Runtime Tamper Monitoring and Detection (RTMD) Security Architecture Requirements - TDA4VM ADAS ECU

1. Functional Security Concept

1.1 Cybersecurity Goals (CSG)

1.2 Functional Security Concept (FSC)

1.3 Functional Security Requirements (FSR)

2. System Requirements and System Static Architecture

2.1 System entities

2.2 Trust boundaries and interfaces

graph LR
  ECU[TDA4VM ECU] --> MON[RTMD Monitor]
  MON --> SAFE[Safety Manager]
  MON --> LOG[Secure Logging]
  LOG --> GW[Gateway/SOC]
  GW --> CLOUD[Cloud Analytics]
  TEST[Tester] -->|Protected Diagnostics| ECU

2.3 System Requirements (SYSR)

3. Technical Security Concept

3.1 Technical Security Concept (TSC)

3.2 Technical Security Requirements (TSR)

4. Hardware Requirements and Hardware Static Architecture

4.1 Hardware elements

graph LR
  MON[A72/R5F Monitor Core] --> SA2UL[SA2UL Hash/Crypto Accelerator]
  MON --> WDT[Reset/Watchdog/Status Peripherals]
  SA2UL --> DMSC[DMSC Cortex-M3 Secure Boot Chain]
  MON --> NvM[Flash/NvM Reference and Evidence Store]
  MON --> JTAGST[JTAG/Sec-AP Debug State Indicators]

4.2 Hardware Requirements (HWR)

5. Software Requirements and Software Static & Dynamic Architecture

5.1 Software blocks

graph LR
  SCH[RTMD Scheduler] --> CHK[Integrity Checker]
  CHK --> CLS[Detection Classifier]
  CLS --> POL[Response Policy Engine]
  POL --> SAFE[Safety Coordinator]
  POL --> LOG[Secure Logging]

5.2 Software Requirements (SWR)

5.3 Runtime tamper detection sequence

Runtime tamper detection sequence

Mermaid source (for editing/regeneration)
sequenceDiagram
  participant S as RTMD Scheduler (periodic tick + event triggers)
  participant C as Integrity Checker (R5F/A72 task)
  participant Y as SA2UL (SHA-256/512)
  participant N as Protected NvM (reference digests)
  participant P as Policy Engine
  participant DM as DEM (event manager)
  participant EM as EcuM/Safety State Manager
  participant L as Secure Logging
  participant W as Watchdog/Reset Controller

  alt Periodic schedule table tick
    S->>C: Trigger scheduled region check (code segment / calibration table)
  else Event trigger
    S->>C: Reset-reason register change, debug-state change (from TIFS), or repeated auth failure count
  end
  C->>Y: Compute digest of target region
  Y-->>C: Digest
  C->>N: Fetch protected reference digest (itself integrity-tagged)
  C->>C: Compare digest vs reference
  alt Match
    C-->>S: Pass, no action
  else Mismatch
    C->>P: Region ID + digest delta + confidence
    P->>P: Classify severity (code-region tamper = critical, calibration drift = moderate)
    P->>DM: Raise DEM event (event ID, region, timestamp, task ID)
    P->>EM: Request graded response bounded by current safety state (no abrupt actuator change mid-cycle)
    EM-->>P: Approved response tier (warn/degrade/reset)
    P->>L: Persist evidence (region, expected vs actual digest, action, watchdog/reset context)
    opt Response tier = reset
      P->>W: Request controlled ECU reset
      W->>C: Re-arm monitor after DMSC BootROM chain re-establishes known-good baseline
    end
  end

5.4 Behavioral requirement focus

6. Hardware-Software Interface (HSI)

6.1 HSI elements

6.2 HSI Requirements (HSI)