12.07.2015 Views

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

the event, and zero all Critical Security Parameters (see Section 9.5.2.6).Do not purge log records.9.4.3.6.3. Normative Requirements: Image Media Block (IMB)The following are normative requirements for the Image Media Block:1. Perform all SM functions as defined under Section 9.4.3.5 Functions of theSecurity Manager (SM).2. Monitor IMB SPB physical security protection integrity 24/7. In the event ofintrusion or other tamper detection, terminate all activity, log the event, andzero all Critical Security Parameters (see Section 9.5.2.6). If communicationwith the SMS is available, issue an alert message. Do not purge log records.3. The existence of the marriage configuration (i.e., when the IMB and projectorare integrated per Section 9.4.3.6.1. Normative Requirements: ProjectorSecure Processing Block) shall indicate to the Security Manager that linkencryption is not needed. When connected directly to the projector SPB (i.e.,no link encryption used), as part of the installation (mechanical connection tothe projector and electrical initiation), perform electrical and logical marriagewith the projector Secure Processing Block (SPB). Electrical connectionintegrity shall be monitored 24/7, and should the integrity of the connection bebroken, log the event and require a re-installation process before becomingactive again. Breaking of the IMB/projector Secure Processing Block (SPB)marriage shall not zero the IMB Secure Processing Block (SPB) long-termidentity keys (RSA private keys).4. Perform Media Decryption for image, audio and subtitle essence.5. Perform Forensic Marking for image and audio essence.6. After image decryption and Forensic Marking (and other non-security plaintext functions as appropriate by design), pass the image signal to theprojector SPB or Link Decryptor Block, as appropriate..7. Record security event data for logging under both powered and un-poweredconditions. Sign and assemble logged information into standardized logrecords per Section 9.4.6.3 Logging Subsystem. If the IMB provides loggingsupport for the projector SPB via a marriage connection per Section 9.4.3.6.1Item 3, then the IMB shall provide such logging support 24/7 under bothpowered and un-powered conditions.9.4.3.6.4. Normative Requirements: Audio Media BlockPer Section 9.4.2.3 Media Blocks (MBs), audio decryption shall be performed withinthe Image Media Block (IMB).9.4.3.6.5. SPB Systems Implementation and Standards OptionsThe following are considerations for implementation details, and standardization.• For the projector system, authentication of the projector SPB to the SM neednot require TLS sessions between the SM and both the Projector and LinkDecryptor Block SPBs. It may be simpler to have the LDB proxy for a directSM TLS connection with the projector SPB. This option enables the projectorSPB to avoid having its own, separate TLS session with the SM, but shall notsubstitute for the requirement for both the LDB and projector certificates to be<strong>DCI</strong> <strong>Digital</strong> <strong>Cinema</strong> System Specification v.1.2 Page 116

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!