12.07.2015 Views

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

performed under the supervision of the security equipment vendor.Maintenance of the SPB type 2 (projector) is permitted for non-securitycomponents accessible via maintenance openings.• All type 1 SPBs shall be issued a new private/public key pair and certificateupon any repair or renewal process that requires opening of the SPBperimeter. (Note that Section 9.7.6 precludes maintaining records of privatekey information.)Repair and renewal is limited to failed devices, or devices which have lost or zeroed theirsecrets (e.g., private keys or digital certificates). Such maintenance does not effect thedevice’s FIPS 140-2 certification or compliance, as long as Section 9.5.2.5 FIPS 140-2Requirements for Type 1 Secure Processing Blocks requirements are met.Requirements for firmware changes to SPBs are given in Section 9.5.2.7 SPB FirmwareModifications.9.5.2.4. Specific Requirements for Type 2 Secure Processing BlocksThe SPB type 2 container has been defined specifically for protection of image essenceexiting either a Link Decryptor Block or Image Media Block (companion SPBs to theprojector SPB) and entering the projector. The purpose of this SPB is to protect theimage essence signal as far as practical, recognizing that “all the way to light” productionis probably not possible. It is also preferable not to impose formal FIPS 140-2requirements on this SPB, as the security and signal flow functions are relatively simple.This SPB is anticipated to surround two fundamental functional environments:1. A security environment consisting of a secure silicon chip, input/output signals tothe chip and projector SPB perimeter open detection signals and circuits.2. A projector image signal processing environment, that prepares the image signalfor light production.The latter environment may require field maintenance, and therefore the projector SPBis allowed to have access doors available to Exhibition personnel. The logicalrelationship and electrical connectivity between the companion and projector SPB wasdefined in Section 9.4.3.6 Functional Requirements for Secure Processing BlockSystems. In addition to these and the requirements of Section 9.5.2.1 Device PerimeterIssues and Section 9.5.2.2 Physical Security of Sensitive Data additional projector SPBrequirements are as follows:• Table 20: Summary of FIPS 140-2 Security Requirements, FIPS 140-2 level3 requirements shall be followed for area (row) number 2, with TransportLayer Security (TLS) security as defined in these specifications providinginput/output logical separation protection if TLS is used for projectorauthentication. The operational environment of the secure chip shall follow Nr6 of the Limited Operational Environment of Table 20: Summary of FIPS140-2 Security Requirements (also see Section 9.5.2.7 SPB FirmwareModifications).• The projector SPB silicon chip and associated input/output signals shall notbe accessible via the SPB’s maintenance door or other openings (i.e., thereshall be a partition that separates the chip and signals from the maintenanceaccessible areas).• The physical environment surrounding the connected (married) companionand projector SPBs shall be designed such that access to the projector SPB<strong>DCI</strong> <strong>Digital</strong> <strong>Cinema</strong> System Specification v.1.2 Page 137

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!