in Figure 4.
Statement

An overview of the key-exchange process is shown in Figure 4.

NoneNoneNoneNoneRFQX-CVS31-0136 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0137The private keys shall be generated using a CRNG.
Statement

The private keys shall be generated using a CRNG.

SSR-KEY-002Key and Certificate Handling — Key and Certificate HandlingAD-008componentRFQX-CVS31-0137 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0138The sessionKey shall be generated according to the pseudo code below.
Statement

The sessionKey shall be generated according to the pseudo code below.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0138 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0139ephemeralPublicKeyServer) ephemeralPublicKeyServer, ephemeralPrivateKeyServer:= Curve25519() sessionKey := X25519(ephemeralPrivateKeyServer, ephemeralPublicKeyClient) sessionKey := X25519(ephemeralPrivateKeyClient , ephemeralPublicKeyServer) ephemeralPublicKeyClient, ephemeralPrivateKeyClient := Curve25519() ProofOfOwnership(...) VerifyCertificate(...) Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange 4.4 External usage of the sessionKey The sessionKey is used outside the Authentication (ISO 14229-1:2020) service and is run through a key derivation function defined in (CVS32) to derive a key that can be used for securedDataTransmission communication.
Statement

ephemeralPublicKeyServer) ephemeralPublicKeyServer, ephemeralPrivateKeyServer:= Curve25519() sessionKey := X25519(ephemeralPrivateKeyServer, ephemeralPublicKeyClient) sessionKey := X25519(ephemeralPrivateKeyClient , ephemeralPublicKeyServer) ephemeralPublicKeyClient, ephemeralPrivateKeyClient := Curve25519() ProofOfOwnership(...) VerifyCertificate(...) Figure 4 – Overview Ephemeral Diffie-Hellman key-exchange 4.4 External usage of the sessionKey The sessionKey is used outside the Authentication (ISO 14229-1:2020) service and is run through a key derivation function defined in (CVS32) to derive a key that can be used for securedDataTransmission communication.

NoneNoneNoneNoneRFQX-CVS31-0139 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0140The SessionKey is referred as SecuredDataTransmissionKey in (CVS32).
Statement

The SessionKey is referred as SecuredDataTransmissionKey in (CVS32).

NoneNoneNoneNoneRFQX-CVS31-0140 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0141The server shall ensure that the sessionKey is exclusively used for the application responsible for communication over securedDataTransmission (CVS32).
Statement

The server shall ensure that the sessionKey is exclusively used for the application responsible for communication over securedDataTransmission (CVS32).

SSR-COM-006Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-001componentRFQX-CVS31-0141 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0142Solution for a CRNG shall be according to (CVS150).
Statement

Solution for a CRNG shall be according to (CVS150).

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0142 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0143The server shall always allow the Authentication 0x29 service (ISO 14229-1:2020) regardless of
Statement

The server shall always allow the Authentication 0x29 service (ISO 14229-1:2020) regardless of

SSR-RBAC-004Secure Diagnostics / RBAC — Secure Diagnostics / RBACAD-001componentRFQX-CVS31-0143 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0144Example: If the server’s RBACC is for some reason corrupt or misconfigured this would lock out the client from doing diagnostics (the server will refuse all diagnostics).
Statement

Example: If the server’s RBACC is for some reason corrupt or misconfigured this would lock out the client from doing diagnostics (the server will refuse all diagnostics).

NoneNoneNoneNoneRFQX-CVS31-0144 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0145Two passive de-authentication mechanisms are described in (ISO 14229-1:2020).
Statement

Two passive de-authentication mechanisms are described in (ISO 14229-1:2020).

NoneNoneNoneNoneRFQX-CVS31-0145 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0146Only Passive time-based de-authentication shall be supported.
Statement

Only Passive time-based de-authentication shall be supported.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0146 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0147The server shall start the timer (A3) after a valid proofOfOwnership has been received.
Statement

The server shall start the timer (A3) after a valid proofOfOwnership has been received.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0147 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0148The server shall restart the timer (A3) every time a request is received by the same client.
Statement

The server shall restart the timer (A3) every time a request is received by the same client.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0148 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0149For this requirement, “same client” refers to a request that originates from the same tester address as the tester currently authenticated by the server.
Statement

For this requirement, “same client” refers to a request that originates from the same tester address as the tester currently authenticated by the server.

NoneNoneNoneNoneRFQX-CVS31-0149 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0150When a request is received, authenticated or not, the server upon verifying it is from the same client will restart the timer (A3).
Statement

When a request is received, authenticated or not, the server upon verifying it is from the same client will restart the timer (A3).

NoneNoneNoneNoneRFQX-CVS31-0150 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0151If the A3 timer timeouts before a new request is received (from the same client), the server shall invalidate the authentication state.
Statement

If the A3 timer timeouts before a new request is received (from the same client), the server shall invalidate the authentication state.

SSR-TOOL-002Tooling / IT / Evidence Storage — Tooling / IT / Evidence StorageAD-002componentRFQX-CVS31-0151 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0152The parameter for passive timeout based deAuthenticate shall be decided in the project.
Statement

The parameter for passive timeout based deAuthenticate shall be decided in the project.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0152 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0153The A3 timer differs from S3 timer in terms of expected behavior during timeout and should not be implemented as a single timer.
Statement

The A3 timer differs from S3 timer in terms of expected behavior during timeout and should not be implemented as a single timer.

NoneNoneAD-008componentRFQX-CVS31-0153 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0154The delay timer represents the required minimum time between verifyCertificateBidirectional
Statement

The delay timer represents the required minimum time between verifyCertificateBidirectional

NoneNoneAD-008componentRFQX-CVS31-0154 / 56hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredCOMPLETE
RFQX-CVS31-0155The delay timer shall be set to 1 second.
Statement

The delay timer shall be set to 1 second.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0155 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0156If the delay timer is not running, the server shall start it as part of verifyCertificateBidirectional request.
Statement

If the delay timer is not running, the server shall start it as part of verifyCertificateBidirectional request.

SSR-KEY-003Key and Certificate Handling — Key and Certificate HandlingAD-002componentRFQX-CVS31-0156 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0157If the server can determine that a delay is not running after reset, it shall accept a subsequent authentication request without any delay.
Statement

If the server can determine that a delay is not running after reset, it shall accept a subsequent authentication request without any delay.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS31-0157 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0158If the server cannot determine that a delay is not running after reset, it shall not accept a subsequent authentication request without any delay.
Statement

If the server cannot determine that a delay is not running after reset, it shall not accept a subsequent authentication request without any delay.

SSR-COM-004Secure Communication and Boundary Control — Secure Communication and Boundary ControlAD-002componentRFQX-CVS31-0158 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS31-0159The Authentication completion timer represents the timeframe that the client is allowed to perform proofOfOwnership request after a verifyCertificateBidirectional request.
Statement

The Authentication completion timer represents the timeframe that the client is allowed to perform proofOfOwnership request after a verifyCertificateBidirectional request.

NoneNoneNoneNoneRFQX-CVS31-0159 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; certificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0160The Authentication completion timer shall be set to 1 minute.
Statement

The Authentication completion timer shall be set to 1 minute.

SSR-SYS-001System Function — System FunctionAD-008componentRFQX-CVS31-0160 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS31-0161The Authentication completion timer is started upon positive response for verifyCertificateBidirectional request.
Statement

The Authentication completion timer is started upon positive response for verifyCertificateBidirectional request.

NoneNoneNoneNoneRFQX-CVS31-0161 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0162Migrated Req.
Statement

Migrated Req. into

NoneNoneNoneNoneRFQX-CVS31-0162 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0163Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0163 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0164Removed AUTH_REQ 137 since it is covered by AUTH_REQ 135 Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported
Statement

Removed AUTH_REQ 137 since it is covered by AUTH_REQ 135 Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported

NoneNoneNoneNoneRFQX-CVS31-0164 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0165Annex B (informative) Change history Release Date Changes The whole standard has been reworked and shall be read in its entirety.
Statement

Annex B (informative) Change history Release Date Changes The whole standard has been reworked and shall be read in its entirety.

NoneNoneAD-008componentRFQX-CVS31-0165 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0166to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0166 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0167Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0167 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0168to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0168 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0169Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0169 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0170to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0170 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0171Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0171 / 21hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0172to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0172 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0173Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0173 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0174to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0174 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0175Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0175 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0176to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0176 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0177Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0177 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0178to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0178 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0179Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0179 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0180to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0180 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0181Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0181 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0182to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0182 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0183Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0183 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0184to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0184 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0185Duplicated AUTH_INFO due to typo.
Statement

Duplicated AUTH_INFO due to typo.

NoneNoneNoneNoneRFQX-CVS31-0185 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0186to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0186 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0187Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0187 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0188to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0188 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0189Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0189 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0190to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0190 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0191Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0191 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0192to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0192 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0193Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0193 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0194to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0194 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0195Changed tag
Statement

Changed tag

NoneNoneNoneNoneRFQX-CVS31-0195 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0196to
Statement

to

NoneNoneNoneNoneRFQX-CVS31-0196 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0197Removed Unused reference Fixed wrong cross reference Migrated Annex A “ephemeralPublicKey” into new chapter 3.3 “SessionKey” and added pseudo code for sessionKey Migrated Info into
Statement

Removed Unused reference Fixed wrong cross reference Migrated Annex A “ephemeralPublicKey” into new chapter 3.3 “SessionKey” and added pseudo code for sessionKey Migrated Info into

NoneNoneNoneNoneRFQX-CVS31-0197 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0198Migrated Info into
Statement

Migrated Info into

NoneNoneNoneNoneRFQX-CVS31-0198 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0199Migrated Req.
Statement

Migrated Req.

NoneNoneNoneNoneRFQX-CVS31-0199 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0200Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0200 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0201Added chapter for Certificate validity Added
Statement

Added chapter for Certificate validity Added

NoneNoneNoneNoneRFQX-CVS31-0201 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredCOMPLETE
RFQX-CVS31-0202Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0202 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0203Added OID for client authentication Changed
Statement

Added OID for client authentication Changed

NoneNoneNoneNoneRFQX-CVS31-0203 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0204Fixed typo Changed
Statement

Fixed typo Changed

NoneNoneNoneNoneRFQX-CVS31-0204 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0205(Removed “shown in only”) Changed
Statement

(Removed “shown in only”) Changed

NoneNoneNoneNoneRFQX-CVS31-0205 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0206(VerifyCertificateres -> VerifyCertificates) Changed Table 5 (lengthofCertificateClient -> lengthOfCertificateClient) Changed Table 6 (lengthOfCertitifacteServer -> lengthOfCertificateServer) Changed
Statement

(VerifyCertificateres -> VerifyCertificates) Changed Table 5 (lengthofCertificateClient -> lengthOfCertificateClient) Changed Table 6 (lengthOfCertitifacteServer -> lengthOfCertificateServer) Changed

NoneNoneNoneNoneRFQX-CVS31-0206 / 56hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0207(fails -> failure) Changed
Statement

(fails -> failure) Changed

NoneNoneNoneNoneRFQX-CVS31-0207 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0208(fails -> failure) Changed Table 7 (EphemeralPublicKeyClient -> ephemeralPublicKeyClient) Removed ambiguity Changed
Statement

(fails -> failure) Changed Table 7 (EphemeralPublicKeyClient -> ephemeralPublicKeyClient) Removed ambiguity Changed

NoneNoneNoneNoneRFQX-CVS31-0208 / 24hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredCOMPLETE
RFQX-CVS31-0209Removed
Statement

Removed

NoneNoneNoneNoneRFQX-CVS31-0209 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0210since it is covered by
Statement

since it is covered by

NoneNoneNoneNoneRFQX-CVS31-0210 / 4hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0211Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported
Statement

Removed in Annex A the reference to verifyCertificatesUniDirectional since it is not supported

NoneNoneNoneNoneRFQX-CVS31-0211 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0212Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0212 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0213Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0213 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0214Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0214 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0215Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0215 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0216Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0216 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0217Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0217 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0218Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0218 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0219Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0219 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0220Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0220 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0221Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0221 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0222Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0222 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0223Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0223 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0224Removed
Statement

Removed

NoneNoneNoneNoneRFQX-CVS31-0224 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0225Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0225 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0226Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0226 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0227Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0227 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0228and
Statement

and

NoneNoneNoneNoneRFQX-CVS31-0228 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0229Updated document quirks chapter Removed the information that italic terms are often clickable.
Statement

Updated document quirks chapter Removed the information that italic terms are often clickable.

NoneNoneNoneNoneRFQX-CVS31-0229 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0230Reformulation for clarity improvement Changed
Statement

Reformulation for clarity improvement Changed

NoneNoneNoneNoneRFQX-CVS31-0230 / 21hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0231Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0231 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0232Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0232 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0233Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0233 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0234Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0234 / 5hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0235Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0235 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0236Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0236 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0237Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0237 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0238Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0238 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0239Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0239 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0240Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0240 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0241Changed
Statement

Changed

NoneNoneNoneNoneRFQX-CVS31-0241 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0242Changed Table 3 (Authentication pending state and authentication state) Changed Table 5 (Changed column name POO -> proofOfOwnershipServer) Changed Table 6 (Changed column name POO -> proofOfOwnershipServer) Changed
Statement

Changed Table 3 (Authentication pending state and authentication state) Changed Table 5 (Changed column name POO -> proofOfOwnershipServer) Changed Table 6 (Changed column name POO -> proofOfOwnershipServer) Changed

NoneNoneNoneNoneRFQX-CVS31-0242 / 24hNot importedNo linked clarificationNo P1 linkboundary ownership; backend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS31-0243(Changed POO -> proofOfOwnershipServer) Removed
Statement

(Changed POO -> proofOfOwnershipServer) Removed

NoneNoneNoneNoneRFQX-CVS31-0243 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0244(Maximum size of elements is to be defined by max size of certificate) Added
Statement

(Maximum size of elements is to be defined by max size of certificate) Added

NoneNoneNoneNoneRFQX-CVS31-0244 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0245(Maximum size of elements is to be defined by max size of certificate) Updated Figure 3 Reformulation requirements over the length of client certificate Removed
Statement

(Maximum size of elements is to be defined by max size of certificate) Updated Figure 3 Reformulation requirements over the length of client certificate Removed

NoneNoneNoneNoneRFQX-CVS31-0245 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; certificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0246Added Chapter 2.1.1.2 lengthOfCertificateClient Added
Statement

Added Chapter 2.1.1.2 lengthOfCertificateClient Added

NoneNoneNoneNoneRFQX-CVS31-0246 / 24hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0247Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0247 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0248Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0248 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0249Clarified the signature algorithm to be used over the authentication process Removed
Statement

Clarified the signature algorithm to be used over the authentication process Removed

NoneNoneNoneNoneRFQX-CVS31-0249 / 26hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS31-0250Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0250 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0251Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0251 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0252Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0252 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-0253Added
Statement

Added

NoneNoneNoneNoneRFQX-CVS31-0253 / 4hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS31-02542025-08 CVS31 First edition 2025-05-30 RFQ 2517 Delivery Added authentication delay timer Added Authentication Completion timer Clarified negative responses cases for each subfunction
Statement

2025-08 CVS31 First edition 2025-05-30 RFQ 2517 Delivery Added authentication delay timer Added Authentication Completion timer Clarified negative responses cases for each subfunction

NoneNoneNoneNoneRFQX-CVS31-0254 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0001The User shall apply the latest version of this CVS32.
Statement

The User shall apply the latest version of this CVS32.

NoneNoneAD-008componentRFQX-CVS32-0001 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS32-0002Foreword This CVS32 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.
Statement

Foreword This CVS32 contains requirement specification for TRATON GROUP and may be used by all within TRATON Group, if applicable.

NoneNoneNoneNoneRFQX-CVS32-0002 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0003Any review of CVS32 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”.
Statement

Any review of CVS32 shall only be done in agreement with the involved departments stated in the table on the first page under section “Technical responsibility”.

NoneNoneAD-003componentRFQX-CVS32-0003 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS32-0004• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.
Statement

• Affiliate means any legal entity that directly or indirectly controls, is controlled by, or is commonly controlled with TRATON SE, it is being understood that “control” shall mean ownership of at least 50% of the voting rights or interest in the issued share capital, including for the avoidance of doubt any branch.

NoneNoneAD-002componentRFQX-CVS32-0004 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS32-0005Summary
Statement

The purpose of this document is to clarify vehicle manufacturer specific extensions and exceptions to the SecuredDataTransmission 0x84 service specified in ISO14229-1:2020 [1]. This specification does not include any redundant requirements of the normative and indispensable documents referenced below. It contains only clarifications of the requirements and recommendations in these documents together with exceptions and additional requirements that apply to this standard in relation to these documents. The following documents are normative and indispensable for the application of this document: • TRATON Specification on Unified diagnostic Services (UDS) requirements [8] • ISO 14229-1:2020, Road vehicles — Unified diagnostic services (UDS) — Part 1: Specification and requirements [1]

NoneNoneNoneNoneRFQX-CVS32-0005 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0006Target Reader
Statement

The target readers for this specification are ECU-suppliers and ECU-developers in reference to the server-side requirements, and diagnostic tool developers and back-end service providers regarding the client-side requirements. These “target readers” can be either internal or external in relation to the vehicle manufacturer.

NoneNoneNoneNoneRFQX-CVS32-0006 / 56hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0007Document Quirks
Statement

The mnemonics defined in the ISO14229-1:2020 [1] standard are reused throughout this document. Some paragraphs in this document includes pseudo code. The pseudo code make use of the following notation: 𝑋 || 𝑌 The concatenation of the octet strings 𝑋 and 𝑌 𝑋𝑠𝑒𝑟𝑣𝑒𝑟 𝑋 is owned by the Server 𝑋𝑐𝑙𝑖𝑒𝑛𝑡 𝑋 is owned by the Client The first occurrence of an abbreviation or term in this document will appear italicized to indicate that it is explained in section 1.4 Abbreviations or section 1.5 Terminology. All paragraphs from here on in this document are assigned unique tags, composed of a prefix and an identification number for non-ambiguous identification. SDT_REQ X identifies a requirement, and tag SDT_INFO X is used to denote informational text. Whether a requirement refers to client-side or server-side behavior is clear from the context and the requirement text itself. The keywords “shall”, “should”, “must” and so forth are used in this document and are to be interpreted in accordance with “Key words for use in RFCs to Indicate Requirement Levels” [10].

SSR-KEY-004Secure communication and freshness protection — Key and Certificate HandlingAD-007componentRFQX-CVS32-0007 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0008The keywords “shall”, “should”, “must” and so forth are used in this document and are to be interpreted in accordance with “Key words for use in RFCs to Indicate Requirement Levels” [10].
Statement

The keywords “shall”, “should”, “must” and so forth are used in this document and are to be interpreted in accordance with “Key words for use in RFCs to Indicate Requirement Levels” [10].

NoneNoneAD-007componentRFQX-CVS32-0008 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS32-0009The implementation of SDT (SecuredDataTransmission) shall follow the information provided in
Statement

The implementation of SDT (SecuredDataTransmission) shall follow the information provided in

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0009 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0010Although SDT (service 0x84) is of course part of UDS, in this document, SDT is treated much like a transport layer for other UDS services.
Statement

Although SDT (service 0x84) is of course part of UDS, in this document, SDT is treated much like a transport layer for other UDS services.

NoneNoneNoneNoneRFQX-CVS32-0010 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0011Figure 1 shows the layout of an SDT message with its protocol elements (for details refer to ISO 14229-1:2020 [1]).
Statement

Figure 1 shows the layout of an SDT message with its protocol elements (for details refer to ISO 14229-1:2020 [1]).

NoneNoneNoneNoneRFQX-CVS32-0011 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0012Whenever a requirement in this document deviates from requirements in ISO14229-1 [1] the requirements of this document shall take precedence.
Statement

Whenever a requirement in this document deviates from requirements in ISO14229-1 [1] the requirements of this document shall take precedence.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0012 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0013ECUs with diagnostic servers in multiple execution states, e.g.
Statement

ECUs with diagnostic servers in multiple execution states, e.g.

NoneNoneNoneNoneRFQX-CVS32-0013 / 29hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0014one diagnostic server in the boot-loader and one in the application, shall support SDT in all execution states.
Statement

one diagnostic server in the boot-loader and one in the application, shall support SDT in all execution states.

NoneNoneAD-007componentRFQX-CVS32-0014 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS32-0015A prerequisite for the SDT service is that a SecuredDataTransmissionKey has been established between client and server using the 0x29 service [6].
Statement

A prerequisite for the SDT service is that a SecuredDataTransmissionKey has been established between client and server using the 0x29 service [6].

NoneNoneNoneNoneRFQX-CVS32-0015 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0016The SDT server shall use the diagnostic tester address of the SDT client to identify the authentication state and hence the SecuredDataTransmissionKey.
Statement

The SDT server shall use the diagnostic tester address of the SDT client to identify the authentication state and hence the SecuredDataTransmissionKey.

SSR-RBAC-007Secure communication and freshness protection — Secure Diagnostics / RBACAD-007componentRFQX-CVS32-0016 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0017(There may be more than one authentication state).
Statement

(There may be more than one authentication state).

NoneNoneNoneNoneRFQX-CVS32-0017 / 56hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0018The number of concurrently active SDT sequences is limited by the number of authentication states that a server is allowed to maintain, refer to [6].
Statement

The number of concurrently active SDT sequences is limited by the number of authentication states that a server is allowed to maintain, refer to [6].

NoneNoneNoneNoneRFQX-CVS32-0018 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0019The server shall not allow an SDT message with service 0x84 as the application layer service (service 0x84 encapsulated inside another service 0x84).
Statement

The server shall not allow an SDT message with service 0x84 as the application layer service (service 0x84 encapsulated inside another service 0x84).

SSR-COM-011Secure communication and freshness protection — Secure Communication and Boundary ControlAD-001componentRFQX-CVS32-0019 / 24hNot importedNo linked clarificationNo P1 linkdiagnostics exposure; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0020The server shall respond with application layer NRC 0x39, i.e.
Statement

The server shall respond with application layer NRC 0x39, i.e.

NoneNoneAD-001componentRFQX-CVS32-0020 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCEBLOCKED BY CUSTOMER DECISION
RFQX-CVS32-0021the response shall be a properly formatted SDT positive 3 ISO 14299-1:2020 Clarifications and Deviations 3.1 Anti-replay Protection and Transaction Coherency Anti-replay protection for SDT messages is provided by the ANTIREPLAYCNT protocol element.
Statement

the response shall be a properly formatted SDT positive 3 ISO 14299-1:2020 Clarifications and Deviations 3.1 Anti-replay Protection and Transaction Coherency Anti-replay protection for SDT messages is provided by the ANTIREPLAYCNT protocol element.

NoneNoneAD-005interfaceRFQX-CVS32-0021 / 24hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0022This specification defines two counters, one for the request messages and one for responses.
Statement

This specification defines two counters, one for the request messages and one for responses.

NoneNoneNoneNoneRFQX-CVS32-0022 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0023The reason for the two separate counters is that the UDS standard allows for a request to result in multiple responses, e.g.
Statement

The reason for the two separate counters is that the UDS standard allows for a request to result in multiple responses, e.g.

NoneNoneNoneNoneRFQX-CVS32-0023 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0024The state variables needed to keep track of these counters are called PREQARC (Previous REQuest Anti-Replay Counter) and PRESARC (Previous RESponse Anti-Replay Counter).
Statement

The state variables needed to keep track of these counters are called PREQARC (Previous REQuest Anti-Replay Counter) and PRESARC (Previous RESponse Anti-Replay Counter).

NoneNoneNoneNoneRFQX-CVS32-0024 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0025Both client and server shall maintain instances of the state variables PREQARC and PRESARC.
Statement

Both client and server shall maintain instances of the state variables PREQARC and PRESARC.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0025 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0026At construction of an SDT request, the client shall increment PREQARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value.
Statement

At construction of an SDT request, the client shall increment PREQARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0026 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0027At reception of an SDT request, the server shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PREQARC, and if the message can be otherwise verified, update PREQARC to reflect the new value, i.e.
Statement

At reception of an SDT request, the server shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PREQARC, and if the message can be otherwise verified, update PREQARC to reflect the new value, i.e.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0027 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0028At construction of an SDT response, the server shall increment PRESARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value.
Statement

At construction of an SDT response, the server shall increment PRESARC by one (1) and populate the ANTIREPLAYCNT protocol element with the resulting value.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0028 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0029At reception of an SDT response, the client shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PRESARC, and if the message can be otherwise verified, update PRESARC to reflect the new value, i.e.
Statement

At reception of an SDT response, the client shall verify that the value of the ANTIREPLAYCNT protocol element is greater than PRESARC, and if the message can be otherwise verified, update PRESARC to reflect the new value, i.e.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0029 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0030The client should populate the ANTIREPLAYCNT protocol element of the first request of an
Statement

The client should populate the ANTIREPLAYCNT protocol element of the first request of an

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0030 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0031The server should populate the ANTIREPLAYCNT protocol element of the first response of an SDT sequence with the value zero (0), and set PRESARC accordingly.
Statement

The server should populate the ANTIREPLAYCNT protocol element of the first response of an SDT sequence with the value zero (0), and set PRESARC accordingly.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0031 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0032It is good practise to start a sequence with ANTIREPLAYCNT set to zero (0), but this is not something that is enforced by the recipient of the message, be it the first request or response.
Statement

It is good practise to start a sequence with ANTIREPLAYCNT set to zero (0), but this is not something that is enforced by the recipient of the message, be it the first request or response.

NoneNoneNoneNoneRFQX-CVS32-0032 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0033If either PREQARC or PRESARC reaches the maximum value 65535 (0xFFFF), the client shall re-authenticate if it wishes to send more messages.
Statement

If either PREQARC or PRESARC reaches the maximum value 65535 (0xFFFF), the client shall re-authenticate if it wishes to send more messages.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0033 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0034The server handles the exhaustion of PREQARC and PRESARC with its “normal behavior”.
Statement

The server handles the exhaustion of PREQARC and PRESARC with its “normal behavior”.

NoneNoneNoneNoneRFQX-CVS32-0034 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0035).
Statement

).

NoneNoneNoneNoneRFQX-CVS32-0035 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0036).
Statement

).

NoneNoneNoneNoneRFQX-CVS32-0036 / 19hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredCOMPLETE
RFQX-CVS32-0037The requirements above are illustrated in Figure 2.
Statement

The requirements above are illustrated in Figure 2.

NoneNoneNoneNoneRFQX-CVS32-0037 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0038Apart from ensuring that old messages are not replayed, it is also necessary for the client to be able to determine that an incoming response is actually a response to the request that is currently outstanding.
Statement

Apart from ensuring that old messages are not replayed, it is also necessary for the client to be able to determine that an incoming response is actually a response to the request that is currently outstanding.

NoneNoneNoneNoneRFQX-CVS32-0038 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0039Since any CipherScheme supported by this specification will at least authenticate messages, there will always be a TAG (MAC or similar) populated in the SIGMACBYTE protocol element of all SDT messages.
Statement

Since any CipherScheme supported by this specification will at least authenticate messages, there will always be a TAG (MAC or similar) populated in the SIGMACBYTE protocol element of all SDT messages. This TAG is used to guarantee request/response coherency and the corresponding state variable is called PREQTAG (Previous REQuest TAG).

NoneNoneNoneNoneRFQX-CVS32-0039 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0040The client shall maintain the state variable PREQTAG.
Statement

The client shall maintain the state variable PREQTAG.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0040 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0041The requirements regarding PREQTAG are detailed in sections 3.2.2 and 3.2.3 since they differ slightly between CipherSchemes.
Statement

The requirements regarding PREQTAG are detailed in sections 3.2.2 and 3.2.3 since they differ slightly between CipherSchemes.

NoneNoneNoneNoneRFQX-CVS32-0041 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0042Figure 3 illustrates transaction coherency and the use of PREQTAG.
Statement

Figure 3 illustrates transaction coherency and the use of PREQTAG.

NoneNoneNoneNoneRFQX-CVS32-0042 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0043The authenticity, and optionally confidentiality, of an SDT message is provided by the CipherScheme with which the SDT message is authenticated/encrypted.
Statement

The authenticity, and optionally confidentiality, of an SDT message is provided by the CipherScheme with which the SDT message is authenticated/encrypted.

NoneNoneNoneNoneRFQX-CVS32-0043 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0044The CipherScheme used when constructing an SDT message shall be indicated by the SIGENCRYPT protocol element according to Table 2.
Statement

The CipherScheme used when constructing an SDT message shall be indicated by the SIGENCRYPT protocol element according to Table 2.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0044 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0045The supported CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305 [9] are described in sections 3.2.2 and 3.2.3 respectively.
Statement

The supported CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305 [9] are described in sections 3.2.2 and 3.2.3 respectively. The two CipherSchemes require different key material. The Key Derivation Function (KDF) is described in section 3.2.1.

NoneNoneNoneNoneRFQX-CVS32-0045 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0046The CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305 shall be supported.
Statement

The CipherSchemes SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305 shall be supported.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0046 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0047At SDT message reception, the recipient shall verify/decrypt the message using the CipherScheme indicated by the SIGENCRYPT protocol element.
Statement

At SDT message reception, the recipient shall verify/decrypt the message using the CipherScheme indicated by the SIGENCRYPT protocol element.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0047 / 18hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0048In case of a positive SDT response, the server shall respond to a client request with the same CipherScheme used in the request.
Statement

In case of a positive SDT response, the server shall respond to a client request with the same CipherScheme used in the request.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0048 / 26hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0049The client may alter the CipherScheme between SDT requests within the same SDT sequence.
Statement

The client may alter the CipherScheme between SDT requests within the same SDT sequence.

NoneNoneNoneNoneRFQX-CVS32-0049 / 18hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0050Since the two CipherSchemes require different key material, the KDF has to be re-run if the CipherScheme changes.
Statement

Since the two CipherSchemes require different key material, the KDF has to be re-run if the CipherScheme changes.

NoneNoneNoneNoneRFQX-CVS32-0050 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0051Client and server should keep state variables that indicate which CipherScheme, and resulting key, was used in the previous SDT transaction.
Statement

Client and server should keep state variables that indicate which CipherScheme, and resulting key, was used in the previous SDT transaction.

SSR-KEY-004Secure communication and freshness protection — Key and Certificate HandlingAD-007componentRFQX-CVS32-0051 / 26hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0052In the following, these state variables are called PSIGENCRYPT (Previous SIGENCRYPT) and PKEY (Previous KEY).
Statement

In the following, these state variables are called PSIGENCRYPT (Previous SIGENCRYPT) and PKEY (Previous KEY).

NoneNoneNoneNoneRFQX-CVS32-0052 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0053At construction of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the client should re-run the KDF, and if and only if the authentication/encryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values.
Statement

At construction of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the client should re-run the KDF, and if and only if the authentication/encryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0053 / 32hNot importedNo linked clarificationNo P1 linkboot/update trust; certificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0054At reception of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the server should re-run the KDF, and if and only if the verification/decryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values.
Statement

At reception of an SDT request, if SIGENCRYPT is different from PSIGENCRYPT, the server should re-run the KDF, and if and only if the verification/decryption succeeds, update the state variables PSIGENCRYPT and PKEY with the new values.

SSR-VV-004Secure communication and freshness protection — Verification and ValidationAD-002componentRFQX-CVS32-0054 / 32hNot importedNo linked clarificationNo P1 linkboot/update trust; certificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0055Figure 4 illustrates the switching of CipherSchemes within an SDT sequence.
Statement

Figure 4 illustrates the switching of CipherSchemes within an SDT sequence. The client has previously used CipherScheme 3, and for request X+1, switches to 2. The server reacts on the different SIGENCRYPT and updates its state accordingly. Client Server PREQARC = X

NoneNoneNoneNoneRFQX-CVS32-0055 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0056Client Server PREQARC = X PREQTAG=TAG_X PSIGENCRYPT=3 PKEY=p..p Check: ANTIREPLAYCNT > PREQARC SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r decrypt(data, TAG_X+1)->ok Check: ANTIREPLAYCNT > PRESARC decrypt(data||PREQTAG, TAG_Y+1)->ok PRESARC = Y+1 PRESARC = Y+1 PREQARC = X PSIGENCRYPT=3 PKEY=p..p encrypt(data)->TAG_X+1 encrypt(data||TAG_X+1)->TAG_Y+1 S1 S2 S3 C1 C2 C3 SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r Figure 4 – Change of CipherScheme mid sequence 3.2.1 HKDF Key Derivation Client and server shall support the HKDF [2] key derivation function using HMAC-SHA512 [3].
Statement

Client Server PREQARC = X PREQTAG=TAG_X PSIGENCRYPT=3 PKEY=p..p Check: ANTIREPLAYCNT > PREQARC SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r decrypt(data, TAG_X+1)->ok Check: ANTIREPLAYCNT > PRESARC decrypt(data||PREQTAG, TAG_Y+1)->ok PRESARC = Y+1 PRESARC = Y+1 PREQARC = X PSIGENCRYPT=3 PKEY=p..p encrypt(data)->TAG_X+1 encrypt(data||TAG_X+1)->TAG_Y+1 S1 S2 S3 C1 C2 C3 SIGENCRYPT != PSIGENCRYPT: KDF(..) -> r..r Figure 4 – Change of CipherScheme mid sequence 3.2.1 HKDF Key Derivation Client and server shall support the HKDF [2] key derivation function using HMAC-SHA512 [3].

SSR-KEY-004Secure communication and freshness protection — Key and Certificate HandlingAD-007componentRFQX-CVS32-0056 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0057ikm : The ikm argument to the HKDF function shall be the octet string containing the SecuredDataTransmissionKey from the service 0x29 authentication state.
Statement

ikm : The ikm argument to the HKDF function shall be the octet string containing the SecuredDataTransmissionKey from the service 0x29 authentication state.

SSR-RBAC-006Secure communication and freshness protection — Secure Diagnostics / RBACAD-001componentRFQX-CVS32-0057 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0058salt: The salt argument to the HKDF function shall be set as the zero length octet string (null).
Statement

salt: The salt argument to the HKDF function shall be set as the zero length octet string (null).

SSR-COM-011Secure communication and freshness protection — Secure Communication and Boundary ControlAD-001componentRFQX-CVS32-0058 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0059info: The info argument to the HKDF function shall be set as the concatenation of the “SDT_0x84_KEY” octet string and the CipherScheme identifier.
Statement

info: The info argument to the HKDF function shall be set as the concatenation of the “SDT_0x84_KEY” octet string and the CipherScheme identifier.

SSR-COM-011Secure communication and freshness protection — Secure Communication and Boundary ControlAD-001componentRFQX-CVS32-0059 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; diagnostics exposureNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0060Example: “SDT_0x84_KEY” = 5344545F307838345F4B4559 (UTF-8 encoded hex) CipherScheme = 02 (SDT_AEAD_CHACHA20_POLY1305) ➔ info := 5344545F307838345F4B455902
Statement

Example: “SDT_0x84_KEY” = 5344545F307838345F4B4559 (UTF-8 encoded hex) CipherScheme = 02 (SDT_AEAD_CHACHA20_POLY1305) ➔ info := 5344545F307838345F4B455902

NoneNoneNoneNoneRFQX-CVS32-0060 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0061L: The L argument determines the length of okm and is determined by whichever CipherScheme to be used, see sections 3.2.2 and 3.2.3.
Statement

L: The L argument determines the length of okm and is determined by whichever CipherScheme to be used, see sections 3.2.2 and 3.2.3.

NoneNoneNoneNoneRFQX-CVS32-0061 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0062okm is the output key material octet string of length L.
Statement

okm is the output key material octet string of length L.

NoneNoneNoneNoneRFQX-CVS32-0062 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handlingMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0063This section describes a CipherScheme based on AEAD_CHACHA20_POLY1305 [9].
Statement

This section describes a CipherScheme based on AEAD_CHACHA20_POLY1305 [9].

NoneNoneNoneNoneRFQX-CVS32-0063 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0064The L argument to the HKDF function shall be set to 64.
Statement

The L argument to the HKDF function shall be set to 64.

SSR-COM-011Secure communication and freshness protection — Secure Communication and Boundary ControlAD-001componentRFQX-CVS32-0064 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0065Octets 0-31 of the okm shall be used as key by the client to encrypt, and the server to decrypt, the request.
Statement

Octets 0-31 of the okm shall be used as key by the client to encrypt, and the server to decrypt, the request.

SSR-KEY-004Secure communication and freshness protection — Key and Certificate HandlingAD-007componentRFQX-CVS32-0065 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0066Octets 32-63 of the okm shall be used as key by the server to encrypt, and the client to decrypt, the response.
Statement

Octets 32-63 of the okm shall be used as key by the server to encrypt, and the client to decrypt, the response.

SSR-KEY-004Secure communication and freshness protection — Key and Certificate HandlingAD-007componentRFQX-CVS32-0066 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0067The above requirements are visualized in Figure 5.
Statement

The above requirements are visualized in Figure 5.

NoneNoneNoneNoneRFQX-CVS32-0067 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0068Figure 5 – Use of HKDF output key material (okm) with SDT_CHACHA20_POLY1305 In subsequent sections (3.2.2.1 and 3.2.2.2) the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets.
Statement

Figure 5 – Use of HKDF output key material (okm) with SDT_CHACHA20_POLY1305 In subsequent sections (3.2.2.1 and 3.2.2.2) the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets.

SSR-KEY-004Secure communication and freshness protection — Key and Certificate HandlingAD-007componentRFQX-CVS32-0068 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0069𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT.
Statement

𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0069 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0070𝑃: The 𝑃 (Plaintext) argument shall be the octet string that is the concatenation of the INTMSGREQID and SRVSPECPARAM.
Statement

𝑃: The 𝑃 (Plaintext) argument shall be the octet string that is the concatenation of the INTMSGREQID and SRVSPECPARAM.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0070 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0071𝐶: When injected into, or extracted from an SDT message, the first octet of 𝐶 shall correspond to INTMSGREQID, and the remaining octets to SRVSPECPARAM.
Statement

𝐶: When injected into, or extracted from an SDT message, the first octet of 𝐶 shall correspond to INTMSGREQID, and the remaining octets to SRVSPECPARAM.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0071 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0072The plaintext (𝑃) and ciphertext (𝐶) octet strings are of the same length and a concatenation of the INTMSGREQID and SRVSPECPARAM protocol elements.
Statement

The plaintext (𝑃) and ciphertext (𝐶) octet strings are of the same length and a concatenation of the INTMSGREQID and SRVSPECPARAM protocol elements.

NoneNoneNoneNoneRFQX-CVS32-0072 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0073The client shall encrypt and authenticate the SDT request with the 𝐴 argument set to the
Statement

The client shall encrypt and authenticate the SDT request with the 𝐴 argument set to the

SSR-DAI-009Secure communication and freshness protection — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS32-0073 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0074The client shall populate the APAR protocol element in the request so that bits 0, 4, 5 and 6 are set to true.
Statement

The client shall populate the APAR protocol element in the request so that bits 0, 4, 5 and 6 are set to true.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0074 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0075The client shall populate the SIGLEN protocol element in the request with 16 (0x0010).
Statement

The client shall populate the SIGLEN protocol element in the request with 16 (0x0010).

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0075 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0076The client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.
Statement

The client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0076 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0077The client shall store 𝑇𝐴𝐺 in its state variable PREQTAG.
Statement

The client shall store 𝑇𝐴𝐺 in its state variable PREQTAG.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0077 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0078𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑑𝑒𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝐶, 𝑇𝐴𝐺) → 𝑜𝑘/𝑛𝑜𝑘, 𝑃 The client shall decrypt and verify the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN, ANTIREPLAYCNT protocol elements of the response and the value stored in the state variable PREQTAG.
Statement

𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑑𝑒𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝐶, 𝑇𝐴𝐺) → 𝑜𝑘/𝑛𝑜𝑘, 𝑃 The client shall decrypt and verify the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN, ANTIREPLAYCNT protocol elements of the response and the value stored in the state variable PREQTAG.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0078 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0079element of the response.
Statement

element of the response.

NoneNoneNoneNoneRFQX-CVS32-0079 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0080The server shall decrypt and verify the SDT request with the 𝐴 argument set to the concatenated octet string comprised of the SDT, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements.
Statement

The server shall decrypt and verify the SDT request with the 𝐴 argument set to the concatenated octet string comprised of the SDT, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0080 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0081element of the request.
Statement

element of the request.

NoneNoneNoneNoneRFQX-CVS32-0081 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0082𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑒𝑛𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝑃) → 𝐶, 𝑇𝐴𝐺 The server shall encrypt and authenticate the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the octet string carried by the SIGMACBYTE protocol element of the corresponding request.
Statement

𝐶𝐻𝐴𝐶𝐻𝐴20-POLY1305𝑒𝑛𝑐𝑟𝑦𝑝𝑡(𝐾, 𝑁, 𝐴, 𝑃) → 𝐶, 𝑇𝐴𝐺 The server shall encrypt and authenticate the SDT response with: the 𝐴 argument set to the concatenated octet string comprised of the SDTPR, APAR, SIGENCRYPT, SIGLEN and ANTIREPLAYCNT protocol elements of the response and the octet string carried by the SIGMACBYTE protocol element of the corresponding request.

SSR-DAI-009Secure communication and freshness protection — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS32-0082 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0083The server shall populate the APAR protocol element in the response so that bits 4 and 5 are set to true.
Statement

The server shall populate the APAR protocol element in the response so that bits 4 and 5 are set to true.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0083 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0084The server shall populate the SIGLEN protocol element in the request with 16 (0x0010).
Statement

The server shall populate the SIGLEN protocol element in the request with 16 (0x0010).

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0084 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0085The server shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.
Statement

The server shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0085 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-00860x84 0x02 xx x X+1 SDT APAR 0x84 0x02 xx x X+1 0xC4 0x02 xxxxxxxxxx x Y+1 0xC4 0x02 xxxxxxxxxx x Y+1 SDTPR APAR RDBI SNOETDID 0 633132 KeyrequestHKDF(ikm, salt, info, 64) -> C TAG || CHACHA20-POLY1305enrypt(Keyrequest, N, A, P)-> CHACHA20-POLY1305decrypt(Keyrequest, N, A, C, TAG)-> S Keyresponse SecuredDataTransmissionKey (ikm) from 0x29 service Client s state variables PREQTAG=TAG_X Server s state variables C 0x22 || Application layer P A || || RDBI0x22 Application layer SNOETDID S C TAG P A CHACHA20-POLY1305enrypt(Keyresponse, N, A, P)-> RDBIPR0x62 0xF19743564320435 64331 SNOETDID Application layer || C TAG S C 6 A || CHACHA20-POLY1305decrypt(Keyresponse, N, A, C, TAG)-> || || RDBIPR SNOETDID 0x62 0xF19743564320435 64331 Application layer S P P ||X+1 N ||X+1 N Y+1 || N ||Y+1 Figure 6 – Example of client and server's behavior using SDT_AEAD_CHACHA20_POLY1305 The example in Figure 6 shows an AEAD_CHACHA20_POLY1305 authenticated and encrypted SDT transaction.
Statement

0x84 0x02 xx x X+1 SDT APAR 0x84 0x02 xx x X+1 0xC4 0x02 xxxxxxxxxx x Y+1 0xC4 0x02 xxxxxxxxxx x Y+1 SDTPR APAR RDBI SNOETDID 0 633132 KeyrequestHKDF(ikm, salt, info, 64) -> C TAG || CHACHA20-POLY1305enrypt(Keyrequest, N, A, P)-> CHACHA20-POLY1305decrypt(Keyrequest, N, A, C, TAG)-> S Keyresponse SecuredDataTransmissionKey (ikm) from 0x29 service Client s state variables PREQTAG=TAG_X Server s state variables C 0x22 || Application layer P A || || RDBI0x22 Application layer SNOETDID S C TAG P A CHACHA20-POLY1305enrypt(Keyresponse, N, A, P)-> RDBIPR0x62 0xF19743564320435 64331 SNOETDID Application layer || C TAG S C 6 A || CHACHA20-POLY1305decrypt(Keyresponse, N, A, C, TAG)-> || || RDBIPR SNOETDID 0x62 0xF19743564320435 64331 Application layer S P P ||X+1 N ||X+1 N Y+1 || N ||Y+1 Figure 6 – Example of client and server's behavior using SDT_AEAD_CHACHA20_POLY1305 The example in Figure 6 shows an AEAD_CHACHA20_POLY1305 authenticated and encrypted SDT transaction.

NoneNoneNoneNoneRFQX-CVS32-0086 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0087The encircled “||” denotes concatenation and the concatenation order is top to bottom in the figure.
Statement

The encircled “||” denotes concatenation and the concatenation order is top to bottom in the figure.

NoneNoneNoneNoneRFQX-CVS32-0087 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0088one octet, and the rest should go in the SRVSPECPARAM protocol element.
Statement

one octet, and the rest should go in the SRVSPECPARAM protocol element.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0088 / 8hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredMISSING JIRA LINK
RFQX-CVS32-0089Encrypted data in the figure is denoted “x..x”, one “x” denotes one encrypted octet.
Statement

Encrypted data in the figure is denoted “x..x”, one “x” denotes one encrypted octet.

NoneNoneNoneNoneRFQX-CVS32-0089 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0090This section describes a CipherScheme based on the AEAD_CHACHA20_POLY1305 [9] algorithm.
Statement

This section describes a CipherScheme based on the AEAD_CHACHA20_POLY1305 [9] algorithm. Note that in this CipherScheme we only use the authentication properties of AEAD_CHACHA20_POLY1305 i.e., no encryption/decryption. The requirements in this section are visualized with an example in Figure 8.

NoneNoneNoneNoneRFQX-CVS32-0090 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0091The L argument to the HKDF function shall be set to 64.
Statement

The L argument to the HKDF function shall be set to 64.

SSR-COM-011Secure communication and freshness protection — Secure Communication and Boundary ControlAD-001componentRFQX-CVS32-0091 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0092Octets 0-31 of the okm shall be used as key by the client to authenticate, and the server to verify, the request.
Statement

Octets 0-31 of the okm shall be used as key by the client to authenticate, and the server to verify, the request.

SSR-DAI-009Secure communication and freshness protection — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS32-0092 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0093Octets 32-63 of the okm shall be used as key by the server to authenticate, and the client to verify, the response.
Statement

Octets 32-63 of the okm shall be used as key by the server to authenticate, and the client to verify, the response.

SSR-DAI-009Secure communication and freshness protection — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS32-0093 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handling; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0094The above requirements are visualized in Figure 7.
Statement

The above requirements are visualized in Figure 7.

NoneNoneNoneNoneRFQX-CVS32-0094 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0095Figure 7 – Use of HKDF output key material (okm) with SDT_POLY1305 In subsequent sections (3.2.3.1 and 3.2.3.2), the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets.
Statement

Figure 7 – Use of HKDF output key material (okm) with SDT_POLY1305 In subsequent sections (3.2.3.1 and 3.2.3.2), the following requirements shall be met: 𝐾: The 𝐾 argument shall be the key octet string of 32 octets.

SSR-KEY-004Secure communication and freshness protection — Key and Certificate HandlingAD-007componentRFQX-CVS32-0095 / 29hNot importedNo linked clarificationNo P1 linkcertificate/key handlingNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0096𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT.
Statement

𝑁: The 𝑁 shall be an octet string of length 12, constructed as follows: - the first 10 octets shall be set to 6E6F6E73656E73652121, and - the remaining 2 octets shall be ANTIREPLAYCNT.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0096 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0097𝑃: The 𝑃 (Plaintext) is a zero length octet string (null).
Statement

𝑃: The 𝑃 (Plaintext) is a zero length octet string (null).

NoneNoneNoneNoneRFQX-CVS32-0097 / 19hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0098𝐶: The 𝐶 (Ciphertext) is a zero length octet string (null).
Statement

𝐶: The 𝐶 (Ciphertext) is a zero length octet string (null).

NoneNoneNoneNoneRFQX-CVS32-0098 / 19hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0099The client shall authenticate the SDT request with the 𝐴 argument set to the octet string
Statement

The client shall authenticate the SDT request with the 𝐴 argument set to the octet string

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0099 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0100The client shall populate the APAR protocol element in the request so that bits 0, 5 and 6 are set to true.
Statement

The client shall populate the APAR protocol element in the request so that bits 0, 5 and 6 are set to true.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0100 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0101The client shall populate the SIGLEN protocol element in the request with 16 (0x0010).
Statement

The client shall populate the SIGLEN protocol element in the request with 16 (0x0010).

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0101 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0102The client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.
Statement

The client shall populate the SIGMACBYTE protocol element in the request with 𝑇𝐴𝐺.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0102 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0103The client shall store 𝑇𝐴𝐺 in its state variable PREQTAG.
Statement

The client shall store 𝑇𝐴𝐺 in its state variable PREQTAG.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0103 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0104The client shall verify the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string stored in the state variable PREQTAG.
Statement

The client shall verify the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string stored in the state variable PREQTAG.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0104 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0105element of the response.
Statement

element of the response.

NoneNoneNoneNoneRFQX-CVS32-0105 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0106The server shall verify the SDT request with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element.
Statement

The server shall verify the SDT request with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element.

SSR-COM-012OEM/Customer Review Interface — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0106 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0107element of the request.
Statement

element of the request.

NoneNoneNoneNoneRFQX-CVS32-0107 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0108The server shall authenticate the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string carried by the SIGMACBYTE protocol element of the corresponding request.
Statement

The server shall authenticate the SDT response with the 𝐴 argument set to the octet string comprised of all protocol elements of the SDT response, excluding the SIGMACBYTE protocol element, concatenated with the octet string carried by the SIGMACBYTE protocol element of the corresponding request.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0108 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0109The server shall populate the APAR protocol element in the response so that bit 5 is set to true.
Statement

The server shall populate the APAR protocol element in the response so that bit 5 is set to true.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0109 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0110The server shall populate the SIGLEN protocol element in the response with 16 (0x0010).
Statement

The server shall populate the SIGLEN protocol element in the response with 16 (0x0010).

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0110 / 16hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0111The client shall populate the SIGMACBYTE protocol element in the response with 𝑇𝐴𝐺.
Statement

The client shall populate the SIGMACBYTE protocol element in the response with 𝑇𝐴𝐺.

SSR-COM-007External Interfaces — Secure Communication and Boundary ControlAD-005interfaceRFQX-CVS32-0111 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-01120x84 0x03 0x22 X+1 SDT APAR 0x84 0x03 0x22 X+1 0xC4 0x03 0xF1974356432043564331 0x62 Y+1 0xC4 0x03 0xF1974356432043564331 0x62 Y+1 SDTPR APAR 0 633132 KeyrequestHKDF(ikm, salt, info, 64) -> null TAG || CHACHA20-POLY1305authenticate(Keyrequest, N, A, null)-> CHACHA20-POLY1305verify(Keyrequest, N, A, null, TAG)-> ok Keyresponse SecuredDataTransmissionKey (ikm) from 0x29 service Client s state variables PREQTAG=TAG_X Server s state variables A || TAG A CHACHA20-POLY1305authenticate(Keyresponse, N, A, null)-> || null TAG 8 A CHACHA20-POLY1305verify(Keyrequest, N, A, null, TAG)-> ok || TAG A 8 ||X+1 N ||X+1 N ||Y+1 N ||Y+1 N Figure 8 – Example of client and server's behavior using SDT_POLY1305 The example in Figure 8 shows an AEAD_CHACHA20_POLY1305 authenticated SDT transaction.
Statement

0x84 0x03 0x22 X+1 SDT APAR 0x84 0x03 0x22 X+1 0xC4 0x03 0xF1974356432043564331 0x62 Y+1 0xC4 0x03 0xF1974356432043564331 0x62 Y+1 SDTPR APAR 0 633132 KeyrequestHKDF(ikm, salt, info, 64) -> null TAG || CHACHA20-POLY1305authenticate(Keyrequest, N, A, null)-> CHACHA20-POLY1305verify(Keyrequest, N, A, null, TAG)-> ok Keyresponse SecuredDataTransmissionKey (ikm) from 0x29 service Client s state variables PREQTAG=TAG_X Server s state variables A || TAG A CHACHA20-POLY1305authenticate(Keyresponse, N, A, null)-> || null TAG 8 A CHACHA20-POLY1305verify(Keyrequest, N, A, null, TAG)-> ok || TAG A 8 ||X+1 N ||X+1 N ||Y+1 N ||Y+1 N Figure 8 – Example of client and server's behavior using SDT_POLY1305 The example in Figure 8 shows an AEAD_CHACHA20_POLY1305 authenticated SDT transaction.

NoneNoneNoneNoneRFQX-CVS32-0112 / 56hNot importedStill Requires Customer DecisionNo P1 linkcertificate/key handling; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0113The encircled “||” denotes concatenation and the concatenation order is top to bottom relative the symbol.
Statement

The encircled “||” denotes concatenation and the concatenation order is top to bottom relative the symbol.

NoneNoneNoneNoneRFQX-CVS32-0113 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0114This specification is mainly concerned with errors generated or detected by the client and server’s security sub-layer [1].
Statement

This specification is mainly concerned with errors generated or detected by the client and server’s security sub-layer [1]. General UDS error handling is out of scope of this document. Figure 9 shows how the different “layers”1 interact conceptually.

NoneNoneNoneNoneRFQX-CVS32-0114 / 56hNot importedStill Requires Customer DecisionNo P1 linkboundary ownership; diagnostics exposure; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0115A UDS request/response, in the figure, means any request/response other than SDT (service 0x84).
Statement

A UDS request/response, in the figure, means any request/response other than SDT (service 0x84).

NoneNoneNoneNoneRFQX-CVS32-0115 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0116The SDT positive response may of course contain an encapsulated negative UDS response.
Statement

The SDT positive response may of course contain an encapsulated negative UDS response.

NoneNoneNoneNoneRFQX-CVS32-0116 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0117Figure 10Figure 10 illustrates error- and state handling in the server’s security sub-layer.
Statement

Figure 10Figure 10 illustrates error- and state handling in the server’s security sub-layer.

NoneNoneNoneNoneRFQX-CVS32-0117 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0118Note that the markings in the figure, (“S1” through “S3”), and the values for the state variables are correlated with Figure 3.
Statement

Note that the markings in the figure, (“S1” through “S3”), and the values for the state variables are correlated with Figure 3.

NoneNoneNoneNoneRFQX-CVS32-0118 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0119Other than the NRCs 0x3A, 0x13 and 0x21, specified by ISO14229-1:2020 [1], the server shall support the NRC 0x34 “authenticationRequired”.
Statement

Other than the NRCs 0x3A, 0x13 and 0x21, specified by ISO14229-1:2020 [1], the server shall support the NRC 0x34 “authenticationRequired”.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0119 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0120At reception of an SDT request, if the security sub-layer is busy, the server shall respond with
Statement

At reception of an SDT request, if the security sub-layer is busy, the server shall respond with

SSR-COM-013Secure communication and freshness protection — Secure Communication and Boundary ControlAD-007componentRFQX-CVS32-0120 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0121At reception of an SDT request, if the requesting client is unauthenticated, the server shall respond with an SDT negative response using the NRC 0x34.
Statement

At reception of an SDT request, if the requesting client is unauthenticated, the server shall respond with an SDT negative response using the NRC 0x34.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0121 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0122At reception of an SDT request, if the request is too short or otherwise malformed, the server shall respond with an SDT negative response using the NRC 0x13.
Statement

At reception of an SDT request, if the request is too short or otherwise malformed, the server shall respond with an SDT negative response using the NRC 0x13.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0122 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0123At reception of an SDT request, if ANTIREPLAYCNT ≤ PREQARC, the server shall respond with an SDT negative response using the NRC 0x3A.
Statement

At reception of an SDT request, if ANTIREPLAYCNT ≤ PREQARC, the server shall respond with an SDT negative response using the NRC 0x3A.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0123 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0124At reception of an SDT request, if PRESARC is exhausted, the server shall respond with an SDT negative response using the NRC 0x3A.
Statement

At reception of an SDT request, if PRESARC is exhausted, the server shall respond with an SDT negative response using the NRC 0x3A.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0124 / 29hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0125At reception of an SDT request, if SIGENCRYPT is not supported, the server shall respond with an SDT negative response using the NRC 0x3A.
Statement

At reception of an SDT request, if SIGENCRYPT is not supported, the server shall respond with an SDT negative response using the NRC 0x3A.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0125 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0126At reception of an SDT request, if APAR is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A.
Statement

At reception of an SDT request, if APAR is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0126 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0127For example, APAR dictates encryption, but SIGENCRYPT does not offer encryption.
Statement

For example, APAR dictates encryption, but SIGENCRYPT does not offer encryption.

NoneNoneNoneNoneRFQX-CVS32-0127 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0128At reception of an SDT request, if SIGLEN is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A.
Statement

At reception of an SDT request, if SIGLEN is in conflict with SIGENCRYPT, the server shall respond with an SDT negative response using the NRC 0x3A.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0128 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0129For example, the CipherScheme indicated by SIGENCRYPT produces a TAG of a length different from that indicated by SIGLEN.
Statement

For example, the CipherScheme indicated by SIGENCRYPT produces a TAG of a length different from that indicated by SIGLEN.

NoneNoneNoneNoneRFQX-CVS32-0129 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0130At reception of an SDT request, if the server fails to verify/decrypt the request, the server shall respond with an SDT negative response using the NRC 0x3A.
Statement

At reception of an SDT request, if the server fails to verify/decrypt the request, the server shall respond with an SDT negative response using the NRC 0x3A.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0130 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0131The server shall update its state, (set PREQARC to the value received in the ANTIREPLAYCNT protocol element in the SDT request), if and only if it successfully verifies/decrypts the SDT request.
Statement

The server shall update its state, (set PREQARC to the value received in the ANTIREPLAYCNT protocol element in the SDT request), if and only if it successfully verifies/decrypts the SDT request.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0131 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0132This means that if the server generates an SDT negative response, the server’s state remains unchanged, i.e.
Statement

This means that if the server generates an SDT negative response, the server’s state remains unchanged, i.e.

NoneNoneNoneNoneRFQX-CVS32-0132 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0133The server shall update its state, (increment PRESARC by one (1)), if and only if it can successfully authenticate/encrypt the SDT response (“S3”).
Statement

The server shall update its state, (increment PRESARC by one (1)), if and only if it can successfully authenticate/encrypt the SDT response (“S3”).

SSR-DAI-009Secure communication and freshness protection — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS32-0133 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0134This means that if the server fails to generate an SDT response, the server’s state remains unchanged, i.e.
Statement

This means that if the server fails to generate an SDT response, the server’s state remains unchanged, i.e.

NoneNoneNoneNoneRFQX-CVS32-0134 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0135As mentioned above in this specification, the UDS standard allows for a request to result in multiple responses, e.g.
Statement

As mentioned above in this specification, the UDS standard allows for a request to result in multiple responses, e.g.

NoneNoneNoneNoneRFQX-CVS32-0135 / 24hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0136Figure 11 shows an example where the client sends a RDBI and the server responds with two instances of RCRRP before delivering the final response.
Statement

Figure 11 shows an example where the client sends a RDBI and the server responds with two instances of RCRRP before delivering the final response.

NoneNoneNoneNoneRFQX-CVS32-0136 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0137Although this behavior does not alter the requirements put on the server, it is worth to point out that since the server will reuse the TAG received in the request for several responses, the server has to “remember” the TAG from the request.
Statement

Although this behavior does not alter the requirements put on the server, it is worth to point out that since the server will reuse the TAG received in the request for several responses, the server has to “remember” the TAG from the request.

NoneNoneNoneNoneRFQX-CVS32-0137 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0138Figure 12Figure 12 illustrates error- and state handling in the client’s security sub-layer.
Statement

Figure 12Figure 12 illustrates error- and state handling in the client’s security sub-layer.

NoneNoneNoneNoneRFQX-CVS32-0138 / 24hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0139The client shall update its state, (increment PREQARC by one (1), if and only if it can successfully authenticate/encrypt the SDT request (“C2”).
Statement

The client shall update its state, (increment PREQARC by one (1), if and only if it can successfully authenticate/encrypt the SDT request (“C2”).

SSR-DAI-009Secure communication and freshness protection — Data Authenticity and Integrity VerificationAD-007componentRFQX-CVS32-0139 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0140At reception of an SDT response, if the client is unauthenticated, the client shall discard the
Statement

At reception of an SDT response, if the client is unauthenticated, the client shall discard the

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0140 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0141At reception of an SDT response, if the request is too short or otherwise malformed, the client shall discard the response.
Statement

At reception of an SDT response, if the request is too short or otherwise malformed, the client shall discard the response.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0141 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0142At reception of an SDT response, if ANTIREPLAYCNT ≤ PRESARC, the client shall discard the
Statement

At reception of an SDT response, if ANTIREPLAYCNT ≤ PRESARC, the client shall discard the

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0142 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0143At reception of an SDT response, if SIGENCRYPT is not supported, the client shall discard the
Statement

At reception of an SDT response, if SIGENCRYPT is not supported, the client shall discard the

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0143 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0144At reception of an SDT response, if APAR is in conflict with SIGENCRYPT, the client shall discard the response.
Statement

At reception of an SDT response, if APAR is in conflict with SIGENCRYPT, the client shall discard the response.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0144 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0145At reception of an SDT response, if SIGLEN is in conflict with SIGENCRYPT, the client shall discard the response.
Statement

At reception of an SDT response, if SIGLEN is in conflict with SIGENCRYPT, the client shall discard the response.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0145 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0146At reception of an SDT response, if the client fails to verify/decrypt the response, the client shall discard the response.
Statement

At reception of an SDT response, if the client fails to verify/decrypt the response, the client shall discard the response.

SSR-COM-010Secure communication and freshness protection — Secure Communication and Boundary ControlAD-008componentRFQX-CVS32-0146 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredTOO BROAD SYSTEM REQUIREMENT
RFQX-CVS32-0147The client shall update its state, (set PRESARC to the value received in the ANTIREPLAYCNT protocol element in the SDT response), if and only if it successfully verifies/decrypts the SDT response (“C3”).
Statement

The client shall update its state, (set PRESARC to the value received in the ANTIREPLAYCNT protocol element in the SDT response), if and only if it successfully verifies/decrypts the SDT response (“C3”).

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0147 / 24hNot importedNo linked clarificationNo P1 linkboot/update trust; backend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0148This means that if the client fails to verify/decrypt the SDT response, the client’s state remains unchanged, i.e.
Statement

This means that if the client fails to verify/decrypt the SDT response, the client’s state remains unchanged, i.e.

NoneNoneNoneNoneRFQX-CVS32-0148 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0149Messages can get lost going from client to server, or vice versa.
Statement

Messages can get lost going from client to server, or vice versa.

NoneNoneNoneNoneRFQX-CVS32-0149 / 56hNot importedStill Requires Customer DecisionNo P1 linkbackend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0150Note that busyRepeatRequest, NRC 0x21 (BRR), can be sent in an SDT negative response, or, encapsulated in an SDT positive response.
Statement

Note that busyRepeatRequest, NRC 0x21 (BRR), can be sent in an SDT negative response, or, encapsulated in an SDT positive response.

NoneNoneNoneNoneRFQX-CVS32-0150 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0151If the client determines an SDT request to be lost in transit, or, if it receives an SDT negative response with NRC BRR (0x21), the client shall • repeat the request byte for byte and leave state variables unchanged.
Statement

If the client determines an SDT request to be lost in transit, or, if it receives an SDT negative response with NRC BRR (0x21), the client shall • repeat the request byte for byte and leave state variables unchanged.

SSR-COM-009Secure communication and freshness protection — Secure Communication and Boundary ControlAD-002componentRFQX-CVS32-0151 / 24hNot importedNo linked clarificationNo P1 linkbackend connectivityNo closure evidence requiredSECURITY REVIEW OPEN
RFQX-CVS32-0152.
Statement

.

NoneNoneNoneNoneRFQX-CVS32-0152 / 16hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0153A negative UDS response BRR encapsulated in a positive SDT response can of course never result in the resending of an old SDT request.
Statement

A negative UDS response BRR encapsulated in a positive SDT response can of course never result in the resending of an old SDT request.

NoneNoneNoneNoneRFQX-CVS32-0153 / 8hNot importedStill Requires Customer DecisionNo P1 linkdiagnostics exposureMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0154Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0154 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0155Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0155 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0156Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0156 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0157Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0157 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0158Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0158 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0159Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0159 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0160Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0160 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0161Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0161 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0162Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0162 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0163Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0163 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0164Updated
Statement

Updated

NoneNoneNoneNoneRFQX-CVS32-0164 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0165SDT_AES_SIV_CMAC_256 and SDT_CMAC_128 was deprecated and replaced with SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305.
Statement

SDT_AES_SIV_CMAC_256 and SDT_CMAC_128 was deprecated and replaced with SDT_AEAD_CHACHA20_POLY1305 and SDT_POLY1305.

NoneNoneNoneNoneRFQX-CVS32-0165 / 8hNot importedStill Requires Customer DecisionNo P1 linkNoneMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0166(new cipher-schemes) Updated Table 2 (new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated Table 2 (new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0166 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0167(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0167 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0168(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0168 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0169(new cipher-schemes) Updated Figure 4 (new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated Figure 4 (new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0169 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0170(new cipher-schemes) Updated 3.2.2 heading (new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated 3.2.2 heading (new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0170 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0171(new cipher-schemes) Updated Figure 5 annotation (new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated Figure 5 annotation (new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0171 / 56hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0172(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0172 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0173(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0173 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0174(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0174 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0175(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0175 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0176(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0176 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0177(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0177 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0178(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0178 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0179(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0179 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0180(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0180 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0181(new cipher-schemes) Updated Figure 6 (new cipher-schemes)
Statement

(new cipher-schemes) Updated Figure 6 (new cipher-schemes)

NoneNoneNoneNoneRFQX-CVS32-0181 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0182(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0182 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0183(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0183 / 8hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0184(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0184 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0185(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0185 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0186(new cipher-schemes) Added
Statement

(new cipher-schemes) Added

NoneNoneNoneNoneRFQX-CVS32-0186 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0187(new cipher-schemes) Added Figure 7 (new cipher-schemes) Updated
Statement

(new cipher-schemes) Added Figure 7 (new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0187 / 8hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0188(new cipher-schemes) Added
Statement

(new cipher-schemes) Added

NoneNoneNoneNoneRFQX-CVS32-0188 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0189(new cipher-schemes) Added
Statement

(new cipher-schemes) Added

NoneNoneNoneNoneRFQX-CVS32-0189 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0190(new cipher-schemes) Added
Statement

(new cipher-schemes) Added

NoneNoneNoneNoneRFQX-CVS32-0190 / 19hNot importedNo linked clarificationNo P1 linkNoneNo closure evidence requiredCOMPLETE
RFQX-CVS32-0191(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0191 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0192(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0192 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0193(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0193 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0194(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0194 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0195(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0195 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0196(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0196 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0197(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0197 / 29hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0198(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0198 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0199(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0199 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0200(new cipher-schemes) Updated Figure 8 (new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated Figure 8 (new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0200 / 24hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0201(new cipher-schemes) Updated
Statement

(new cipher-schemes) Updated

NoneNoneNoneNoneRFQX-CVS32-0201 / 24hNot importedNo linked clarificationNo P1 linkboot/update trustNo closure evidence requiredCOMPLETE
RFQX-CVS32-0202(new cipher-schemes) Updated 4 References (new cipher-schemes) Updated Annex A (new cipher-schemes) Updated test vectors to be correct after change from SHA-256 to SHA-512 Exhausted PRESARC server behavior.
Statement

(new cipher-schemes) Updated 4 References (new cipher-schemes) Updated Annex A (new cipher-schemes) Updated test vectors to be correct after change from SHA-256 to SHA-512 Exhausted PRESARC server behavior.

NoneNoneNoneNoneRFQX-CVS32-0202 / 29hNot importedStill Requires Customer DecisionNo P1 linkboot/update trust; backend connectivityMISSING CLARIFICATION EVIDENCECOMPLETE
RFQX-CVS32-0203and updated Figure 9.) 2025-08 1 This standard has been revised and is valid for continued use.
Statement

and updated Figure 9.) 2025-08 1 This standard has been revised and is valid for continued use.

NoneNoneNoneNoneRFQX-CVS32-0203 / 29hNot importedStill Requires Customer DecisionNo P1 linkboot/update trustMISSING CLARIFICATION EVIDENCECOMPLETE