12.07.2015 Views

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

7. Accept and store link decryption keys, and associated parameters, providedby the SM. The LDB shall have the capacity to store at least 16key/parameter sets.8. Purge LD keys upon expiration of the SM designated validity period, SM“purge” command, Link Decryptor Block SPB tamper detection, break ofprojector LDB SPB electrical connection, or change in TLS networkparameters suggestive of an attack or equipment substitution.9. Record security event data for logging under both powered and un-poweredconditions. Assemble logged information into standardized log records perSection 9.4.6.3 Logging Subsystem. If the LDB provides logging support forthe projector SPB via a marriage connection per Section 9.4.3.6.1 Item 3,then the LDB shall provide such logging support 24/7 under both poweredand un-powered conditions.10. Monitor Link Decryptor Block SPB physical security protection integrity 24/7.In the event of intrusion or other tamper detection, terminate all activity, logthe event, and zero all Critical Security Parameters (see Section 9.5.2.6Critical Security Parameters and D-<strong>Cinema</strong> Security Parameters).9.4.3.6.2.1. Normative Requirements for LD/LE SPB DevicesThe following requirements are normative where a special purpose SPB thatperforms link decryption followed by link encryption is used (see Section 9.4.4.1):1. Within the LD/LE Device's type 1 SPB perimeter, perform link decryptionfollowed by link encryption at the image essence input and output ports.2. Respond to the Security Manager's (SM's) initiatives in establishing aTransport Layer Security (TLS) session and SPB device authentication.Maintain this session until commanded to terminate.3. LD/LE SPB Devices shall not establish security communications with morethan one SM at a time.4. LD/LE SPB Devices shall contain a UTC time reference clock that isbattery backed and operative for time stamping log events under poweredand un-powered conditions. The SPB shall communicate time informationwith the SM using standardized Intra-Theater Messaging.5. Respond to SM "status” queries, and other Intra-Theater Messages (ITMs)and SM commands as necessary to support SM behavior requirements.6. Accept and store LD/LE keys, and associated parameters, provided by theSM. The SPB shall have the capacity to store at least 16 key/parametersets.7. Purge LD/LE keys upon expiration of the SM designated validity period,SM "purge” command, SPB tamper detection, or change in TLS networkparameters suggestive of an attack or equipment substitution.8. Record security event data for logging under both powered and unpoweredconditions. Sign and assemble logged information intostandardized log records per Section 9.4.6.3.9. Monitor LD/LE SPB Device physical security protection integrity 24/7. Inthe event of intrusion or other tamper detection, terminate all activity, log<strong>DCI</strong> <strong>Digital</strong> <strong>Cinema</strong> System Specification v.1.2 Page 115

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!