Access Request - vECU BROP Stage 1 - Joyson

<h2>Access Request for Joyson — vECU Development & BROP Stage 1 Compliance</h2>

<p><strong>Subject:</strong> Access Request for Joyson — vECU Development & BROP Stage 1 Compliance (MB.EA-L)</p>

<p><strong>Project:</strong> RevAS | <strong>KLH:</strong> RevAS CompSpec BL V9.3</p>

<p>We are preparing to build and deploy a vECU for BROP Stage 1. Below is a breakdown of what access is required by BROP stage.</p>

<h3>BROP Stage 1 (Mandatory for ALL ECUs — Step 3.1, CW05/2025)</h3>

<table border="1" cellpadding="6" cellspacing="0">
<tr><th>#</th><th>Resource</th><th>Access Type</th><th>Why</th><th>Source</th></tr>
<tr><td>1</td><td>MB SW-Base-Layer (MBBL) SLP11 SIP/CSP Step 3.1</td><td>Diagnoseportal / MB.OS Portal</td><td>Core BSW with diagnostic, communication, security stacks — required from BROP Stage 1 (MSS30003 req: 13091108, 6553467)</td><td>MB_SW_Base_Layer_PartA, vECU_Infosheet p.9</td></tr>
<tr><td>2</td><td>StarterKit / Development Kit</td><td>Diagnoseportal</td><td>Reference integration for SSA, crypto library/vHSM, secure diagnostics. Contains the stacks for diagnostics, communication, security as a template. "A template, at least for the BSW, would be the MB Baselayer"</td><td>vECU_Infosheet p.9; SupplierInfo_MBEAL p.5-13</td></tr>
<tr><td>3</td><td>SSA Security Extension</td><td>Diagnoseportal → Standard-Software → Security → SSA</td><td>CeBAS CA Root/Backend public key certificates for cryptographic root of trust</td><td>SupplierInfo_MBEAL p.15-16</td></tr>
<tr><td>4</td><td>ECU Extract & Diagnostic Extract (ARXML, CDD)</td><td>Diagnoseportal</td><td>Defines SWCs to integrate, bus/communication config, and diagnostic services (session handling, ReadDataByIdentifier). Required for "Basic diagnosis operations (focus integration)" at BROP Stage 1 (MSS30003 req: 6553462)</td><td>vECU_Infosheet p.9; MSS30003 p.12</td></tr>
<tr><td>5</td><td>NEST & TATS test suites</td><td>Diagnoseportal (MSS-10797)</td><td>Required security test suites — must pass test groups for NTS (networking) and security validation at BROP Stage 1</td><td>SupplierInfo_MBEAL p.57-60</td></tr>
<tr><td>6</td><td>MBBL GitLab (MB-Base-Layer-Projekthaus-MB-VI)</td><td>GitLab</td><td>Access to vHSM documentation, integration code, technical references</td><td>SupplierInfo_MBEAL p.65</td></tr>
<tr><td>7</td><td>BROP vECU test cases</td><td>DNG / Jama Connect</td><td>List of feasible test suites and test cases for BROP (vECU Supplement)</td><td>vECU_Infosheet p.8</td></tr>
<tr><td>8</td><td>MCP Jira Platform</td><td>Jira</td><td>Support tickets for SSA/HSM integration and NEST/TATS testing</td><td>SupplierInfo_MBEAL p.7-8</td></tr>
<tr><td>9</td><td>ServiceNow</td><td>ServiceNow</td><td>Initiate ECU Trust Model (ETM) onboarding process</td><td>SupplierInfo_MBEAL p.14</td></tr>
<tr><td>10</td><td>ETM PKI (INT + PROD environments)</td><td>Online (OIDC clients)</td><td>Submit CSRs and receive ETM ECU certificates. Requires two-phase onboarding: INT first, then PROD</td><td>SupplierInfo_MBEAL p.14</td></tr>
<tr><td>11</td><td>ACDC / ZenZefi</td><td>Web portals</td><td>Diagnostic Authentication Certificates for secure diagnostics (required at BROP Stage 1 per MSS30003 req: 6608997)</td><td>SupplierInfo_MBEAL p.15</td></tr>
</table>

<h4>What we can self-provide at B1:</h4>
<ul>
<li>We can generate our own ETM key pairs (supplier-side), but ETM certificates must be issued by MB's online ETM PKI</li>
<li>We can use a crypto library (not real vHSM) for vECU security simulation — "A crypto libraries solution in the beginning would be ok" (vECU_Infosheet p.12). This means vHSM integration info is NOT strictly required at B1 if we use a crypto library approach</li>
<li>Flashware encryption and signing with development keys is NOT required at B1 (starts at B2)</li>
</ul>

<h3>BROP B2 (Flashware Encryption & Signing — Future)</h3>
<ul>
<li>Development (DEV) flashware signing infrastructure — self-managed using DEV private keys ("Flashware shall be signed by the ECU project or supplier CI/CD using development (DEV) private keys")</li>
<li>FLASH-ExtendedTest (FET) test reports</li>
<li>Source: SupplierInfo_MBEAL p.25, p.42</li>
</ul>

<h3>BROP B9 (Series Keys — Future)</h3>
<ul>
<li>Unikey access (MB internal PKI for series key generation)</li>
<li>SRM (Service Resource Management) for HW part number registration</li>
<li>MB.OS Portal / Flashware Origin for series signature calculation</li>
<li>Source: SupplierInfo_MBEAL p.25, p.63</li>
</ul>

id: 2bfed07887b143ffb4e49e340c1de26a
parent_id: beb251c3b3f9490285e6cb68942a5145
created_time: 2026-08-04T11:08:13.159Z
updated_time: 2026-08-04T11:12:16.252Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author: 
source_url: 
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data: 
order: 1785841693159
user_created_time: 2026-08-04T11:08:13.159Z
user_updated_time: 2026-08-04T11:08:13.159Z
encryption_cipher_text: 
encryption_applied: 0
markup_language: 1
is_shared: 0
share_id: 
conflict_original_id: 
master_key_id: 
user_data: 
deleted_time: 1785841936252
is_locked: 0
extracted_resource_ids: 
type_: 1