CDSA 01月30日
Renewal & Provisioning Working Group Debut a Set of Implementation Guidelines
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

CDSA旗下的更新与配置工作组发布了流媒体设备安全实施指南,旨在解决内容滥用和服务滥用问题。该指南由内容创作者、流媒体服务提供商、DRM提供商和IP技术提供商共同制定,明确了设备保护服务和内容的安全性期望与功能需求。指南关注DRM可信计算基(TCB)的当前状态,并探讨如何安全更新受损的TCB或凭据,以及防止回滚到易受攻击的固件版本。该指南建立在先前关于设备实现信任根(RoT)的平台无关建议之上,旨在确保设备状态可信,并为安全环境提供合适的DRM凭据。

🔒CDSA工作组发布了流媒体设备安全实施指南,该指南旨在解决内容滥用和服务滥用问题,为行业提供参考。

🛠️该指南由行业内多个领域的专家共同制定,包括内容创作者、流媒体服务提供商、DRM提供商和IP技术提供商,确保了指南的全面性和实用性。

🔄指南重点关注DRM可信计算基(TCB)的更新与维护,并提出了安全更新受损TCB或凭据,以及防止固件版本回滚的方案。

🛡️该指南基于先前关于设备实现信任根(RoT)的建议,旨在建立可信设备状态,并为安全环境提供合适的DRM凭据。

The Renewal & Provisioning Working Group which operates under the CDSA has recently released a set of Implementation Guidelines which are now being shared across the industry for peer review. This group has been meeting bi-weekly for several years with the purpose of understanding how streaming devices can mitigate the risk of content being misused, or services providing that content being abused.

With contributors from across the industry, including Content creators, streaming service providers, DRM providers and IP-technology providers, this group has created security expectations and functional requirements for how devices can protect services and content.

These are reviewed with streaming device manufacturers to ensure expectations are clear and any requirements are practical. Input is also sought on how any recommendations will affect the user experience.

The topic under consideration by the working group led to the creation of a set of Implementation Guidelines which examine the issues associated with establishing the current state of the DRM Trusted Computing Base (TCB).

The TCB consists of hardware, firmware and software components that implement and support the DRM system. The challenges examined by the working group were to consider:

–How to securely update in the field any compromised DRM TCB or credentials in the field.
–How to ensure such updates cannot be rolled back to vulnerable firmware versions.

This builds upon previous work which produced platform agnostic recommendations for devices to achieve a Root of Trust (RoT). The device RoT enables establishment and measurement of the TCB to determine whether the state is adequate and if it is not, support restoring the state to a trustworthy one and then provisioning suitable DRM credentials to the secured environment.

For any additional information about the working group or to get involved please contact the Office of the Secretariat (secretariat@CDSAonline.org).

To provide any feedback on the implementation guidelines please use the feedback form.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

CDSA 流媒体设备安全 DRM 可信计算基 信任根
相关文章