• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer

mkpeReport

top analysis covering digital cinema, 3-D, HFR, and laser illumination

  • Reports
  • About
  • mkpe.com
  • cinepedia.com

NIST/FIPS News

March 2011 by Michael Karagosian

NIST imposes a few challenges to digital cinema as its security requirements migrate to more stringent standards. One of these challenges is with the multiuse of the media block certificate for both digital signatures and decryption of security keys contained in KDMs. But this problem has been solved, at least conceptually. (See last month’s report on this subject.)

Another security update problem is slowly rearing its head, and that’s the migration of signature algorithms from SHA1 to SHA256. No need to look these up in Wikipedia. All that’s needed in terms of understanding is that the algorithm is changing.

Digital signature works by adding additional data to a message (or file) that’s derived from the content of the message itself and the private key of the signer. Upon receipt of the message, the receiving machine can regenerate the additional data using the digital signature algorithm. It then uses the public key of the signer to check that the new additional data generated matches the data that arrived with the message. If they match, then the message is intact and unmodified. If not, then this is taken as evidence of tampering.

Digital signatures are used in several ways in digital cinema: in projector communications, in security key decryption, and in signing security logs. A change in algorithm could cause such mechanisms to be inoperable. In US government work, the migration to the newer algorithm is taken seriously, and the potential for inoperability is real. A recent government public briefing outlines the timeline for the migration, which began in January of this year, and the need for dual recognition of algorithms during the crossover period.

But government agencies are geared to practice the standards imposed on them. So they will employ SHA256 signatures, and require equipment upgrades so that their signatures are recognized. Studios, on the other hand, are less likely to quickly adopt new standards, even though they will impose compliance to the new standards on others. This behavior can be seen in the requirement of equipment to pass DCI Compliance testing, when the studios themselves distribute content that does not comply with DCI specs.

So while new equipment will be required to employ the newer SHA256 for FIPS compliance, it will also be required to support the older SHA1 for backwards compatibility. Knowing that significant numbers of equipment in the field are unlikely to be upgraded with the new algorithm, studios are equally unlikely to move away from the use of SHA1 for many years to come. This would require dual implementation of both algorithms for a long time, much longer than the US government would accept of its own agencies. All this, of course, has yet to be documented in the DCI spec.

Similarly, this behavior of causing others to meet new security requirements while also imposing backwards compatibility on equipment could become the standard operating procedure for new NIST-imposed security standards. Ironically, it will be the studios that will lag most in using updated NIST-approved security methods, even though it will be the studios that demand immediate adoption of these same methods by digital cinema equipment manufacturers.

Filed Under: Servers and IMBs Tagged With: DCI, NIST

Primary Sidebar

Search

Topics

  • 3-D
  • Accessibility
  • Alt Content & Advertising
  • Anti-Piracy
  • Color
  • Communications
  • Deployment Entities
  • Distributors
  • Exhibitors
  • Fulfillment
  • High Dynamic Range
  • Higher Frame Rates
  • Installations
  • Patents
  • Projectors
  • Servers and IMBs
  • Sound
  • Technical Bodies
  • Theatre Management Systems
  • Trade Organizations and Shows

Full Archives

a publication of
MKPE Consulting LLC

Footer

Important Stuff

  • About
  • Privacy Policy

Archives

  • Category & Monthly Archives
Archives date back to 2008.

MKPE

mkpeReport is a publication of MKPE, a world-class consultancy building business at the crossroads of cinema and technology.
Learn more about MKPE.

copyright © 2008 - 2026 mkpe consulting llc

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}