CHTS requirement clause

4.5.1.10 — Replace CHF Security Credentials

17 technical records havebeen identified at this reference: 16 Section 20 items and 1 explicit clause reference. The links below describe documented interfaces and observable effects; they do not assert compliance with the source requirement.

CHFGPFAlert touchpoint onlyGBCS use case only
16

Atomic items

Section 20 objects, attributes or methods at this source reference.

21

Documented touchpoints

Typed relationships supported by source mapping rows.

0

Linked SRVs

Unique retained services reached through exact control rows.

5

Linked alerts

Explicit requirement-to-alert references.

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.method: replace

PublicKeySecurityCredentialsStore - replace

GBCS use case only

The method to replace one or more of the Known Remote Party Security Credentials held on a Device.

Object
PublicKeySecurityCredentialsStore
Attribute / method
method: replace
Interface disposition
E
Category
Method
Section 20 meaning
The method to replace one or more of the Known Remote Party Security Credentials held on a Device.

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1266

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: activateNextDateTime

PublicKeySecurityCredentialsStore - activateNextDateTime

GBCS use case only

The date-time at which the replacements are to be attempted (only valid for replacement of supplier credentials)

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: activateNextDateTime
Interface disposition
E
Category
Method Input
Section 20 meaning
The date-time at which the replacements are to be attempted (only valid for replacement of supplier credentials)

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1267

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: replacementCredentials[1..9].credential

PublicKeySecurityCredentialsStore - replacementCredentials credential

GBCS use case only

The credentials to be used in the replacements

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: replacementCredentials[1..9].credential
Interface disposition
E
Category
Method Input
Section 20 meaning
The credentials to be used in the replacements

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1280

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: certificationPathCredentials[1..9].credential

PublicKeySecurityCredentialsStore - certificationPathCredentials credential

GBCS use case only

The credentials to be used in certification path validation of the replacements

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: certificationPathCredentials[1..9].credential
Interface disposition
E
Category
Method Input
Section 20 meaning
The credentials to be used in certification path validation of the replacements

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1281

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: replacementMode

PublicKeySecurityCredentialsStore - replacementMode

GBCS use case only

Which role is undertaking which kinds of replacements

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: replacementMode
Interface disposition
E
Category
Method Input
Section 20 meaning
Which role is undertaking which kinds of replacements

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1853

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: symmetricKey

PublicKeySecurityCredentialsStore - symmetricKey

GBCS use case only

A key used only in contingency recovery situations

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: symmetricKey
Interface disposition
E
Category
Method Input
Section 20 meaning
A key used only in contingency recovery situations

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1854

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: applyTime BasedChecks

PublicKeySecurityCredentialsStore - applyTime BasedChecks

GBCS use case only

Only present (and set to disapply) where such checks are not to be applied by the Device

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: applyTime BasedChecks
Interface disposition
E
Category
Method Input
Section 20 meaning
Only present (and set to disapply) where such checks are not to be applied by the Device

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1855

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: remotePartyRole[1..6].antiReplayCounters

PublicKeySecurityCredentialsStore - remotePartyRole antiReplayCounters

GBCS use case only

The values of to be used in re-setting anti replay counters on the Device for Remote Party Roles affected by this Command

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: remotePartyRole[1..6].antiReplayCounters
Interface disposition
E
Category
Method Input
Section 20 meaning
The values of to be used in re-setting anti replay counters on the Device for Remote Party Roles affected by this Command

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1856

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodInput: replacementCredentials[1..9].targetTrustAnchorCell

PublicKeySecurityCredentialsStore - replacementCredentials targetTrustAnchorCell

GBCS use case only

The Trust Anchor Cell in to which the corresponding certificate's details are to be placed.

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodInput: replacementCredentials[1..9].targetTrustAnchorCell
Interface disposition
E
Category
Method Input
Section 20 meaning
The Trust Anchor Cell in to which the corresponding certificate's details are to be placed.

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1858

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodOutput: originatorCounter

PublicKeySecurityCredentialsStore - originatorCounter

GBCS use case only

The originator counter from the command that triggered these replacments

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodOutput: originatorCounter
Interface disposition
E
Category
Method Output
Section 20 meaning
The originator counter from the command that triggered these replacments

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1859

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodOutput: replacementMode

PublicKeySecurityCredentialsStore - replacementMode

GBCS use case only

Which role undertook which kinds of replacements

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodOutput: replacementMode
Interface disposition
E
Category
Method Output
Section 20 meaning
Which role undertook which kinds of replacements

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1860

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodOutput: remotePartyRole[1..6].antiReplayCounters

PublicKeySecurityCredentialsStore - remotePartyRole antiReplayCounters

GBCS use case only

The values used in re-setting anti replay counters on the Device for Remote Party Roles affected by this change

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodOutput: remotePartyRole[1..6].antiReplayCounters
Interface disposition
E
Category
Method Output
Section 20 meaning
The values used in re-setting anti replay counters on the Device for Remote Party Roles affected by this change

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1861

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].existingRemotePartyIdentifier

PublicKeySecurityCredentialsStore - remotePartyRoleDetailRequired trustAnchorCell existingRemotePartyIdentifier

GBCS use case only

The Entity Identifier of the Remote Party which was in this cell before any replacement

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].existingRemotePartyIdentifier
Interface disposition
E
Category
Method Output
Section 20 meaning
The Entity Identifier of the Remote Party which was in this cell before any replacement

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1862

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].existingPublicKeyIdentifier

PublicKeySecurityCredentialsStore - remotePartyRoleDetailRequired trustAnchorCell existingPublicKeyIdentifier

GBCS use case only

The SHA-1 hash of the public key which was in this cell before any replacement

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].existingPublicKeyIdentifier
Interface disposition
E
Category
Method Output
Section 20 meaning
The SHA-1 hash of the public key which was in this cell before any replacement

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1863

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].replacingRemotePartyIdentifier

PublicKeySecurityCredentialsStore - remotePartyRoleDetailRequired trustAnchorCell replacingRemotePartyIdentifier

GBCS use case only

The Entity Identifier of the Remote Party which was to be placed in this cell

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].replacingRemotePartyIdentifier
Interface disposition
E
Category
Method Output
Section 20 meaning
The Entity Identifier of the Remote Party which was to be placed in this cell

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1864

CHTS4.5.1.10 · item PublicKeySecurityCredentialsStore.methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].replacingPublicKeyIdentifier

PublicKeySecurityCredentialsStore - remotePartyRoleDetailRequired trustAnchorCell replacingPublicKeyIdentifier

GBCS use case only

The SHA-1 hash of the public key which was to be placed in this cell

Object
PublicKeySecurityCredentialsStore
Attribute / method
methodOutput: remotePartyRoleDetailRequired[1..6].trustAnchorCell[1..3].replacingPublicKeyIdentifier
Interface disposition
E
Category
Method Output
Section 20 meaning
The SHA-1 hash of the public key which was to be placed in this cell

Documented touchpoints

  • UpdatesCS02bCHF
Evidence:source paragraph 362, 363Section 20 row 1865

CHTS4.5.1.10 · item clause.4.5.1.10

Replace CHF Security Credentials

Alert touchpoint only

This source clause is explicitly referenced by the GBCS device alert table.

Category
Alert reference

Documented touchpoints

  • Alert touchpoint0x8F4FDevice's own Key Agreement Certificate replacement succeeded
  • Alert touchpointGPF0x8F70Update Security Credentials
  • Alert touchpoint0x8F4EDevice's own Key Agreement Certificate replacement failed
  • Alert touchpoint0x8F4DDevice's own Digital Signing Certificate replacement succeeded
  • Alert touchpoint0x8F4CDevice's own Digital Signing Certificate replacement failed
Evidence:source paragraph 362, 363

How to read this page

Evidence is kept at record level

A source clause can contain several separately mapped Section 20 items and an explicit alert reference. One item may be read by an SRV, another updated by a different service, and another have only an Alert or local-HAN path. Accordingly, the clause summary does not collapse those distinctions into a single covered or uncovered result.