12.07.2015 Views

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

DCI Specs - Digital Cinema Initiatives

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

secure silicon chip, input/output signals to the chip, and signals goingbetween the SPBs is not possible without causing permanent and easilyvisible damage to either or both of the SPBs.• Projector SPB access doors or panels shall be lockable using pick-resistantmechanical locks employing physical or logical keys, or shall be protectedwith tamper-evident seals (e.g., evidence tape or holographic seals). Inaddition, protection from external probing of security-sensitive signals (i.e.,image essence and the silicon chip input/output signals) shall be provided byassuring barriers exist to prevent access to such signals via ventilation holesor other openings.The FIPS references of only this section establish technical and robustness thresholdsfor selected aspects of projector SPB implementations. The requirements to follow FIPS140-2 guidelines do not require FIPS certification or strict FIPS 140-2 documentation orevaluation criteria be undertaken.In summary, a tamper detecting/responding secure silicon chip provides protection forCSPs. Protection for image essence (and the silicon chip) is provided by the projector’sSPB’ physical perimeter. An SPB type 2 intrusion detection/response is minimallyprovided by the access door open detection, and Exhibition visual inspection is reliedupon to detect physical abuse that might allow compromise of, or access to, decryptedimage essence.9.5.2.5. FIPS 140-2 Requirements for Type 1 Secure Processing BlocksRobustness requirements for <strong>Digital</strong> <strong>Cinema</strong> Secure Processing Blocks (SPBs) shallfollow the guidelines of the Federal Information Processing Standards [FIPS PUB 140-2] 28 . A summary of these requirements is shown in the table below.FIPS 140-2 specifies eleven areas for evaluation against a rating, which shall beperformed by US government recognized independent laboratories.All SPB type 1 shall meet and be certified for the requirements of FIPS 140-2 Level 3 inall areas except those subject to the following exceptions or additional notes (the Nrindicators refer to the table items by row):• Nr 2 – Logical data port separation requirements shall be supported by theuse of Transport Layer Security (TLS) protection on well known port 1173 asdefined in Section 9.4.5.2.3 General RRP Requirements.• Nr 6 – The software operating environment of Secure Processing Blocks(SPBs) shall be restricted to the Limited Operational Environment. Thiseliminates the requirements for Common Criteria (CC) and EvaluationAssurance Level (EAL) testing, and any additional FIPS140-2-specificlogging/audit processes other than those specified in Section 9.5.2.7 SPBFirmware Modifications for firmware modifications.• Nr 7 – Section 9.7 Essence Encryption and Cryptography of these <strong>Digital</strong><strong>Cinema</strong> requirements shall supersede any conflicts with Nr 7.• Nr 8 – Secure Processing Blocks (SPBs) shall only be required to meetSecurity Level 2 business use A FCC class requirements.28 Readers unfamiliar with [FIPS PUB 140-2] will need to refer to the standards text to fully understand the table andexceptions.<strong>DCI</strong> <strong>Digital</strong> <strong>Cinema</strong> System Specification v.1.2 Page 138

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!