The creator of a DICOM SOP Instance may generate signatures using the Creator RSA Digital Signature Profile. The Digital Signature produced by this Profile serves as a lifetime data integrity check that can be used to verify that the pixel data in the SOP instance has not been altered since its initial creation. An implementation that supports the Creator RSA Digital Signature Profile may include a Creator RSA Digital Signature with every SOP Instance that it creates; however, the implementation is not required to do so.
As a minimum, an implementation shall include the following attributes in generating the Creator RSA Digital Signature:
the SOP Class and Instance UIDs
the SOP Creation Date and Time, if present
the Study and Series Instance UIDs
any attributes of the General Equipment module that are present
any attributes of the Overlay Plane, Curve or Graphic Annotation modules that are present
any attributes of the General Image and Image Pixel modules that are present
any attributes of the SR Document General and SR Document Content modules that are present
any attributes of the Waveform and Waveform Annotation modules that are present
any attributes of the Multi-frame Functional Groups module that are present
any attributes of the Enhanced MR Image module that are present
any attributes of the MR Spectroscopy modules that are present
any attributes of the Raw Data module that are present
any attributes of the Enhanced CT Image module that are present
any attributes of the Enhanced XA/XRF Image module that are present
any attributes of the Segmentation Image module that are present
any attributes of the Encapsulated Document module that are present
any attributes of the X-Ray 3D Image module that are present
any attributes of the Enhanced PET Image module that are present
any attributes of the Enhanced US Image module that are present
any attributes of the Surface Segmentation module that are present
any attributes of the Surface Mesh Module that are present
any attributes of the Structured Display, Structured Display Annotation, and Structured Display Image Box modules that are present
any Attributes of the Implant Template module that are present
any Attributes of the Implant Assembly Template module that are present
any Attributes of the Implant Template Group module that are present
any attributes of the Point Cloud Module that are present
The Digital Signature shall be created using the methodology described in the Base RSA Digital Signature Profile. Typically the certificate and associated private key used to produce Creator RSA Digital Signatures are configuration parameters of the Application Entity set by service or installation engineers.
Creator RSA Digital Signatures bear no direct relationship to other Digital Signatures. However, other Digital Signatures, such as the Authorization Digital Signature, may be used to collaborate the timestamp of a Creator RSA Digital Signature.