Overview¶
We discuss here how to use commercial DRMs with GPAC. We assume that you are familiar with encrypting ISOBMFF files with GPAC. If not, please read the Encryption first.
GPAC provides a generic framework for protecting data with encryption. As Free Software, GPAC's community is more inclined towards privacy. However we need your inputs to support commercial DRMs too.
DRM config file¶
Introduction¶
For historical reasons, commercial DRMs require some custom processing and fields, often centralized in the pssh box or the MPEG-DASH MPD manifest, but not only. GPAC tries an automatic detection or relies on user-based input such as a DRM config file.
PSSH box localisation¶
With adapting streaming (dasher filter), the pssh box can be set both inband (in the global moov or the fragment moof) or outband (in the manifest). Most DRMs mandate both (dasher:pssh=mv) ; however CMAF and DASH-IOP recommend against duplication in media file when already present in the manifest.
Specifying right management servers¶
License Acquisition¶
If you need to specify a License Acquisition server URL ("LAURL"), use the dasher filter laurl parameter.
If all streams share the same LAURL, specify laurl like this:
If each source has its own licence URL:
MP4Box -dash 1000 cypted.mp4:#LAUrl=https://ck.gpac.io/GetLicence1 cypted2.mp4:#LAUrl=https://ck.gpac.io/GetLicence2 -out dash/manifest.mpd
Certificate information¶
If you need to specify a server to get certificate information("CertURL"), use the dasher filter certurl parameter. This is for instance needed with Apple FairPlay.
If all streams share the same URL, specify certurl like this:
If each source has its own licence URL:
MP4Box -dash 1000 cypted.mp4:#CertUrl=https://ck.gpac.io/cert1.cer cypted2.mp4:#CertUrl=https://ck.gpac.io/cert2.cer -out dash/manifest.mpd
Mapping the DRM-vendor information with¶
Most vendors will provide you some mapping with GPAC. If they don't, they will likely provide you with standard information such as a PSSH ISOBMFF box. Not that GPAC write the box for you so you need to remove the header from the DRM PSSH manually by removing the first 48 bytes:
- The 8 first bytes which represent the box header.
- The next 32 bytes corresponds to the System Id (=a DRM unique identifier).
- The next 8 bytes encode the size of the following payload.
GPAC XML format supports many binary formats. However one may still need to accomplish manual conversions depending on the data provided by the DRM vendor.
PlayReady DRM¶
The DRM config file (syntax) for PlayReady looks like (replace the three dots by your DRM vendor information - more on that above):
<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="CENC AES-CTR">
<!-- Playready -->
<DRMInfo type="pssh" version="0">
<BS ID128="9a04f07998404286ab92e65be0885f95"/> <!-- System ID -->
<BS data="9802000001..."/>
</DRMInfo>
<CrypTrack trackID="1" IsEncrypted="1" IV_size="16" first_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9"/>
</CrypTrack>
</GPACDRM>
A corresponding PlayReady command-line is:
gpac -i input.mp4 cecrypt:cfile=playready.xml -o output/dash.mpd:pssh=mv:laurl=(playready)https://drm.com/auth?p=my_id
Some examples were contributed to the GPAC's testsuite too.
Widevine DRM¶
The DRM config file (syntax) for Widevine looks like (replace the three dots by your DRM vendor information - more on that above):
<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="CENC AES-CTR">
<!-- Widevine -->
<DRMInfo type="pssh" version="0">
<BS ID128="edef8ba979d64acea3c827dcd51d21ed"/> <!-- System ID -->
<BS data="12100123456789..."/>
</DRMInfo>
<CrypTrack trackID="1" IsEncrypted="1" IV_size="16" first_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9"/>
</CrypTrack>
</GPACDRM>
A corresponding Widevine command-line is:
gpac -i input.mp4 cecrypt:cfile=../widevine.xml -o output/dash.mpd:pssh=mv:laurl=(widevine)https://drm.com/proxy?p=my_id
FairPlay DRM¶
The DRM config file (syntax) for FairPlay looks like (replace the three dots by your DRM vendor information - more on that above):
<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="cbcs">
<!-- FairPlay -->
<DRMInfo type="pssh" version="0">
<BS ID128="94CE86FB07FF4F43ADB893D2FA968CA2"/> <!-- System ID -->
</DRMInfo>
<CrypTrack trackID="1" IsEncrypted="1" constant_IV_size="16" constant_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9" hlsInfo='URI="skd://01234567-8901-2345-6789-012345678901:01234567890123456789012345678901",KEYFORMAT="com.apple.streamingkeydelivery",KEYFORMATVERSIONS="1"'/>
</CrypTrack>
</GPACDRM>
A corresponding FairPlay command-line is:
gpac -i input.mp4 cecrypt:cfile=fairplay.xml -o output/dash.mpd:pssh=mv:laurl=(fairplay)https://drm.com/auth?p=my_id&assetID=01234567-8901-2345-6789-012345678901:certurl=https://drm.com/cert.cer
Other DRMs¶
All DRMs work similarly. In case of doubt, contact us.
Combining multiple DRMs¶
Combining DRMs consist in stacking options. Make sure the encryption parameters are compatible among DRMs. The DRM config file contains several PSSH box descriptions:
<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="cbcs">
<!-- Playready -->
<DRMInfo type="pssh" version="0">
<BS ID128="9a04f07998404286ab92e65be0885f95"/> <!-- System ID -->
<BS data="9802000001..."/>
</DRMInfo>
<!-- Widevine -->
<DRMInfo type="pssh" version="0">
<BS ID128="edef8ba979d64acea3c827dcd51d21ed"/> <!-- System ID -->
<BS data="12100123456789..."/>
</DRMInfo>
<!-- FairPlay -->
<DRMInfo type="pssh" version="0">
<BS ID128="94CE86FB07FF4F43ADB893D2FA968CA2"/> <!-- System ID -->
</DRMInfo>
<CrypTrack trackID="1" IsEncrypted="1" constant_IV_size="16" constant_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9" hlsInfo='URI="skd://01234567-8901-2345-6789-012345678901:01234567890123456789012345678901",KEYFORMAT="com.apple.streamingkeydelivery",KEYFORMATVERSIONS="1"'/>
</CrypTrack>
</GPACDRM>
A corresponding multi-DRM command-line is:
gpac -i input.mp4 cecrypt:cfile=../widevine.xml -o output/dash.mpd:pssh=mv:laurl=(widevine)https://drm.com/proxy?p=my_id,(widevine)https://drm.com/proxy?p=my_id,(fairplay)https://drm.com/auth?p=my_id&assetID=01234567-8901-2345-6789-012345678901:certurl=https://drm.com/cert.cer
Using CPIX¶
CPIX is a document format for DRM information exchange. GPAC offers to parse CPIX documents. If the current parsing is too limited for your needs, please contact our open-source or commercial teams.
Here is a CPIX example:
<?xml version="1.0" encoding="UTF-8"?>
<cpix:CPIX version="2.3" xmlns:cpix="urn:dashif:org:cpix" xmlns:pskc="urn:ietf:params:xml:ns:keyprov:pskc">
<cpix:ContentKeyList>
<cpix:ContentKey kid="01234567-8901-2345-6789-012345678901" explicitIV="ASNFZ4kBI0VniQEjRWeJAQ==" commonEncryptionScheme="cenc">
<cpix:Data><pskc:Secret><pskc:PlainValue>Dw4NDAsKCQgHBgUEAwIBAA==</pskc:PlainValue></pskc:Secret></cpix:Data>
</cpix:ContentKey>
</cpix:ContentKeyList>
<cpix:DRMSystemList>
<cpix:DRMSystem kid="01234567-8901-2345-6789-012345678901" systemId="edef8ba9-79d6-4ace-a3c8-27dcd51d21ed">
<cpix:PSSH>AAAAP3Bzc2gAAAAA7e+LqXnWSs6jyCfc1R0h7QAAAB8SEAEjRWeJASNFZ4kBI0VniQEaBWFiY2RlSOPclZsG</cpix:PSSH>
</cpix:DRMSystem>
<cpix:DRMSystem kid="01234567-8901-2345-6789-012345678901" systemId="94ce86fb-07ff-4f43-adb8-93d2fa968ca2">
<cpix:HLSSignalingData playlist="media">I0VYVC1YLUtFWTpNRVRIT0Q9U0FNUExFLUFFUyxVUkk9InNrZDovLzAxMjM0NTY3LTg5MDEtMjM0NS02Nzg5LTAxMjM0NTY3ODkwMTowMTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMSIsS0VZRk9STUFUPSJjb20uYXBwbGUuc3RyZWFtaW5na2V5ZGVsaXZlcnkiLEtFWUZPUk1BVFZFUlNJT05TPSIxIg==</cpix:HLSSignalingData>
</cpix:DRMSystem>
</cpix:DRMSystemList>
<cpix:ContentKeyUsageRuleList>
<cpix:ContentKeyUsageRule kid="01234567-8901-2345-6789-012345678901"/>
</cpix:ContentKeyUsageRuleList>
</cpix:CPIX>