12.07.2015 Views

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

with the security system, it is also considered to be part of the Security Entity (SE) 20 . TheSM responds to the directives that Theater Management System (TMS) issues via theSMS. For purposes of simplicity, and subject to the TMS constraint below, thisspecification uses the term SMS to mean either/both Theater Management System(TMS) or Screen Management System (SMS). From the security system perspective,SMS functions are those associated with “category 1” Intra-Theater Messages of Table15: Intra-theater Message (ITM) Request-Response Pairs (RRP).SMS Requirements:• The SMS shall carry a <strong>DCI</strong> compliant digital certificate (see Section 9.5.1) toidentify the SMS entity to the SM. The SMS certificate shall indicate only theSMS role unless the SMS is contained within a SPB meeting the protectionrequirements for any other designated roles.• The SMS digital certificate may be permanent to the SMS, or “operatorcertificates” may be assigned to designated personnel (e.g., using a dongle,smart card, etc.) for association with the SMS.• In the event that Exhibition command and control designs include the TMS as adevice that interfaces with the SMs, such a TMS shall be viewed by the securitysystem as an SMS, and it shall carry a digital certificate and follow all other SMSbehavior, Transport Layer Security (TLS) and Intra-Theater Message (ITM)communications requirements.• Identification of the SMS operator for purposes of the “AuthorityID” field (seeSection 9.4.5.2.4) shall be by:• Certificate thumbprint, where “operator certificates” are used, or• Username/password or the like, as specified by exhibition management.SM interaction with the SMS 21 is normatively defined (see Section 9.4.3.5 Functions ofthe Security Manager (SM)). These include the requirements that:• The SM provides log records identifying the SMS for which it operates, as wellas the AuthorityID field. In the case where “operator certificates” are used, thisinformation is the same (i.e., the digital certificate thumbprint).9.4.2.6. Projection SystemsFrom the security perspective, a projection system consists of the projector type 2Secure Processing Block (SPB) and its “companion” SPB, which will be either the LinkDecryptor Block (LDB) or Image Media Block (IMB). A critical security issue is assuringthat the clear text image output of the LDB or IMB goes to a legitimate projection device.Therefore Section 9.4.3.6.1 Normative Requirements: Projector Secure ProcessingBlock defines a “marriage” process with the companion SPB. The marriage, inconjunction with the Trusted Device List (TDL) and TLS-based authentication of thecompanion and projector SPBs, addresses the legitimate projector security issue.The purpose of the marriage is to have a human authority figure supervise theinstallation of a projection system to assure the physical connection of the two SPBs,20 The Screen Management System (SMS) is part of the Security Entity (SE) but is not a secure device.21 SMS-to-SM Intra-Theater Message (ITM) commands (see Section 9.4.5.3.1 Screen Management System to SecurityManager Messages)include means to carry SMS operator identification via the “AuthorityID” field. The specificoperational policies used at exhibition that surround operator identification, empowerment or enforcement are outside thescope of this specification.<strong>DCI</strong> <strong>Digital</strong> <strong>Cinema</strong> System Specification v.1.2 Page 103

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!