Architectures/Cloud · companion · TCU
Public reference architecture

Connected Vehicle System

One freshness-aware vehicle truth from edge evidence to owner experience.

Separate device receipt, cloud projection, authorized command request and physical vehicle outcome while keeping identity, consent and lifecycle coherent.

Know which component owns the state—and what it must never infer.

Every layer exposes an authoritative responsibility and an explicit non-authority boundary.

01
TCU / approved vehicle services

Vehicle evidence

OwnsSignal source, event sequence and device health

Must not inferNo cloud or app success is inferred from local observation alone

02
Device gateway

Secure ingress

OwnsDevice identity, schema, sequence, consent and durable receipt

Must not inferReceipt is not digital-twin projection or business completion

03
SAAS-01

Vehicle cloud

OwnsFreshness-aware twin, trips, events, policy and command lifecycle

Must not inferNever invents physical execution without adapter evidence

04
APP-02 / OEM channels

Owner and operations

OwnsPresentation, intent and user acknowledgement

Must not inferUI wording cannot advance vehicle state

State advances through evidence—not optimistic UI.

Each transition names both the action and the identity or version evidence that makes it reproducible.

  1. 01

    Observe

    Normalize an approved source event with unit, quality, source time and sequence.

    device · schema · signal profile · event identity
  2. 02

    Buffer

    Encrypt and prioritize during weak connectivity using bounded store-and-forward.

    queue class · capacity · drop/gap record
  3. 03

    Reconcile

    Deduplicate, preserve late evidence and advance only a newer qualified twin.

    event time · receipt time · watermark · consent
  4. 04

    Request

    Authorize a remote intent against role, vehicle state, nonce, expiry and capability.

    actor · policy · idempotency · context revision
  5. 05

    Resolve

    Expose requested, delivered, acknowledged, completed, rejected, expired or uncertain distinctly.

    adapter receipt · terminal source · correlation

Interfaces that a production program must own.

01

Telemetry ingress

Versioned signals, source clocks, sequence, quality and consent.

02

Digital twin

Current/historical state with source, freshness and projection revision.

03

Remote actions

Capability, preconditions, nonce, expiry, idempotency and terminal evidence.

04

Lifecycle

Provisioning, configuration, health, update, transfer and decommission.

Failure states stay truthful and useful.

No network

Retain bounded priority events and declare queue pressure or loss; never backfill silently.

Duplicate or late delivery

Preserve source identity, project once and never regress the twin watermark.

Consent withdrawn

Stop new projection for the purpose and preserve only approved audit evidence.

Command acknowledgement missing

Expose uncertain/expired state; do not display vehicle completion.

Privilege follows the narrowest useful boundary.

  • Unique device and service identity with tenant/program binding
  • Purpose, role and field policy before storage or projection
  • Mutually authenticated ingress and replay-resistant command envelopes
  • Owner transfer revokes prior rights and rebinds vehicle context
  • Secrets, VIN and precise location are redacted from support traces

A green demo is not a production acceptance case.

  • 01Signal/schema compatibility and source-binding tests
  • 02Network loss, duplication, gap and delayed-delivery replay
  • 03Consent, ownership-transfer and retention evidence
  • 04Remote-action authorization, timeout and uncertain-outcome tests
  • 05Target TCU/vehicle/cloud/app correlation and rollback evidence

Compose the system without collapsing product ownership.

Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.

OEM program workshop

Turn the Connected Vehicle System reference into your program architecture.

Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.