DDL — D‑Cine Display Lock
DDL binds protected playback to one or more approved display chains. A qualified user can enroll several screens so a portable player works with any approved display while rejecting unknown displays when its KDM requires DDL.
KDM targeting
Put DDL1, DDL2 or DDL3 in the signed KDM AnnotationText. The marker may start the annotation or follow an underscore or line break. It must end at the annotation boundary or before a full stop, underscore or line break. Valid examples include DDL3_Feature, Feature_DDL3_Client and Feature_DDL3. Markers are uppercase; repeated, conflicting or unsupported markers fail closed.
| Status | Requirement |
|---|---|
| Unlocked | No protected DDL output is established. |
| DDL1 | Authenticated HDCP; the display need not be enrolled. |
| DDL2 | DDL1 plus an active enrolled EDID/display fingerprint. |
| DDL3 | DDL2 plus the enrolled authenticated HDCP receiver identity and topology. |
Enroll or remove a screen
- Open Config → Display & Time.
- Enter credentials for an Authority user with Can manage D‑Cine Display Lock screens permission.
- Give the screen a friendly name, select its connected display and choose Enroll screen.
- Confirm the generated screen ID and achieved DDL level in the table.
- To revoke it, authenticate and choose Remove. The removal remains in the history.
Credentials are sent only for the live HTTPS authorization and are not stored. Changes fail closed if authority.d-cine.net cannot authorize them. Approved identities are cached locally so playback enforcement does not depend on a live Authority request.
Display identity details
The enrolled-screen table shows the EDID manufacturer code, display/model name, product code, serial number or serial text, manufacture week/year and physical dimensions when the display publishes those fields. It also shows a shortened EDID SHA‑256 fingerprint; the complete EDID hash remains the DDL2 identity. EDID fields are manufacturer-supplied and may be incomplete, generic or absent, so the friendly name and cryptographic fingerprint remain visible.
Audit history
After authentication, the player page shows Authority records for successful and denied authorization requests, enrollments and removals. A signed-in Authority user can also open DDL Activity to review their activity across players. DDL audit activity is retained for two years (730 days). Authority administrators grant the DDL permission to individual user accounts.
Operational rules
- DDL and HDCP are checked during KDM selection and playlist preflight.
- A missing marker uses legacy DDL1 protected-output behaviour.
- DDL2 compares the connected display’s EDID SHA‑256 with the active approved list.
- DDL3 additionally compares authenticated receiver identity and repeater receiver list.
- An identity mismatch or loss of authenticated HDCP blocks protected playback.
Documentation edition: 6 September 2026. Check procedures against the installed release and venue policy.

