Parking ECU — ADAS Parking Assist / Surround View System (SVS)
TDA4VM (TI Jacinto 7 / J721E) ADAS ECU cybersecurity requirements documents, a TARA dashboard, and a vulnerability analysis report/evidence set, all scoped to the Parking Assist / Surround View System (SVS) ECU.
Topics
| Document | Topic |
|---|---|
| Secure and Authentic Boot with Runtime Integrity | Secure/authentic boot and runtime integrity |
| Secure JTAG and Debug Control | JTAG/debug port access control |
| Secure Access | UDS SecurityAccess (diagnostic access control) |
| SecOC | Secure communication stack: AUTOSAR SecOC per-PDU authenticity/freshness, confidentiality channels, off-board TLS |
| Secure Logging | Secure/tamper-evident logging |
| OTA/FOTA/SOTA | OTA/FOTA/SOTA update delivery |
| Secure Reprogramming | Secure ECU reprogramming |
| RTMD | Runtime tamper monitoring and detection |
| Secure Storage | Secure storage of keys/credentials at rest |
| Parking/TARA/Ref/ | TARA dashboard |
Vulnerability analysis: process vs. deliverable
These two documents are deliberately kept separate and live together under Parking/Vulnerability_Analysis/:
| Document | What it is |
|---|---|
| Vulnerability Management Process | Requirements doc. Defines the ongoing ISO 21434 continuous-cybersecurity-activity capability (SBOM/CVE monitoring, TARA re-assessment, risk-treatment routing) using this repo’s CSG/FSR/SYSR/TSC/TSR taxonomy. Says a capability must exist - contains no analysis of a specific subsystem. |
| SVS / Parking Assist Vulnerability Analysis Report | Point-in-time report. One concrete engagement deliverable produced by that process for the SVS/Parking Assist subsystem: attack surfaces, STRIDE, CVSS-scored risk matrix, case-study narratives, and evidence appendices (CAN/UDS logs, pen-test findings, static/dynamic/fuzz results). |
Requirement ID taxonomy
TARA (Threat Analysis and Risk Assessment - see the TARA Dashboard above) is what supplies the CSG: every Cybersecurity Goal comes from a TARA risk-treatment decision, and each subsequent ID in the chain below is derived from the one before it, in order:
graph LR
TARA["TARA (Threat Analysis and Risk Assessment)"] --> CSG["CSG (Cybersecurity Goal)"]
CSG --> FSC["FSC (Functional Security Concept)"]
FSC --> FSR["FSR (Functional Security Requirements)"]
FSR --> SYSR["SYSR (System Requirement)"]
SYSR --> TSC["TSC (Technical Security Concept)"]
TSC --> TSR["TSR (Technical Security Requirements)"]
TSR --> HWR["HWR (Hardware Requirement)"]
TSR --> SWR["SWR (Software Requirement)"]
HWR --> HSI["HSI (Hardware-Software Interface)"]
SWR --> HSI
- CSG - Cybersecurity Goal (what must be true)
- FSC - Functional Security Concept (the overarching strategy for realizing the CSGs)
- FSR - Functional Security Requirements (decomposed, testable, still implementation-agnostic)
- SYSR - System Requirement (system-level allocation across entities/trust boundaries)
- TSC - Technical Security Concept (how, at a functional level)
- TSR - Technical Security Requirements (how, at a concrete TI TDA4VM mechanism level)
- HWR - Hardware Requirement
- SWR - Software Requirement
- HSI - Hardware-Software Interface Requirement (register/API/message contract)