Skip to content

Overview

We discuss here how to use commercial DRMs with GPAC. We assume that you are familiar with encrypting ISOBMFF files with GPAC. If not, please read the Encryption first.

GPAC provides a generic framework for protecting data with encryption. As Free Software, GPAC's community is more inclined towards privacy. However we need your inputs to support commercial DRMs too.

DRM config file

Introduction

For historical reasons, commercial DRMs require some custom processing and fields, often centralized in the pssh box or the MPEG-DASH MPD manifest, but not only. GPAC tries an automatic detection or relies on user-based input such as a DRM config file.

PSSH box localisation

With adapting streaming (dasher filter), the pssh box can be set both inband (in the global moov or the fragment moof) or outband (in the manifest). Most DRMs mandate both (dasher:pssh=mv) ; however CMAF and DASH-IOP recommend against duplication in media file when already present in the manifest.

Specifying right management servers

License Acquisition

If you need to specify a License Acquisition server URL ("LAURL"), use the dasher filter laurl parameter.

If all streams share the same LAURL, specify laurl like this:

MP4Box -dash 1000 cypted.mp4 -out dash/manifest.mpd:laurl=https://drm.com/GetLicence

If each source has its own licence URL:

MP4Box -dash 1000 cypted.mp4:#LAUrl=https://ck.gpac.io/GetLicence1 cypted2.mp4:#LAUrl=https://ck.gpac.io/GetLicence2  -out dash/manifest.mpd

Certificate information

If you need to specify a server to get certificate information("CertURL"), use the dasher filter certurl parameter. This is for instance needed with Apple FairPlay.

If all streams share the same URL, specify certurl like this:

MP4Box -dash 1000 cypted.mp4 -out dash/manifest.mpd:cerurl=https://drm.com/cert.cer

If each source has its own licence URL:

MP4Box -dash 1000 cypted.mp4:#CertUrl=https://ck.gpac.io/cert1.cer cypted2.mp4:#CertUrl=https://ck.gpac.io/cert2.cer  -out dash/manifest.mpd

Mapping the DRM-vendor information with

Most vendors will provide you some mapping with GPAC. If they don't, they will likely provide you with standard information such as a PSSH ISOBMFF box. Not that GPAC write the box for you so you need to remove the header from the DRM PSSH manually by removing the first 48 bytes:
- The 8 first bytes which represent the box header.
- The next 32 bytes corresponds to the System Id (=a DRM unique identifier).
- The next 8 bytes encode the size of the following payload.

GPAC XML format supports many binary formats. However one may still need to accomplish manual conversions depending on the data provided by the DRM vendor.

PlayReady DRM

The DRM config file (syntax) for PlayReady looks like (replace the three dots by your DRM vendor information - more on that above):

<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="CENC AES-CTR">

<!-- Playready -->
<DRMInfo type="pssh" version="0">
  <BS ID128="9a04f07998404286ab92e65be0885f95"/> <!-- System ID -->
  <BS data="9802000001..."/>
</DRMInfo>

<CrypTrack trackID="1" IsEncrypted="1" IV_size="16" first_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9"/>
</CrypTrack>

</GPACDRM>

A corresponding PlayReady command-line is:

gpac -i input.mp4 cecrypt:cfile=playready.xml -o output/dash.mpd:pssh=mv:laurl=(playready)https://drm.com/auth?p=my_id

Some examples were contributed to the GPAC's testsuite too.

Widevine DRM

The DRM config file (syntax) for Widevine looks like (replace the three dots by your DRM vendor information - more on that above):

<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="CENC AES-CTR">

<!-- Widevine -->
<DRMInfo type="pssh" version="0">
  <BS ID128="edef8ba979d64acea3c827dcd51d21ed"/> <!-- System ID -->
  <BS data="12100123456789..."/>
</DRMInfo>

<CrypTrack trackID="1" IsEncrypted="1" IV_size="16" first_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9"/>
</CrypTrack>

</GPACDRM>

A corresponding Widevine command-line is:

gpac -i input.mp4 cecrypt:cfile=../widevine.xml -o output/dash.mpd:pssh=mv:laurl=(widevine)https://drm.com/proxy?p=my_id

FairPlay DRM

The DRM config file (syntax) for FairPlay looks like (replace the three dots by your DRM vendor information - more on that above):

<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="cbcs">

<!-- FairPlay -->
<DRMInfo type="pssh" version="0">
  <BS ID128="94CE86FB07FF4F43ADB893D2FA968CA2"/> <!-- System ID -->
</DRMInfo>

<CrypTrack trackID="1" IsEncrypted="1" constant_IV_size="16" constant_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9" hlsInfo='URI="skd://01234567-8901-2345-6789-012345678901:01234567890123456789012345678901",KEYFORMAT="com.apple.streamingkeydelivery",KEYFORMATVERSIONS="1"'/>
</CrypTrack>

</GPACDRM>

A corresponding FairPlay command-line is:

gpac -i input.mp4 cecrypt:cfile=fairplay.xml -o output/dash.mpd:pssh=mv:laurl=(fairplay)https://drm.com/auth?p=my_id&assetID=01234567-8901-2345-6789-012345678901:certurl=https://drm.com/cert.cer

Other DRMs

All DRMs work similarly. In case of doubt, contact us.

Combining multiple DRMs

Combining DRMs consist in stacking options. Make sure the encryption parameters are compatible among DRMs. The DRM config file contains several PSSH box descriptions:

<?xml version="1.0" encoding="UTF-8" />
<GPACDRM type="cbcs">

<!-- Playready -->
<DRMInfo type="pssh" version="0">
  <BS ID128="9a04f07998404286ab92e65be0885f95"/> <!-- System ID -->
  <BS data="9802000001..."/>
</DRMInfo>

<!-- Widevine -->
<DRMInfo type="pssh" version="0">
  <BS ID128="edef8ba979d64acea3c827dcd51d21ed"/> <!-- System ID -->
  <BS data="12100123456789..."/>
</DRMInfo>

<!-- FairPlay -->
<DRMInfo type="pssh" version="0">
  <BS ID128="94CE86FB07FF4F43ADB893D2FA968CA2"/> <!-- System ID -->
</DRMInfo>

<CrypTrack trackID="1" IsEncrypted="1" constant_IV_size="16" constant_IV="0x01234567890123456789012345678901" saiSavedBox="senc">
<key KID="0x01234567890123456789012345678901" value="0x173b1ae9f0bfc8bafa20f98eba0e07d9" hlsInfo='URI="skd://01234567-8901-2345-6789-012345678901:01234567890123456789012345678901",KEYFORMAT="com.apple.streamingkeydelivery",KEYFORMATVERSIONS="1"'/>
</CrypTrack>

</GPACDRM>

A corresponding multi-DRM command-line is:

gpac -i input.mp4 cecrypt:cfile=../widevine.xml -o output/dash.mpd:pssh=mv:laurl=(widevine)https://drm.com/proxy?p=my_id,(widevine)https://drm.com/proxy?p=my_id,(fairplay)https://drm.com/auth?p=my_id&assetID=01234567-8901-2345-6789-012345678901:certurl=https://drm.com/cert.cer

Using CPIX

CPIX is a document format for DRM information exchange. GPAC offers to parse CPIX documents. If the current parsing is too limited for your needs, please contact our open-source or commercial teams.

gpac -i input.mp4 cecrypt:cfile=cpix.xml:laurl=... -o output/dash.mpd:pssh=mv"

Here is a CPIX example:

<?xml version="1.0" encoding="UTF-8"?>
<cpix:CPIX version="2.3" xmlns:cpix="urn:dashif:org:cpix" xmlns:pskc="urn:ietf:params:xml:ns:keyprov:pskc">
  <cpix:ContentKeyList>
    <cpix:ContentKey kid="01234567-8901-2345-6789-012345678901" explicitIV="ASNFZ4kBI0VniQEjRWeJAQ==" commonEncryptionScheme="cenc">
      <cpix:Data><pskc:Secret><pskc:PlainValue>Dw4NDAsKCQgHBgUEAwIBAA==</pskc:PlainValue></pskc:Secret></cpix:Data>
    </cpix:ContentKey>
  </cpix:ContentKeyList>
  <cpix:DRMSystemList>
    <cpix:DRMSystem kid="01234567-8901-2345-6789-012345678901" systemId="edef8ba9-79d6-4ace-a3c8-27dcd51d21ed">
      <cpix:PSSH>AAAAP3Bzc2gAAAAA7e+LqXnWSs6jyCfc1R0h7QAAAB8SEAEjRWeJASNFZ4kBI0VniQEaBWFiY2RlSOPclZsG</cpix:PSSH>
    </cpix:DRMSystem>
    <cpix:DRMSystem kid="01234567-8901-2345-6789-012345678901" systemId="94ce86fb-07ff-4f43-adb8-93d2fa968ca2">
      <cpix:HLSSignalingData playlist="media">I0VYVC1YLUtFWTpNRVRIT0Q9U0FNUExFLUFFUyxVUkk9InNrZDovLzAxMjM0NTY3LTg5MDEtMjM0NS02Nzg5LTAxMjM0NTY3ODkwMTowMTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMSIsS0VZRk9STUFUPSJjb20uYXBwbGUuc3RyZWFtaW5na2V5ZGVsaXZlcnkiLEtFWUZPUk1BVFZFUlNJT05TPSIxIg==</cpix:HLSSignalingData>
    </cpix:DRMSystem>
  </cpix:DRMSystemList>
  <cpix:ContentKeyUsageRuleList>
    <cpix:ContentKeyUsageRule kid="01234567-8901-2345-6789-012345678901"/>
  </cpix:ContentKeyUsageRuleList>
</cpix:CPIX>

Was this page helpful?