id: bf181660d9824e09ae3b75f787efb695
parent_id: 
item_type: 1
item_id: 2bfed07887b143ffb4e49e340c1de26a
item_updated_time: 1785841936252
title_diff: "[{\"diffs\":[[1,\"Access Request - vECU BROP Stage 1 - Joyson\"]],\"start1\":0,\"start2\":0,\"length1\":0,\"length2\":43}]"
body_diff: "[{\"diffs\":[[1,\"<h2>Access Request for Joyson — vECU Development & BROP Stage 1 Compliance</h2>\\\n\\\n<p><strong>Subject:</strong> Access Request for Joyson — vECU Development & BROP Stage 1 Compliance (MB.EA-L)</p>\\\n\\\n<p><strong>Project:</strong> RevAS | <strong>KLH:</strong> RevAS CompSpec BL V9.3</p>\\\n\\\n<p>We are preparing to build and deploy a vECU for BROP Stage 1. Below is a breakdown of what access is required by BROP stage.</p>\\\n\\\n<h3>BROP Stage 1 (Mandatory for ALL ECUs — Step 3.1, CW05/2025)</h3>\\\n\\\n<table border=\\\"1\\\" cellpadding=\\\"6\\\" cellspacing=\\\"0\\\">\\\n<tr><th>#</th><th>Resource</th><th>Access Type</th><th>Why</th><th>Source</th></tr>\\\n<tr><td>1</td><td>MB SW-Base-Layer (MBBL) SLP11 SIP/CSP Step 3.1</td><td>Diagnoseportal / MB.OS Portal</td><td>Core BSW with diagnostic, communication, security stacks — required from BROP Stage 1 (MSS30003 req: 13091108, 6553467)</td><td>MB_SW_Base_Layer_PartA, vECU_Infosheet p.9</td></tr>\\\n<tr><td>2</td><td>StarterKit / Development Kit</td><td>Diagnoseportal</td><td>Reference integration for SSA, crypto library/vHSM, secure diagnostics. Contains the stacks for diagnostics, communication, security as a template. \\\"A template, at least for the BSW, would be the MB Baselayer\\\"</td><td>vECU_Infosheet p.9; SupplierInfo_MBEAL p.5-13</td></tr>\\\n<tr><td>3</td><td>SSA Security Extension</td><td>Diagnoseportal → Standard-Software → Security → SSA</td><td>CeBAS CA Root/Backend public key certificates for cryptographic root of trust</td><td>SupplierInfo_MBEAL p.15-16</td></tr>\\\n<tr><td>4</td><td>ECU Extract & Diagnostic Extract (ARXML, CDD)</td><td>Diagnoseportal</td><td>Defines SWCs to integrate, bus/communication config, and diagnostic services (session handling, ReadDataByIdentifier). Required for \\\"Basic diagnosis operations (focus integration)\\\" at BROP Stage 1 (MSS30003 req: 6553462)</td><td>vECU_Infosheet p.9; MSS30003 p.12</td></tr>\\\n<tr><td>5</td><td>NEST & TATS test suites</td><td>Diagnoseportal (MSS-10797)</td><td>Required security test suites — must pass test groups for NTS (networking) and security validation at BROP Stage 1</td><td>SupplierInfo_MBEAL p.57-60</td></tr>\\\n<tr><td>6</td><td>MBBL GitLab (MB-Base-Layer-Projekthaus-MB-VI)</td><td>GitLab</td><td>Access to vHSM documentation, integration code, technical references</td><td>SupplierInfo_MBEAL p.65</td></tr>\\\n<tr><td>7</td><td>BROP vECU test cases</td><td>DNG / Jama Connect</td><td>List of feasible test suites and test cases for BROP (vECU Supplement)</td><td>vECU_Infosheet p.8</td></tr>\\\n<tr><td>8</td><td>MCP Jira Platform</td><td>Jira</td><td>Support tickets for SSA/HSM integration and NEST/TATS testing</td><td>SupplierInfo_MBEAL p.7-8</td></tr>\\\n<tr><td>9</td><td>ServiceNow</td><td>ServiceNow</td><td>Initiate ECU Trust Model (ETM) onboarding process</td><td>SupplierInfo_MBEAL p.14</td></tr>\\\n<tr><td>10</td><td>ETM PKI (INT + PROD environments)</td><td>Online (OIDC clients)</td><td>Submit CSRs and receive ETM ECU certificates. Requires two-phase onboarding: INT first, then PROD</td><td>SupplierInfo_MBEAL p.14</td></tr>\\\n<tr><td>11</td><td>ACDC / ZenZefi</td><td>Web portals</td><td>Diagnostic Authentication Certificates for secure diagnostics (required at BROP Stage 1 per MSS30003 req: 6608997)</td><td>SupplierInfo_MBEAL p.15</td></tr>\\\n</table>\\\n\\\n<h4>What we can self-provide at B1:</h4>\\\n<ul>\\\n<li>We can generate our own ETM key pairs (supplier-side), but ETM certificates must be issued by MB's online ETM PKI</li>\\\n<li>We can use a crypto library (not real vHSM) for vECU security simulation — \\\"A crypto libraries solution in the beginning would be ok\\\" (vECU_Infosheet p.12). This means vHSM integration info is NOT strictly required at B1 if we use a crypto library approach</li>\\\n<li>Flashware encryption and signing with development keys is NOT required at B1 (starts at B2)</li>\\\n</ul>\\\n\\\n<h3>BROP B2 (Flashware Encryption & Signing — Future)</h3>\\\n<ul>\\\n<li>Development (DEV) flashware signing infrastructure — self-managed using DEV private keys (\\\"Flashware shall be signed by the ECU project or supplier CI/CD using development (DEV) private keys\\\")</li>\\\n<li>FLASH-ExtendedTest (FET) test reports</li>\\\n<li>Source: SupplierInfo_MBEAL p.25, p.42</li>\\\n</ul>\\\n\\\n<h3>BROP B9 (Series Keys — Future)</h3>\\\n<ul>\\\n<li>Unikey access (MB internal PKI for series key generation)</li>\\\n<li>SRM (Service Resource Management) for HW part number registration</li>\\\n<li>MB.OS Portal / Flashware Origin for series signature calculation</li>\\\n<li>Source: SupplierInfo_MBEAL p.25, p.63</li>\\\n</ul>\"]],\"start1\":0,\"start2\":0,\"length1\":0,\"length2\":4483}]"
metadata_diff: {"new":{"id":"2bfed07887b143ffb4e49e340c1de26a","parent_id":"beb251c3b3f9490285e6cb68942a5145","latitude":"0.00000000","longitude":"0.00000000","altitude":"0.0000","author":"","source_url":"","is_todo":0,"todo_due":0,"todo_completed":0,"source":"joplin-desktop","source_application":"net.cozic.joplin-desktop","application_data":"","order":1785841693159,"user_updated_time":1785841693159,"markup_language":1,"is_shared":0,"share_id":"","conflict_original_id":"","master_key_id":"","user_data":"","deleted_time":1785841936252},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-08-04T11:18:49.476Z
created_time: 2026-08-04T11:18:49.476Z
is_locked: 0
type_: 13