Vulnerability Analysis and Management Requirements - TDA4VM ADAS ECU

Scope note (this doc adapts the repo’s template deliberately): every other doc in this repo covers a runtime security mechanism on the ECU (boot, JTAG, comms, storage, …). Vulnerability analysis is instead an ISO 21434 continuous cybersecurity activity (monitoring, event evaluation, vulnerability analysis, vulnerability management) that runs across the item’s whole lifecycle and feeds back into those mechanisms. To keep this doc traceable in the same CSG->FSR->SYSR->TSC->TSR-> HWR/SWR->HSI shape as the rest of the repo:

1. Functional Security Concept

1.1 Cybersecurity Goals (CSG)

1.2 Functional Security Concept (FSC)

1.3 Functional Security Requirements (FSR)

2. System Requirements and System Static Architecture

2.1 System entities

2.2 Trust boundaries and interfaces

graph LR
  Src[Monitoring Sources] --> Match[Intake/Matching Engine]
  SBOM[Component Inventory] --> Match
  Match --> Triage[Analyst Triage Workspace]
  Triage --> Dec[Risk-Treatment Decision Record]
  Dec --> OTA[Secure Reprogramming/OTA Path]
  Dec --> RTMD[Secure Logging/RTMD]
  PSIRT[OEM PSIRT] --> Triage

2.3 System Requirements (SYSR)

3. Technical Security Concept

3.1 Technical Security Concept (TSC)

3.2 Technical Security Requirements (TSR)

4. Hardware Requirements and Hardware Static Architecture

4.1 Hardware elements (asset inventory and fingerprinting surface, not a new crypto engine)

graph LR
  Tool[Vulnerability Analysis Tooling] --> UID[TISCI GET_SOC_UID/eFuse SWREV-KEYREV Read]
  UID --> DMSC[DMSC BootROM/SYSFW]
  Tool --> INV[Hardware Asset Inventory]
  INV --> SA2UL[SA2UL Crypto Engine]
  INV --> EFUSE[eFuse Array]
  INV --> OTP[Extended OTP]
  INV --> JTAG[JTAG/Sec-AP Debug Interface]
  INV --> CORES[A72/R5F/DSP Compute Domains]

4.2 Hardware Requirements (HWR)

5. Software Requirements and Software Static & Dynamic Architecture

5.1 Software blocks

graph LR
  Feed[CVE/Advisory Feed Ingester] --> Match[SBOM Component Matcher]
  Match --> Tri[TARA Re-Assessment Workspace]
  Tri --> Dec[Risk-Treatment Decision Engine]
  Dec --> Link[Cross-Doc Requirement ID Linker]
  Dec --> OTAc[OTA/Reprogramming Connector]
  Dec --> RTMDc[RTMD/Secure Logging Connector]
  Feed --> Embargo[Embargo Tracker]

5.2 Software Requirements (SWR)

5.3 Vulnerability ingestion, TARA re-assessment, and risk-treatment flow

Vulnerability ingestion, TARA re-assessment, and risk-treatment flow

Mermaid source (for editing/regeneration)
sequenceDiagram
  participant Src as Monitoring Source
  participant Ing as Feed Ingester
  participant Match as SBOM Matcher
  participant An as Analyst Triage
  participant Dec as Risk-Treatment Decision
  participant OTA as OTA/Reprogramming Connector
  participant RT as RTMD/Secure Logging Connector
  participant Emb as Embargo Tracker

  Src->>Ing: New disclosure, component identifier and version
  Ing->>Emb: Register embargo window if coordinated disclosure
  Ing->>Match: Normalized component identifier
  alt No matching inventoried component/version
    Match->>Match: Route to low-priority monitoring queue
  else Matching fielded component found
    Match->>An: Matched disclosure plus affected component
    An->>An: Derive asset, threat scenario, impact rating, attack feasibility
    An->>Dec: TARA re-assessment record
    alt Risk retained, existing CSG/TSR sufficient
      Dec->>Dec: Close record, cite existing requirement ID
    else Risk requires compensate
      Dec->>RT: Register detection rule for exploitation indicator
    else Risk requires mitigate
      Dec->>OTA: Candidate patch image for dual-bank activation
      OTA->>OTA: Standard signature/anti-rollback verification on activation
    end
  end

5.4 Behavioral requirement focus

6. Hardware-Software Interface (HSI)

6.1 HSI elements

6.2 HSI Requirements (HSI)