ISO 26430-2:2008
Digital cinema (D-cinema) operations — Part 2: Digital certificate
Digital cinema (D-cinema) operations — Part 2: Digital certificate
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 19
- Дата публикации:
- 20 августа 2008 г.
- Издание:
- ISO IS 26430 edition 1 version 1
- ICS:
- 35.040
ISO 26430-2:2008 presents a specification for digital certificates for use in digital cinema systems. ISO 26430-2:2008 defines the digital certificate format and associated processing rules in sufficient detail to enable vendors to develop and implement interoperable security solutions. In the digital cinema environment, certificates have the primary applications of: establishing identity of security devices; supporting secure communications at the network layer, or application-messaging layer; authentication and integrity requirements for Composition Play Lists (CPL) and Packing Lists (PL).
Abstract
Overview
ISO 26430-2:2008 - Digital cinema (D‑cinema) operations - Part 2: Digital certificate specifies a constrained X.509v3 certificate format and processing rules for use in digital cinema systems. Developed from SMPTE 430-2-2006, the standard defines how certificates are encoded (ASN.1 DER), what fields are required, and how certificate chains and validation should be handled so vendors can implement interoperable, high‑security D‑cinema solutions.
Keywords: ISO 26430-2, digital cinema, D-cinema, digital certificate, X.509v3, certificate processing, ASN.1 DER
Key topics and technical requirements
- Constrained X.509v3 format: Uses widely supported X.509v3 features but restricts optional complexity to improve interoperability.
- Required fields: SignatureAlgorithm, SignatureValue, Version, SerialNumber, Signature (inside), Issuer, Subject, Validity, SubjectPublicKeyInfo and AuthorityKeyIdentifier (as specified in the standard).
- Encoding rules: Certificates shall be encoded with ASN.1 Distinguished Encoding Rules (DER) to produce canonical byte representations.
- Thumbprints and naming: Includes guidance on subject and issuer naming, root/organization identifiers, public key thumbprints and role descriptions (CommonName usage).
- Processing and validation: Defines certificate processing rules, validation context, chain verification and human verification recommendations to establish trust in device identities.
- Security primitives referenced: RSA/PKCS#1, SHA-1/SHA-256 (FIPS-180-2), and related IETF/ITU standards (e.g., RFC3280, RFC4055, X.509).
- Interoperability focus: Balances security, scalability and ease of vendor implementation without requiring a centralized certification lab.
Applications and who uses it
ISO 26430-2 is intended for organizations and professionals building or operating secure D‑cinema ecosystems:
- Studios / Rights Owners issuing keys and KDMs (Key Delivery Messages)
- Distributors and exhibitors securing media delivery and playback
- Equipment vendors (media decryptors, link encryptors/decryptors, security entities) implementing certificate issuance and verification
- System integrators and TMS (Theatre Management System) developers integrating TLS, Extra‑Theatre Messages (ETM), CPL and PL authentication
- Security architects designing trust models, CA hierarchies and certificate lifecycle policies
Practical uses include authenticating device identity, securing TLS sessions for intra‑theater messaging, and providing authentication and integrity for Composition Play Lists (CPL) and Packing Lists (PL).
Related standards
- ISO 26430-1: Key delivery message (KDM)
- ISO 26430-3: Generic extra‑theatre message format
- ITU‑T X.509, RFC3280 (X.509/CRL profiles), RFC4055, FIPS-180-2, PKCS#1
Note: ISO 26430-2:2008 indicates there may be patent claims related to parts of the specification; see the standard for details.
Технические детали
- Технический комитет
- ISO/TC 36 - Cinematography
- SKU
- ISO 26430-2:2008
Похожие стандарты
Стандарты, упомянутые в описании