This is topic KDM timing question in forum Digital Cinema Forum at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=16;t=001410

Posted by Jack Ondracek (Member # 1466) on 03-06-2013, 11:40 AM:
 
Being a drive-in, I can see us getting to within a couple hours of a KDM's expiration on the last night of a booking.

Will a picture play through an expiry time (Doremi)?

I'm assuming the server validates everything at the start of a playlist (that's what it appears to be doing, anyway), and my biggest risk is having to restart, for some reason.
 
Posted by Chris Slycord (Member # 4239) on 03-06-2013, 12:11 PM:
 
On the doremi's I worked with, a movie continued playing when the kdm was set to expire in the middle of the movie.
 
Posted by Manny Knowles (Member # 1171) on 03-06-2013, 12:16 PM:
 
This came up a few weeks back in this thread.

From DCI Specification v1.2

Section 9.4.3.5, Under the sub-heading "Security Manager (SM) Functions."

quote:
2. Security Manager (SM) KDM usage policy is specified as follows:

a. Playout shall be fully supported by a single KDM, inclusive of all required essence
keys and playout time window (i.e., a playout shall not occur that requires the
combination of two or more KDMs).

b. For any given composition, playout shall be enabled for any start time that is within
the KDM's time window.


c. To avoid end of engagement issues, a show time’s playout may extend beyond the
end of the KDM's playout time window, if started within the KDM playout time
window, by a maximum of six (6) hours.


d. Excepting the requirements of item 2c above, the SM shall delete any KDM and
associated keys for which the playback time window has expired (passed).

Emphasis is mine.
 
Posted by Brad Miller (Member # 2) on 03-06-2013, 12:18 PM:
 
Yes it will continue to play as long as you start the feature before the KDM expires. Note the movie has to finish within 6 hours as well, meaning you can't play/pause the show during the KDM window and run it the next day.

Also note playlists are MAXIMUM of 6 hours, so if you decide to do a triple feature, you had better watch the total length of the playlist because at 6 hours *poof* the show is over.
 
Posted by Gavin Lewarne (Member # 5397) on 03-06-2013, 12:52 PM:
 
Brad - I didnt know this....what happens at 6 hours? does it just stop?

I was about to program a continious triple feature marathon but now i will do them seperatly
 
Posted by Brad Miller (Member # 2) on 03-06-2013, 02:29 PM:
 
Each server may be different as I've not tested it on anything but a Dolby, but either the picture and/or sound stops, or the server stops playback.
 
Posted by Jack Ondracek (Member # 1466) on 03-06-2013, 03:43 PM:
 
Thanks, all. Manny... good info.

Brad, one of your customers was talking about that in another chat list we have. I wasn't aware of the 6-hour limit, but I'm sure other "triple-feature players" will be interested.

Does this regard continuous playout, or does a pause (intermission) in the playlist make any difference?
 
Posted by Dave Macaulay (Member # 813) on 03-06-2013, 06:56 PM:
 
Once the playlist is started you can have pauses but the 6hr limit has to be considered. You could start a playlist (on a Doremi you just press "pause", the server does its security checks and stops at playback time "00:00:00" - put your first macro at +1 second or it will execute when you "pause") and then wait past the KDM expiry to actually start it.
 
Posted by Joris Springer (Member # 4175) on 03-12-2013, 05:19 PM:
 
The time limit in the KDM personally frustrates me, sometimes you get a KDM just for 10 days which is every 10 days renewed, all it causes is extra costs and extra money even though the logs already tell the distributor when a movie is played.
Sure a time limit can be useful but seriously, a premiere movie and a key just for 1 day, or even a sneak preview that is valid for just 5 hours?
Talking about being paranoid and yet, blu-rays leak out weeks before release, how about securing that more tightly instead of a movie that is not even playable on normal computers?

They said Digital would make the work more easy and yet the KDM's make it already more frustrating with all the licensing and serial numbers...
 
Posted by System Notices (Member # 2357) on 10-16-2014, 10:51 PM:
 

It has been 583 days since the last post.


 
Posted by Tim Sherman (Member # 569) on 10-16-2014, 10:51 PM:
 
Any idea if the 6 Hour time limit is affecting Doremi Showvault with IMB, running the most current Firmware? I ran a playlist over 6 hours last year if i'm not mistaken and it ran just fine.
The playlist I am planning on running is just under 7 hours. It will be a mix of encrypted and unencrypted movies.
 
Posted by Marcel Birgelen (Member # 6801) on 10-17-2014, 01:09 AM:
 
This has nothing to do with a general max. playlist length, but with KDMs and expiry.

If all encrypted content in this playlist expires after the end of the show, there should be no problem at all. If it expires while playing the show, the limit should apply to all encrypted content that was STARTED BEFORE expiry, but ended up expiring while playing. If you're playing a mix of content and you end up trying to start something past KDM expiry, you're out of luck.

This "6h limit" for showtime ends of encrypted content past expiration should affect all servers, as this is enforced per DCI specs.
 
Posted by Frank Angel (Member # 248) on 10-17-2014, 08:33 AM:
 
How exactly does having a 6hr playlist limit protect the studio from anything -- perhaps some unscrupulous exhibitor sneaking in an unauthorized show or a pirate with an eye patch hiding in the DI bushes hell bent on doing some nefarious copyright infringement? If the right to play a title is given via a KDM for a certain time frame, why is there an additional limit imposed by the "player?" Seems the KDM should be valid no matter how the title is programmed at the site.

Really, it's a totally foolish and useless restriction borne out of the well established studio "piracy paranoia," ESPECIALLY as there are now exhibitors such as DIs who routinely run programs like triple features that play longer than 6hrs. But then again, never was distribution terribly concerned about the burden caused by their unilateral imposition of digital on exhibition.
quote: Joris Springer
...it causes is extra costs and extra money even though the logs already tell the distributor when a movie is played.
No doubt, Joris.

What I don't quite understand is, the KDMs can be authored to whatever time the distributor has booked the film; if it is known that an exhibitor is running triple features that run over the 12m mark, why can't the distributor just send a KDM that accommodates that need? Or it is just business as usual, i.e., the day ends at 12m and to hell with what the exhibitor needs? It's not brain surgery for the studio to author the KDM to end at 2am. What's the big deal or is it just orneriness?
 
Posted by Carsten Kurz (Member # 5396) on 10-17-2014, 08:53 AM:
 
Again - there is NO 6hr playlist limit imposed by DCI, studios, etc.

Such a limit is purely up to the server manufacturer/software programmer. They may impose one for certain reasons or not, just as they would impose limits on the max number of DCPs or KDMs in storage for specific reasons or not. Some may actually use the DCI-imposed KDM playback-expiration limit of 6hrs as a reason to internally limit all playlists to 6hrs max. But that is not what DCI intended with it, and it is not what DCI enforces.

In reality, this is not really a problem. There may be rare cases where a KDM expires unreasonably fast. Most of our KDMs expire at a time around 1 or 3 o'clock in the morning, but typically multiple days or weeks, sometimes months, after booking expired.

A KDM expiring at 1 o'clock in the morning means that the feature could be played until 7 o'clock if contained in a playlist and paused within. The last option to start the feature OR playlist containing this feature would be 0:59:59 or whatever a few seconds would give around checking for the condition. I don't see what the issue here should be. If a KDM is issued too sharp, then request another one and quote a good reason. True, festival KDMs with 3hr validity windows are stupid, but there is neither the server company nor the DCI to blame for it. If your showtimes are a moving target, you should notify the KDM issuing entity of this in advance, or make sure someone is answering the phone instantly once you need a prolongation.

- Carsten
 
Posted by Frank Angel (Member # 248) on 10-17-2014, 08:53 AM:
 
How exactly does having a 6hr playlist limit protect the studio from anything -- perhaps some unscrupulous exhibitor sneaking in an unauthorized show or a pirate with an eye patch hiding in the DI bushes hell bent on doing some nefarious copyright infringement?

If the right to play a title is given via a KDM for a certain time frame, why is there an additional limit imposed by the "player?" Seems the KDM should be valid no matter how the title is programmed at the site.

Really, the 6hr limit is a totally foolish and useless restriction borne out of the well established studio "piracy paranoia," ESPECIALLY as there are now exhibitors such as DIs who routinely run programs like triple features that play longer than 6hrs. But then again, never was distribution terribly concerned about the burden caused by their unilateral imposition of digital on exhibition.
quote: Joris Springer
...it causes is extra costs and extra money even though the logs already tell the distributor when a movie is played.
No doubt, Joris.

As for the show to terminate after 12m just because it's a new day, that makes no sense at all -- the KDMs are day AND time specific, yes? They are authored to whatever time the distributor has the film booked, If it is known that an exhibitor is running triple features that run over the 12m mark, why can't the distributor just send a KDM that accommodates that need? Or it is just business as usual, i.e., the day ends at 12m and to hell with that it will screw the exhibitor? It's not brain surgery for the studio to just author the KDM to end at 2am rather than midnight. What's the big deal or is it just orneriness? Or worse, do they sit in their offices thinking what a laugh it is that they can cause a guy's show to stop right in the middle of the climax? Or worse than that, do they not even care?
 
Posted by Steve Guttag (Member # 268) on 10-17-2014, 09:30 AM:
 
Is there some goofy 6-hour limit requirement on the TLS session? Subject to interpretation, the keys issued to the "SPB" are supposed to only be valid for 6-hours. So once the show starts, the keys have a 6-hour window for those keys. I'm thinking that may pertain particularly to Enigma based systems the security is handed off to the Link Decryptor.
 
Posted by Carsten Kurz (Member # 5396) on 10-17-2014, 09:57 AM:
 
quote: Frank Angel was the last to post
If the right to play a title is given via a KDM for a certain time frame, why is there an additional limit imposed by the "player?" Seems the KDM should be valid no matter how the title is programmed at the site.
But that is not the case?! The 6hr limit only extends the issuer allowed KDM window into the future for pragmatic reasons - the reason is - no lost shows, or no interrupted shows. This is clearly a feature in favor of the exhibitor, so he has an extended safety window e.g. for intermissions or shifts of showtimes or secure clocks.

If a server would adhere strictly to KDM imposed timeframe, it would be a disantvantage, because the KDM issuing entity can never know in advance which complications could arise on site. The idea is, once a show is started, it should proceed until the end of the feature in order to protect the expectation of the audience and to reduce the danger of having to refund.

- Carsten
 
Posted by Marcel Birgelen (Member # 6801) on 10-17-2014, 10:41 AM:
 
quote: Steve Guttag
Is there some goofy 6-hour limit requirement on the TLS session?
I've never heard about that in particular, but it's not like the DCI specs are so forthcoming in transparency. If it would be, and there is no working infrastructure to renew keys/associations while the feature is playing, it would make any single >6h feature impossible.

We could never have a "The Hobbit - Special Extended Ultimate Edition" or "Transformers 5 - The Director's Ego Cut" in DCP format. At least not as a single feature... shocking. [Wink]

And what Carsten said: If anything besides your customers is limiting you from building a playlist as long as you want, it's for once, not the DCI police's fault, but your server/IMB manufacturer's.
 
Posted by Carsten Kurz (Member # 5396) on 10-17-2014, 11:35 AM:
 
quote: Steve Guttag
Is there some goofy 6-hour limit requirement on the TLS session? Subject to interpretation, the keys issued to the "SPB" are supposed to only be valid for 6-hours. So once the show starts, the keys have a 6-hour window for those keys.
Wouldn't that (literally ;-) at the same time mean you could never pause a playlist for more than 6hrs on an HD-SDI/Enigma system no matter how long the playlist or the KDM window were? That could be easily tested.

- Carsten
 
Posted by Marcel Birgelen (Member # 6801) on 10-17-2014, 12:06 PM:
 
Yeah, that SHOULD have exactly the same result. Maybe you should switch off your lamp though, it's a bit of a waste otherwise...

But then again, DCPs do their best to mimic film with terms like "reels"... After 6 hours you just run out of virtual platter space! [Smile]
 
Posted by Tim Sherman (Member # 569) on 10-17-2014, 12:54 PM:
 
Just ran a test of 6 movies last night in one spl with the lamp turned off. The show ran for 8 hours and 41 minutes till the end of the playlist without problem. So at least on Doremi Showvault/IMB 8+ hour shows aren't an issue as long as KDMs aren't expiring within that time frame.
 
Posted by Steve Guttag (Member # 268) on 10-17-2014, 01:01 PM:
 
Perusing the DCI specifications. You have :

quote:
9.4.3.5.7. Perform remote Secure Processing Block (SPB) and Screen Management System (SMS) authentication through Transport Layer Security (TLS) session establishment, and maintain the certificate lists so collected.
a.
Associate certificate lists with TDLs delivered in KDMs per Section 5.2.5 of the KDM specification (SMPTE430-1: D-Cinema Operations - Key Delivery Message) to support the identification of security devices that are trusted/not trusted.
b.
Maintain TLS sessions open for not more than 24 hours between complete restarts (i.e., forces periodic fresh TLS keys).

Which seems to ensure that you have a maximum of 24-hours in a TLS session so there is an absolute limit there. Elsewhere, they discuss that after a reboot it has to do the whole security check.

But here is one that may fall victim to interpretation:

quote:
9.4.3.5.9

Prepare and issue content keys to Media Decryptor (MD) and Forensic Marking (FM) SEs as may require keying per the CPL. Constrain use of keys to:

b. Usage validity periods of six (6) hours for remote SPBs (in line with the rule of item 2c above).

Item "2c" refers to the situation where if a show starts with a valid key, it is to be allowed to continue for up to 6-hours.

But "usage validity periods" could easily be read as meaning that is how long a key is to be allowed to be valid (within the SPB).
 
Posted by Carsten Kurz (Member # 5396) on 10-17-2014, 01:18 PM:
 
Well unlike the KDM expiration window this doesn't necessary mean that playback or pause would need to be broken after 6 hrs - only that a new session would have to be opened. Couldn't the server handle this transparently - if it enforces it at all.
One could look at the CTP as well, but I can't remember having seen something like that.

Well, hardly an issue under real-world conditions anyway, and rather easy to test over night.

- Carsten
 
Posted by Steve Guttag (Member # 268) on 10-17-2014, 04:11 PM:
 
The problem would be when the TLS session is broken/restarted...the show would stop. Why not just put the shows on the schedule back-to-back-to-back rather than one large show (to make a 6-hour performance. What theatre doesn't want periodic breaks to "lets all go to the lobby." Who's bladder is so good that they want to hold it for 6-hours?
 
Posted by Philip Jones (Member # 6677) on 10-17-2014, 04:13 PM:
 
the only time we've had a very long show was with the final Twilight film when we did a Marathon of the previous 4 culminating with the last one at midnight.

the first 4 films were sent as a single clip and midway through one of them (can't remember how far in it was now) the picture went off but the sound continued. it came up with a Mediablock disconnected error and we had to do a server restart to get things back on properly.

could this have been related to this 6 hour thing?
 
Posted by Carsten Kurz (Member # 5396) on 10-17-2014, 05:06 PM:
 
It could be, from what Steve describes, but on a long continued program like this, it could just as well have been the occasional hickup.

It could easily be tested over night, with the lamp being off.

It's true, though, that the show may not actually stop but only the picture will vanish. I remember that when I recently played with the Doremi and NC900C with HD-SDI/Enigma, I sometimes pulled out the ethernet cable from the projector. I don't know currently wether I had encrypted content running - but I think the audio continued, the picture went black, and the Doremi indicated a 'connection lost'.

Steve is right in that normally you would do something like this with normal single feature SPLs and scheduling.

Of course, that wouldn't work if you intentionally want to spread the key expiration window for one of these features appearing in the later schedules, because scheduling does not keep the keys from expiring after the assigned validity window ;-)

- Carsten
 
Posted by Marcel Birgelen (Member # 6801) on 10-19-2014, 09:37 AM:
 
quote: Steve Guttag
The problem would be when the TLS session is broken/restarted...the show would stop. Why not just put the shows on the schedule back-to-back-to-back rather than one large show (to make a 6-hour performance. What theatre doesn't want periodic breaks to "lets all go to the lobby." Who's bladder is so good that they want to hold it for 6-hours?
It doesn't really make sense to have one >6h feature. So, besides the oddball situation where somebody manages to put a few movies back to back into a single feature (apparently studios manage to do so, at least according to Philip), you would never encounter the problem in production. It's still interesting to know though.

I guess this "limited time-frame of TLS session validity", if it's true (because like you pointed out, the specs are at least a bit ambiguous here), has probably been implemented as a security measure, to avoid data being transferred with the same session key for too long...

Newer implementations of TLS support a "New Session Ticket" extension to the TLS protocol. This allows a renewed key exchange on an open session. Some "SSL VPN" implementations actively use it. It eliminates some overhead, especially over public IP links, but still, the key exchange will introduce some interruption in the actual stream and given the fact that you cannot really buffer much data without causing inherent latency issues, this will probably also cause some noticeable hickups/frame drops if it's actually implemented.
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2