This page was not yet optimized for use on mobile devices.
Christie IMB-S4 4K Integrated Media Block (IMB)
Certificate details
| Certificate ID | #5099 |
|---|---|
| Status | active |
| Validation dates | 01.12.2025 |
| Sunset date | 30-11-2030 |
| Standard | FIPS 140-3 |
| Security level | 2 |
| Type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Caveat | When operated in approved mode |
| Exceptions |
|
| Description | The Christie IMB-S4 is a DCI-compliant solution to enable the playback of video, audio, and timed text essences on Christie Digital CineLife+ projectors. |
| Vendor | Christie Digital Systems Canada Inc. http://www.christiedigital.com |
| Lab | AEGISOLVE, Inc. |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES, CAST, HMACAsymmetric Algorithms
RSA 2048Hash functions
SHA-1, SHA-256, MD5Protocols
TLS 1.0Randomness
DRBG, RBGTrusted Execution Environments
PSPVendor
NXPSecurity level
Level 2, level 2Certification process
out of scope, Any firmware loaded into this module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validationCross-references
Outgoing- 2048 - historical - Allegro Cryptographic Engine
Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
Loading...
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 5099,
"dgst": "86ca719e42d65ce5",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"#A4665",
"RSA SigVer (FIPS186-4)C838",
"SHA-1A4665",
"#C838",
"SHA2-256C837",
"#C837"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"2048"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"2048"
]
}
},
"policy_prunned_references": {
"_type": "Set",
"elements": [
"2048"
]
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 0,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "RSA SigVer (FIPS186- 4)",
"cavpCertName": "C838",
"properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072",
"reference": "FIPS 186-4"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A4665",
"properties": "Message Length - Message Length: 8-1024 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A4665",
"properties": "Message Length - Message Length: 8-1024 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "C837",
"properties": "Message Length - Message Length: 0-51200 Increment 8",
"reference": "FIPS 180-4"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Verify authenticity and integrity of firmware package.",
"indicator": "Ethernet (S4- Data) Status (FIPS_STATE) == approved",
"inputs": "Firmware Package, CAVE SMS Certificate",
"name": "Upgrade",
"outputs": "Ethernet (S4- Data) Upgrade Status == Success",
"rolesSspAccess": "Crypto Officer - Christie Firmware Update Certificate: E - Christie Firmware Update Public Key: E - Cave SMS Certificate: W - Cave SMS Public Key: W - Christie Root CA Self Signed Certificate: E - Christie Root CA Public Key: E - Christie CA Certificate Chain: E",
"secFunImpl": "Digital Signature Secure Hash"
},
{
"description": "Retrieve hardware version and firmware version (Show Version)",
"indicator": "Ethernet (S4- Data) Status (FIPS_STATE) == approved",
"inputs": "None",
"name": "Get Module Information",
"outputs": "Hardware Version, Firmware Version",
"rolesSspAccess": "Unauthenticated",
"secFunImpl": "None"
},
{
"description": "Retrieve Status (Show Status)",
"indicator": "Ethernet (S4- Data) Status (FIPS_STATE) == approved",
"inputs": "None",
"name": "Get Status",
"outputs": "Status of module",
"rolesSspAccess": "Unauthenticated",
"secFunImpl": "None"
},
{
"description": "Run pre- operational self-tests",
"indicator": "N/A - self-tests are performed at boot-up irrespective of the mode of operation.",
"inputs": "None",
"name": "Perform Self-test (power cycle)",
"outputs": "Ethernet (S4- Data) FIPS_STATE == approved",
"rolesSspAccess": "Unauthenticated",
"secFunImpl": "None"
},
{
"description": "Zeroize all SSPs",
"indicator": "FIPS Error State",
"inputs": "None",
"name": "Zeroization",
"outputs": "FIPS Error State",
"rolesSspAccess": "Crypto Officer - Christie Firmware Update Certificate: Z - Christie Firmware Update Public Key: Z - Cave SMS Certificate: Z - Christie Root CA Self Signed Certificate: Z - Christie Root CA Public Key: Z - Christie CA Certificate Chain: Z",
"secFunImpl": "None"
},
{
"description": "Retrieve status of upgrade",
"indicator": "Ethernet (S4- Data) Status (FIPS_STATE) == approved",
"inputs": "None",
"name": "Get Upgrade Status",
"outputs": "Status Information of upgrade",
"rolesSspAccess": "Unauthenticated",
"secFunImpl": "None"
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [
{
"description": "Identity-based operator authentication",
"mechanism": "RSA Digital Signature Verification",
"name": "RSA Digital Signature Verification",
"perMinute": "There is a 1 second retry delay after each attempt which limits the number of attempts that can be launched per",
"strength": "The authentication is based on RSA 2048 which provides an equivalent encryption strength of 112 bits. The"
},
{
"description": "",
"mechanism": "",
"name": "",
"perMinute": "minute. The probability that a random attempt will successfully authenticate to the module within one minute is 60/2 ^ 112 which is less than 1/100,000.",
"strength": "probability that a random attempt will succeed, or a false acceptance will occur is 1/2 ^ 112 which is less than 1/1,000,000."
}
],
"found": true,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "RSA SigVer (FIPS186- 4) (C838)",
"condition": "Power-Up",
"details": "Sign, Verify",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=KAT_CHECK\" and FIPS LED will be solid red.",
"testMethod": "KAT",
"testProps": "2048-bit data, 160- bit digest",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-256 (A4665)",
"condition": "Power-Up",
"details": "Secure Hash",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=KAT_CHECK\" and FIPS LED will be solid red.",
"testMethod": "KAT",
"testProps": "SHA-256, 256-bit data",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A4665)",
"condition": "Power-Up",
"details": "Secure Hash",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=KAT_CHECK\" and FIPS LED will be solid red.",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigVer (FIPS186- 4) (C838)",
"condition": "Conditional",
"details": "Verify",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=UPGRADE_FAILURE\" and FIPS LED will be solid red.",
"testMethod": "SW/FW Load",
"testProps": "2048-bit key with SHA2-256 Signature Verification",
"type": "SW/FW Load"
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "Full loss of power Security Enclosure Removal Started by Crypto Officer",
"description": "Tampering, Zeroization Service",
"indicator": "FIPS LED will be solid red.",
"name": "Tampered",
"recoveryMethod": "Return to Factory"
},
{
"conditions": "Pre-operational self-test failure",
"description": "Critical Function Failure",
"indicator": "FIPS LED will be solid red.",
"name": "Self-Test Failure",
"recoveryMethod": "Return to Factory"
},
{
"conditions": "Incorrect checksum",
"description": "Verify Firmware Integrity SHA2-256 checksum",
"indicator": "FIPS LED will be solid red.",
"name": "Firmware Integrity Failure",
"recoveryMethod": "Return to Factory"
},
{
"conditions": "Signature Verification or SHA Checksum failure.",
"description": "Failure during firmware load",
"indicator": "FIPS LED will be solid red.",
"name": "Firmware Load Test Failure",
"recoveryMethod": "Power Cycle"
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [
{
"inspectFreq": "Upon receipt of module and as often as feasible.",
"inspectGuidance": "Visually inspect metal enclosure for scratches, gouges, deformation, and other signs of visible signs of tamper.",
"mechanism": "Metal Security Enclosure"
},
{
"inspectFreq": "Upon receipt of module and as often as feasible.",
"inspectGuidance": "Visually inspect the tamper evident seals for scratches, gouges, deformation, or other physical signs of tampering.",
"mechanism": "Tamper Evident Seals"
}
],
"found": true,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "Running in non- approved mode of operation",
"name": "Non- Approved",
"statusIndicator": "The module supports a separate indicator for non-approved security services. Module will display Ethernet (S4-Data) Status (FIPS_STATE) == non-approved",
"type": "Non- Approved"
},
{
"description": "Running in approved mode of operation",
"name": "Approved",
"statusIndicator": "The module supports a separate indicator for approved security services. Module will display Ethernet (S4-Data) Status (FIPS_STATE) == approved",
"type": "Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [
{
"name": "MD5",
"use": "Used as part of the TLS 1.0 implementation."
},
{
"name": "RSA (non-compliant)",
"use": "Used as part of the TLS 1.0 implementation and the Ingest, Generate SM Report, Perform Marriage services."
},
{
"name": "TLS 1.0 KDF (non- compliant)",
"use": "Used as part of the TLS 1.0 implementation."
},
{
"name": "AES (non-compliant)",
"use": "Used as part of the TLS 1.0 implementation and the Ingest, Load Content, Playback services."
},
{
"name": "HMAC (non-compliant)",
"use": "Used as part of the TLS 1.0 implementation and the Load Content, Playback services."
},
{
"name": "SHS (non-compliant)",
"use": "Used as part of the TLS 1.0 implementation and Generate SM Report, Perform Marriage services."
},
{
"name": "DRBG (non-compliant)",
"use": "Used as part of the TLS 1.0 implementation."
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve and store DCP / KDM",
"name": "Ingest",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Unwrap Content Decryption Keys and perform CPL verification",
"name": "Load Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Decrypt Content, verify frame integrity, and perform playback",
"name": "Playback",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Build and sign the SM Report",
"name": "Generate SM Report",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Perform Electronic Marriage",
"name": "Perform Marriage",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "List all remote device configurations",
"name": "List Remote Device Configurations",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Specify a remote device to ingest content from",
"name": "Add Remote Device Configuration",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Delete a remote device configuration",
"name": "Delete Remote Device Configuration",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Confirm connectivity to FTP Server",
"name": "Test FTP Server",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "List sources to ingest content from",
"name": "List Ingest Sources",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Find all ingestible content on local drives",
"name": "Scan for Ingestible Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Cancel a scan in progress",
"name": "Cancel Scan for Ingestible Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "List all ingestible content found from scan",
"name": "List Ingestible Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Cancel an ingest in progress",
"name": "Cancel Ingest",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Get Status information about current ingest",
"name": "Get Ingest Status",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve list of shared directories on NAS drive",
"name": "Get List of Shared Directories",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve list of content",
"name": "List Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Refresh cached list of content",
"name": "Refresh Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve a CPL",
"name": "Get CPL",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Retrieve details of a CPL",
"name": "Get CPL Details",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Confirm all assets are available for CPL",
"name": "Is CPL Complete",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve a KDM",
"name": "Get KDM",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Remove content from Onboard Storage",
"name": "Delete Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve type of content for UUID",
"name": "Get Type of UUID",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve status of load operation",
"name": "Get Load Status",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Retrieve ID of loaded content",
"name": "Get ID of Loaded Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Enable content looping",
"name": "Enable Looping",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Unload content from memory",
"name": "Unload Content",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Start information collection of Module",
"name": "Get Module Details / History",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve status of information collection",
"name": "Get Status of Information Collection",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve list of show playlists",
"name": "Get Show Playlists",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Determine if all components of show playlist are present",
"name": "Is Show Playlist Complete",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Check if content exists in a playlist",
"name": "Does Content Exist in Show Playlist",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Confirm that all KDMs for playlist are valid at specified time",
"name": "Confirm KDM Validity for Show Playlist",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Validate a specified playlist",
"name": "Validate Show Playlist",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Get the results of the playlist validation",
"name": "Get Show Playlist Validation Results",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Enable flag indicating that scheduler is active",
"name": "Enable Scheduler Support",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Retrieve individual status item",
"name": "Get Status Item",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve SM Leaf Certificate",
"name": "Get SM Certificate",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve LS Leaf Certificate",
"name": "Get LS Certificate",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Stop SM Report generation",
"name": "Stop SM Report Generation",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve Audio Configuration",
"name": "Get Audio Configuration",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Save Audio Configuration",
"name": "Save Audio Configuration",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Verify connectivity to NAS",
"name": "Test NAS Connectivity",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Retrieve status of each storage device",
"name": "Get Storage Status",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Save Storage Configuration",
"name": "Save Storage Configuration",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Get Storage Configuration",
"name": "Get Storage Configuration",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Check for an individual show playlist",
"name": "Does Show Playlist Exist",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Save a show playlist",
"name": "Save Show Playlist",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant)",
"description": "Retrieve a saved show playlist",
"name": "Get Show Playlist",
"role": "Crypto Officer"
},
{
"alg_accessed": "DRBG (non- compliant)",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Adjust the Real Time Clock",
"name": "Adjust Time",
"role": "Crypto Officer"
},
{
"alg_accessed": "MD5 RSA (non-compliant) TLS 1.0 KDF (non- compliant) AES (non-compliant) HMAC (non- compliant) SHS (non-compliant) DRBG (non- compliant)",
"description": "Return True if SM is Busy",
"name": "Is SM Busy",
"role": "Crypto Officer"
}
],
"found": true,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "Latent - Reserved for future use",
"logicalInterface": "Data Input Data Output Control Output Status Output",
"physicalPort": "Aux Audio"
},
{
"data": "Latent - Reserved for future use",
"logicalInterface": "Control Output",
"physicalPort": "Sync Out"
},
{
"data": "Latent - Reserved for future use",
"logicalInterface": "Control Input",
"physicalPort": "Sync In"
},
{
"data": "Time code information",
"logicalInterface": "Control Output",
"physicalPort": "LTC"
},
{
"data": "Unencrypted Audio",
"logicalInterface": "Data Output",
"physicalPort": "AES3 Audio"
},
{
"data": "SSD 1 / 2 / 3 status information",
"logicalInterface": "Status Output",
"physicalPort": "Storage LEDs"
},
{
"data": "DCP / KDM",
"logicalInterface": "Data Input",
"physicalPort": "Ingest USB"
},
{
"data": "DCP / KDM",
"logicalInterface": "Data Input Data Output",
"physicalPort": "Media"
},
{
"data": "Network Link status, Network Activity Status (via LEDs) Unauthenticated Status Information (TCP port 2000)",
"logicalInterface": "Status Output",
"physicalPort": "Media"
},
{
"data": "FIPS Status",
"logicalInterface": "Status Output",
"physicalPort": "FIPS LED"
},
{
"data": "Service Door open / closed",
"logicalInterface": "Status Output",
"physicalPort": "Service Door LED"
},
{
"data": "Unencrypted Video",
"logicalInterface": "Data Output",
"physicalPort": "Video SERDES (S4-Data)"
},
{
"data": "DCP / KDM / Show Playlist",
"logicalInterface": "Data Input Data Output",
"physicalPort": "SSDs M.2"
},
{
"data": "Electrical signal indicating open or closed Marriage Ring",
"logicalInterface": "Control Input",
"physicalPort": "Marriage (S4-Data)"
},
{
"data": "Electrical signal indicating open or closed Service Door",
"logicalInterface": "Control Input",
"physicalPort": "Service Door (S4-Data)"
},
{
"data": "DCP / KDM",
"logicalInterface": "Data Input Data Output",
"physicalPort": "NAS"
},
{
"data": "Network Link status, Network Activity Status (via LEDs) Unauthenticated Status Information (TCP port 2000)",
"logicalInterface": "Status Output",
"physicalPort": "NAS"
},
{
"data": "FPGA handshake signals",
"logicalInterface": "Control Input",
"physicalPort": "Projector I/O (S4-Data)"
},
{
"data": "IMB Ready Electrical Signal",
"logicalInterface": "Control Output",
"physicalPort": "Projector I/O (S4-Data)"
},
{
"data": "Audio",
"logicalInterface": "Data Input",
"physicalPort": "Aux SERDES (S4-Data)"
},
{
"data": "Latent - Reserved for future use",
"logicalInterface": "Status Output",
"physicalPort": "Aux SERDES (S4-Data)"
},
{
"data": "DCP / KDM",
"logicalInterface": "Data Input",
"physicalPort": "Ethernet (S4-Data)"
},
{
"data": "DCP / KDM / Rendered Subtitles",
"logicalInterface": "Data Output",
"physicalPort": "Ethernet (S4-Data)"
},
{
"data": "CEP API",
"logicalInterface": "Control Input",
"physicalPort": "Ethernet (S4-Data)"
},
{
"data": "FTP control as a client to a server",
"logicalInterface": "Control Output",
"physicalPort": "Ethernet (S4-Data)"
},
{
"data": "Unauthenticated Status Information (TCP port 2000)",
"logicalInterface": "Status Output",
"physicalPort": "Ethernet (S4-Data)"
},
{
"data": "N/A",
"logicalInterface": "Power",
"physicalPort": "Ingest USB"
},
{
"data": "N/A",
"logicalInterface": "Power",
"physicalPort": "SSDs M.2"
},
{
"data": "N/A",
"logicalInterface": "Power",
"physicalPort": "Battery 1 \u0026 2"
},
{
"data": "N/A",
"logicalInterface": "Power",
"physicalPort": "S4-Power"
},
{
"data": "Latent - Reserved for future use",
"logicalInterface": "Status Output",
"physicalPort": "DAD"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "RSA Digital Signature Verification",
"name": "Crypto Officer",
"operatorType": "Crypto Officer",
"type": "Identity"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "2",
"section": "1",
"title": "General"
},
{
"level": "2",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "3",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "3",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "3",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "N/A",
"section": "6",
"title": "Operational environment"
},
{
"level": "2",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "3",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "2",
"section": "10",
"title": "Self-tests"
},
{
"level": "3",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "N/A",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "2",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "Check Security MCU",
"details": "Check Security MCU",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=SECURITY_MCU_OFFLINE\" and FIPS LED will be solid red. If success",
"testMethod": "N/A",
"testProps": "N/A",
"type": "Critical Function"
},
{
"algorithmOrTest": "Check Enclosure Status",
"details": "Check Enclosure Status",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=TAMPERED: 1 EN_OPEN: 1\" and FIPS LED will be solid red.",
"testMethod": "N/A",
"testProps": "N/A",
"type": "Critical Function"
},
{
"algorithmOrTest": "Check NXP SE050",
"details": "Check NXP SE050",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=TPM_FAILURE\" and FIPS LED will be solid red.",
"testMethod": "N/A",
"testProps": "N/A",
"type": "Critical Function"
},
{
"algorithmOrTest": "SHS",
"details": "Secure Hash",
"indicator": "If success, \"FIPS_ERROR=None\" and FIPS LED will be solid green. If failed, \"FIPS_ERROR=IMAGE_INTEGRITY\" and FIPS LED will be solid red.",
"testMethod": "FW Integrity",
"testProps": "SHA2-256",
"type": "SW/FW Integrity"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "N/A",
"distribution": "Automated",
"entry": "Electronic",
"format": "Plaintext",
"name": "Factory Installed",
"sfiAlgo": "",
"source": "Manufacturer"
},
{
"dest": "IMB CPU RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Plaintext",
"name": "Upgrade Service",
"sfiAlgo": "",
"source": "Ethernet (S4-Data)"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "Start the zeroization service.",
"method": "Zeroization Service",
"operatorId": "Zeroization Service",
"rationale": ""
},
{
"description": "Security Enclosure Removal or full loss of power",
"method": "Tamper",
"operatorId": "Remove Security Enclosure Remove Both Batteries and main power",
"rationale": ""
},
{
"description": "Loss of Main Power but battery power is still present",
"method": "Loss of Main Power",
"operatorId": "Disconnect power from S4-Power Physical Port",
"rationale": ""
},
{
"description": "SSP temporary values are zeroised at the completion of a service",
"method": "Completion of Service",
"operatorId": "Automatically performed by the module",
"rationale": ""
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "System Memory",
"name": "IMB CPU RAM",
"persistance": "Dynamic"
},
{
"description": "System Non-Volatile Memory",
"name": "IMB CPU Flash",
"persistance": "Static"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [
{
"features": "N/A",
"fwVersion": "1.0.0- 5494@a",
"hwVersion": "000-201699- 01",
"modelPartNum": "Christie IMB-S4 4K Integrated Media Block (IMB)",
"processors": "Intel Atom x7-E3950 and SE050 (HW P/N: N7121 B1)"
},
{
"features": "",
"fwVersion": "Value",
"hwVersion": "Status Item",
"modelPartNum": "Data",
"processors": ""
},
{
"features": "",
"fwVersion": "IMB-S4",
"hwVersion": "FIPS Model Name",
"modelPartNum": "Module name",
"processors": ""
},
{
"features": "",
"fwVersion": "000-201699-01",
"hwVersion": "FIPS Hardware Version",
"modelPartNum": "Hardware part number / version",
"processors": ""
},
{
"features": "",
"fwVersion": "1.0.0-5494@a",
"hwVersion": "IMB Software Version",
"modelPartNum": "Firmware Version",
"processors": ""
}
],
"found": true,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"RSA": {
"RSA 2048": 6
}
},
"certification_process": {
"OutOfScope": {
"Any firmware loaded into this module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation": 1,
"out of scope": 1
}
},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"TLS": {
"TLS": {
"TLS 1.0": 60
}
}
},
"crypto_scheme": {},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"fips_cert_id": {
"Cert": {
"Certificate 2048": 1
}
},
"fips_certlike": {
"Certlike": {
"# A4665": 1,
"- PKCS 1": 1,
"AES3": 1,
"PKCS 1": 1,
"RSA 2048": 6,
"SHA-1": 7,
"SHA-256": 2,
"SHA2-256": 11
}
},
"fips_security_level": {
"Level": {
"Level 2": 3,
"level 2": 1
}
},
"hash_function": {
"MD": {
"MD5": {
"MD5": 53
}
},
"SHA": {
"SHA1": {
"SHA-1": 7
},
"SHA2": {
"SHA-256": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 53
},
"RNG": {
"RBG": 2
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-3": 6,
"FIPS 180-4": 3,
"FIPS 186-4": 3,
"FIPS 186-5": 2,
"FIPS140-3": 1,
"FIPS186-4": 3
},
"PKCS": {
"PKCS 1": 1
},
"X509": {
"X.509": 8
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 53
},
"CAST": {
"CAST": 6
}
},
"constructions": {
"MAC": {
"HMAC": 53
}
}
},
"tee_name": {
"AMD": {
"PSP": 7
}
},
"tls_cipher_suite": {},
"vendor": {
"NXP": {
"NXP": 4
}
},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"RSA SigVer (FIPS186-4)C838",
"SHA2-256C837",
"SHA-1A4665"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A4665",
"#C838",
"#C837"
]
},
"policy_metadata": {
"/Author": "Hawes, David J. (Fed)",
"/CreationDate": "D:20251121085527-05\u002700\u0027",
"/Creator": "Microsoft\u00ae Word for Microsoft 365",
"/ModDate": "D:20251121085527-05\u002700\u0027",
"/Producer": "Microsoft\u00ae Word for Microsoft 365",
"pdf_file_size_bytes": 692007,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 33
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "88637ce2fb4cc1fe81c1ae4f0bbb2f863942ae5065fe87a50d3e22a2441162fb",
"source_hash": "c10b68696f24f9f5fa0d9e3e54d0270cc7f1028305045a7bbd6dadf2b1348aec",
"txt_hash": "76009a9c719b7b3ffd776d5062c5d6183a7cfd0e2fb5863348b1c2e2987d9335"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in approved mode",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/December 2025_230126_1053.pdf",
"date_sunset": "2030-11-30",
"description": "The Christie IMB-S4 is a DCI-compliant solution to enable the playback of video, audio, and timed text essences on Christie Digital CineLife+ projectors.",
"embodiment": "Multi-Chip Embedded",
"exceptions": [
"Cryptographic module interfaces: Level 3",
"Roles, services, and authentication: Level 3",
"Software/Firmware security: Level 3",
"Operational environment: N/A",
"Non-invasive security: N/A",
"Sensitive security parameter management: Level 3",
"Life-cycle assurance: Level 3",
"Mitigation of other attacks: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 2,
"mentioned_certs": {},
"module_name": "Christie IMB-S4 4K Integrated Media Block (IMB)",
"module_type": "Hardware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2025-12-01",
"lab": "AEGISOLVE, Inc.",
"validation_type": "Initial"
}
],
"vendor": "Christie Digital Systems Canada Inc.",
"vendor_url": "http://www.christiedigital.com"
}
}