A DAP block is like a signature across a whole .cap file load. For this purpose you need a supplementary security domain populated with a DAP key (assymetric, RSA public key).
The application provider acquires from a controlling authority a set of keys, provides the public key to the personalizer (for the SSD) and signs the applications with the private key. Now each time an application has to be loaded, the personalizer can verify the integrity (comparing the result with a HASH block) and authenticity.