I am coming again.
quote: Michael QuNo. They would also need to know the key that was used to encrypt the picture and sound assets.
Dose this mean anyone who got the encrypted DCP's CPL can make KDM for their server with the server's certification file?
quote: Carl HetheringtonOh, so where is the key stored?
No. They would also need to know the key that was used to encrypt the picture and sound assets.
quote: Carsten KurzHi Carsten,I use DCP-o-matic,which is a free sofetware.I package the DCP with my PC,so the key is in my PC?But I didn't find any other files except the DCP fiLes.
On the machine that you used to create the DCP and KDM.
The KDM then will also store this key, naturally, but encrypted with the target servers certificate. So as long as you don't expose the key from your local machine, your DCP is safe.
Which software are you using?
quote:Source
The first part is simple: ticking the Encrypted box in the DCP tab of DCP-o-matic will encrypt the DCP using a random key that DCP-o-matic generates. The key will be written to the film's metadata file, which should be kept secure.
quote: Marcel BirgelenMore information in the documentation?Several mouths ago,I read the whole document, but this time,only the "KDM" part. I will check it for more.
Michael, did you check the On-line documentation of DCP-o-matic?
quote: Marcel BirgelenOh,this make me clear.I misunderstand the privite key as the key of the DCP Maker
The simplified version:
- You encrypt your content with your own encryption key. Essentially, you encrypt all content related assets in the DCP, both audio and video.
- Your customer's server also has an encryption key stored in the media block, actually a private and a public key. The public key can be exported, the private key in the server remains private, even for the customer. It's protected by all kinds of security measures, so you cannot easily retrieve it from the media block.
- Your customer sends you their public key.
- Now you send them your key to the content via a KDM. But you do not send this key plain text, otherwise your customer could just get the key from the KDM and essentially do whatever they want with it. The key in your KDM is encrypted, using the public key from the server of your customer. This way, it can only be decrypted with the private key inside the media block in the server.
The media block, the protected part in the server, serves as content police and secure key vault. It's responsible for securely storing the server's private key, securely decrypting the content and also enforcing time limitations on the validity of the KDM.
A secure media block must be designed in such a way, that any tampering will essentially destroy the sensitive parts of the memory. It also keeps its own clock, which can only be adjusted within very limited time frames, this is to avoid somebody using the age old trick of resetting the clock to extend content/license validity.
quote: Michael QuMichael - the 'raw' key that is used to encrypt the DCP, and which is used to create the KDM afterwards, is stored with the other project definition in the metadata.xml file. You can look it up there if you want.
I package the DCP with my PC,so the key is in my PC?But I didn't find any other files except the DCP fiLes.
quote: Carsten KurzThanks Carsten,I understand it now.
Michael - the 'raw' key that is used to encrypt the DCP, and which is used to create the KDM afterwards, is stored with the other project definition in the metadata.xml file. You can look it up there if you want.
So this stays safe on your computer, if you don't accidentally copy it with the DCP to a distribution drive. If you lose it, delete the project file/folder, etc., you will not be able to create another KDM for this particular DCP/CPL.
You would have to create the full DCP from scratch incl. encryption with a new key.
To create KDMs, you will first need to create a database of certificates/screen/theater references within DCP-o-matic. When creating a KDM for a specific screen, you will link this screens/servers certificate with the CPL you created, then either store the KDM file locally or set up an email chain to send it directly to the theater/projectionist.
This KDM is then only valid for that particular screen, and within the given time frame you set. DCP-o-matic will create this time frame based on your local machine timezone settings. So if you let the window start at 9am, this will be YOUR 9am. As long as your DCP doesn't cross timezones, you can ignore this.
It has been 1363 days since the last post.
quote: Cameron GlendinningYes, so long as you have a DKDM for the encrypted DCP.
Can you generate KDM's for DCP's authored and encrypted on other software like Clipster, through Dcp O Matic?
quote: Frank AngelDCP-o-matic does it for you, or you can consult The ISDCF's page
Is there a chart showing the specific abbreviations used in the DCP name that identifies the movie title, picture and sound formats etc., and the order they are supposed to be listed when giving the DCP name? Is the DCP name with those specific abbreviations, generated by the DCP authoring software or does it the name need to be created manually?
quote: Frank AngelNot so far as I am aware. If a KDM could be decrypted by anybody then anybody could make new KDMs with different start/stop times.
Secondly, can a KDM be authored so it will have a start and stop dates and times, but not necessarily required to have the private key of the projector, in other words, it can be played anywhere on any projector but restricted to within that specified time frame?
quote: Frank AngelI've only used Doremi servers, and you can on those (just hit pause on the control panel).
If a DCP has multiple items in the playlist, say a film festival with a program of multiple shorts, is it possible for the projectionist (or rather I should say the "server operator") to manually pause between items on the playlist as the show is running and how easy or difficult is it?
quote: Frank AngelOn some equipment (such as Doremi & Christie) it's also possible to build an
is it possible for the projectionist (or rather I should say the "server operator") to manually pause between items on the playlist