---
title: "Advanced Encryption Techniques: Content Protection Tags for MPDs and PSSH Boxes for DASH."
description: In this installment of TheDRMBlog we take an in-depth look at Advanced Encryption Techniques.
image: https://go.buydrm.com/hubfs/BuyDRM_AdvancedEncryptionTechniques_1200x628_V1.png
---

[![BuyDRM\_logo\_primary-1](https://go.buydrm.com/hs-fs/hubfs/BuyDRM_logo_primary-1.png?width=180&name=BuyDRM_logo_primary-1.png "BuyDRM_logo_primary-1")](http://www.buydrm.com)

[![](https://go.buydrm.com/hubfs/images/basic/buttons/btn_drmblog_rss.png)](https://go.buydrm.com/thedrmblog/rss.xml)

[![](https://go.buydrm.com/hubfs/images/basic/buttons/btn_drmblog.png?t=1480019361394)](https://go.buydrm.com/thedrmblog)

- ![BuyDRM\_AdvancedEncryptionTechniques\_1920x450-1](https://go.buydrm.com/hubfs/BuyDRM_AdvancedEncryptionTechniques_1920x450-1.png "BuyDRM_AdvancedEncryptionTechniques_1920x450-1")

- ![763x430\_BuyDRM\_EPIX](https://go.buydrm.com/hubfs/763x430_BuyDRM_EPIX.jpg "763x430_BuyDRM_EPIX")

- ![BuyDRM\_AdvancedEncryptionTechniques\_372x300](https://go.buydrm.com/hubfs/BuyDRM_AdvancedEncryptionTechniques_372x300.png "BuyDRM_AdvancedEncryptionTechniques_372x300")

# Advanced Encryption Techniques: Content Protection Tags for MPDs and PSSH Boxes for DASH.

Posted by [Roman K.](https://go.buydrm.com/thedrmblog/author/roman-k) on Oct 25, 2017, 1:52:40 PM

- [Tweet](https://twitter.com/share)

Here, at BuyDRM we support a wide array of encoding partners and solutions in the industry with our KeyOS Encyption Key API. This allows end users to choose from a myriad of choices based on their needs and financial possibilities. However, the existence of many different encoding/packaging partners also means that we needed to find a way to work with them in a conistent manner and provide a way for them to request all the required information to apply DRM protection in their products fast and easy.

As a result, we provide the KeyOS Encryption Key API that is responsible for generating encryption keys, headers, and PSSH box data for our encoding partners to use in their products.

We would like to provide some tips to those who are just getting into content encoding, who have already read numerous specs (ISO/IEC 23001-7, ISO/IEC 23009-1, PANTOS, and many others) and are ready to dive into encoding with encryption.

We will concentrate on MPEG-DASH in this article and will describe how to build ContentProtection tags that go into DASH Media Presentation Description file (MPD) and PSSH boxes that go into media content. This, of course, doesn’t cover the complete encryption process, but the intent of this post wasn’t to teach you how to write packaging software. We wrote this post because more and more customers are asking about how to create PROs and PSSHs to use in different scenarios and we thought that not only our customers, but also others may find answers on these questions useful.

## Getting data required from the KeyOS Encryption Key API

MPEG-DASH is a very popular format because it allows you to cover a wide array of platforms thanks to its CENC support. The CENC spec defines encryption and key mapping mechanisms that may be utilized by one or more DRM systems to allow the decryption of the same file using different DRM systems which makes it possible to playback MPEG-DASH assets on devices that support PlayReady DRM or Widevine DRM [\[CENC\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#CENC).

Of course, it is not a panacea, and we look forward to seeing how CMAF will prove itself; however, currently we have MPEG-DASH and in order to make it work with different DRMs, you need to correctly apply DRM signaling into the manifest and initialization chunks.

Let’s assume you already made a request to the API and got your response. Aside from the content key that you get and should use to encrypt your content, you will also need PlayReady header and the Widevine PSSH box data. Both are returned by the API, but, you can’t use them out of the box in your MPD or PSSH boxes.

## Building ContentProtection tags and PSSH boxes for PlayReady

First, let’s deal with adding PlayReady DRM support into the MPEG-DASH asset. DASH defines two types of ContentProtection Descriptor elements for ISO Media.

1. With @schemeIdUri=”urn:mpeg:dash:mp4protection:2011” @value=”\<scheme\>”
2. With @schemeIdUri=”urn:uuid:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx” @value=”DRMNAME version”

The first descriptor type indicates the four character code of the encryption scheme that is contained in the Protection Scheme Information Box (‘schi’) in each encrypted ISO Media track. This descriptor is inside the manifest to tell the client that the content is encrypted.

The second descriptor type indicates the UUID string for a particular DRM system that can provide a license and decryption key for the associated Adaptation Set [\[DASH-CENC\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#DASH). In other words you define what DRMs are supported with encrypted asset.

The first descriptor will look like this:

`<ContentProtection schemeIdUri="urn:mpeg:dash:mp4protection:2011" value="cenc" cenc:default_KID="4CD90DCF-5592-4573-8990-9C6A4D7199B2" />`

Where the “*default\_KID”* field’s value will come from the KeyOS Encryption Key API response KeyID field. The field will be presented in GUID format for your convenience.

The second descriptor type is just what we need to tell the client that we will support PlayReady, Widevine, or other DRMs. We will focus on PlayReady and Widevine for now. For PlayReady, based on the MPEG DASH PlayReady 1.2 specification [\[DASH-CENC\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#DASH), the descriptor will look as follows:

```
<ContentProtection xmlns:mspr="urn:microsoft:playready" schemeIdUri="urn:uuid:9A04F079-9840-4286-AB92-E65BE0885F95" value="Microsoft PlayReady">
    <mspr:pro> <!-- base64-encoded PlayReady Header Object --> </mspr:pro>
    <cenc:pssh> <!-- base64-encoded PlayReady 'pssh' complete box --> </cenc:pssh>
</ContentProtection>
    
```

The “*mspr:pro”* element is defined by Microsoft PlayReady, and includes only the PlayReady Header Object (PRO) [\[PRHEADER\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#PRHEADER) information, not the box structure included in *“pssh”* and *“cenc:pssh”*. Including both *“mspr:pro”* and *“cenc:pssh”* will enable old players including a player based on Silverlight, and new players including web pages using script to play protected DASH presentations on HTML5 browsers.

### Building a PRO

To build something you need to understand what buildings blocks it consists of. In our case, those building blocks are bytes. Here is how PRO looks like:

- 4 bytes – holds the size of the PlayReady header object in bytes. The length of a PlayReady header object should not exceed 15 kilobytes (KB).
- 2 bytes – specifies the number of PlayReady records in the PlayReady object.
- byte array – contains a variable number of records that contain information related to licenses and license acquisition. 
    - 2 bytes – specifies the type of data stored in the record value field.
    - 2 bytes – specifies the size in bytes of the record value field.
    - byte array – the content of the object depends on the value of record type.

Besides that, the PRO specification requires the PRO to be in UTF-16 LE format.

Now, when you understand how PRO looks like in theory, let us construct one based on the information acquired from the KeyOS Encryption Key API. Let us presume you have this PlayReady header from the API:

`<WRMHEADER xmlns="http://schemas.microsoft.com/DRM/2007/03/PlayReadyHeader" version="4.0.0.0"><DATA><PROTECTINFO><KEYLEN>16></KEYLEN><ALGID>AESCTR</ALGID></PROTECTINFO><KID>+rbqVgPoa0iAkLlEKCQUcA==</KID><LA_URL>http://sldrm.licensekeyserver.com/core/rightsmanager.asmx</LA_URL><DS_ID>VlR7IdsIJEuRd06Laqs2jw==</DS_ID><CUSTOMATTRIBUTES xmlns=""><CID>E363j+wos0O4KG5BXDt95A==</CID><DRMTYPE>smooth</DRMTYPE></CUSTOMATTRIBUTES><CHECKSUM>RV1yHHiLPak=</CHECKSUM></DATA></WRMHEADER>`

Now imagine a binary array in which we will be putting our data. However, we will not be appending it, we will be PRE-pending it – we will go from the bottom up so to say, from finish to start. This makes it easier to calculate size of the data added into our imaginary array.

Let us start. First, you put your PlayReady Header there in UTF-16 LE format.

```
    
3C 00 57 00 52 00 4D 00 48 00 45 00 41 00 44 00 45 00 52 00 20 00 78 00 6D 00 6C 00 6E 00 73 00 3D 00 22 
00 68 00 74 00 74 00 70 00 3A 00 2F 00 2F 00 73 00 63 00 68 00 65 00 6D 00 61 00 73 00 2E 00 6D 00 69 00 
63 00 72 00 6F 00 73 00 6F 00 66 00 74 00 2E 00 63 00 6F 00 6D 00 2F 00 44 00 52 00 4D 00 2F 00 32 00 30
00 30 00 37 00 2F 00 30 00 33 00 2F 00 50 00 6C 00 61 00 79 00 52 00 65 00 61 00 64 00 79 00 48 00 65 00
61 00 64 00 65 00 72 00 22 00 20 00 76 00 65 00 72 00 73 00 69 00 6F 00 6E 00 3D 00 22 00 34 00 2E 00 30
00 2E 00 30 00 2E 00 30 00 22 00 3E 00 3C 00 44 00 41 00 54 00 41 00 3E 00 3C 00 50 00 52 00 4F 00 54 00 
45 00 43 00 54 00 49 00 4E 00 46 00 4F 00 3E 00 3C 00 4B 00 45 00 59 00 4C 00 45 00 4E 00 3E 00 31 00 36 
00 0D 00 0A 00 3C 00 2F 00 4B 00 45 00 59 00 4C 00 45 00 4E 00 3E 00 3C 00 41 00 4C 00 47 00 49 00 44 00 
3E 00 41 00 45 00 53 00 43 00 54 00 52 00 3C 00 2F 00 41 00 4C 00 47 00 49 00 44 00 3E 00 3C 00 2F 00 50 
00 52 00 4F 00 54 00 45 00 43 00 54 00 49 00 4E 00 46 00 4F 00 3E 00 3C 00 4B 00 49 00 44 00 3E 00 2B 00
72 00 62 00 71 00 56 00 67 00 50 00 6F 00 61 00 30 00 69 00 41 00 6B 00 4C 00 6C 00 45 00 4B 00 43 00 51
00 55 00 63 00 41 00 3D 00 3D 00 3C 00 2F 00 4B 00 49 00 44 00 3E 00 3C 00 4C 00 41 00 5F 00 55 00 52 00
4C 00 3E 00 68 00 74 00 74 00 70 00 3A 00 2F 00 2F 00 73 00 6C 00 64 00 72 00 6D 00 2E 00 6C 00 69 00 63 
00 65 00 6E 00 73 00 65 00 6B 00 65 00 79 00 73 00 65 00 72 00 76 00 65 00 72 00 2E 00 63 00 6F 00 6D 00 
2F 00 63 00 6F 00 72 00 65 00 2F 00 72 00 69 00 67 00 68 00 74 00 73 00 6D 00 61 00 6E 00 61 00 67 00 65 
00 72 00 2E 00 61 00 73 00 6D 00 78 00 0D 00 0A 00 3C 00 2F 00 4C 00 41 00 5F 00 55 00 52 00 4C 00 3E 00 
3C 00 44 00 53 00 5F 00 49 00 44 00 3E 00 56 00 6C 00 52 00 37 00 49 00 64 00 73 00 49 00 4A 00 45 00 75 
00 52 00 64 00 30 00 36 00 4C 00 61 00 71 00 73 00 32 00 6A 00 77 00 3D 00 3D 00 3C 00 2F 00 44 00 53 00 
5F 00 49 00 44 00 3E 00 3C 00 43 00 55 00 53 00 54 00 4F 00 4D 00 41 00 54 00 54 00 52 00 49 00 42 00 55 
00 54 00 45 00 53 00 20 00 78 00 6D 00 6C 00 6E 00 73 00 3D 00 22 00 22 00 3E 00 3C 00 43 00 49 00 44 00 
3E 00 45 00 33 00 36 00 33 00 6A 00 2B 00 77 00 6F 00 73 00 30 00 4F 00 34 00 4B 00 47 00 35 00 42 00 58 
00 44 00 74 00 39 00 35 00 41 00 3D 00 3D 00 3C 00 2F 00 43 00 49 00 44 00 3E 00 3C 00 44 00 52 00 4D 00 
54 00 59 00 50 00 45 00 3E 00 73 00 6D 00 6F 00 6F 00 74 00 68 00 3C 00 2F 00 44 00 52 00 4D 00 54 00 59 
00 50 00 45 00 3E 00 3C 00 2F 00 43 00 55 00 53 00 54 00 4F 00 4D 00 41 00 0D 00 0A 00 54 00 54 00 52 00 
49 00 42 00 55 00 54 00 45 00 53 00 3E 00 3C 00 43 00 48 00 45 00 43 00 4B 00 53 00 55 00 4D 00 3E 00 52
00 56 00 31 00 79 00 48 00 48 00 69 00 4C 00 50 00 61 00 6B 00 3D 00 3C 00 2F 00 43 00 48 00 45 00 43 00 
4B 00 53 00 55 00 4D 00 3E 00 3C 00 2F 00 44 00 41 00 54 00 41 00 3E 00 3C 00 2F 00 57 00 52 00 4D 00 48 
00 45 00 41 00 44 00 45 00 52 00 3E 00
```

You then prepend the array with 2 bytes that define the size of the PlayReady Header. Remember, that we still write in Little Endian notation and we will continue for the whole PRO:

`BE 03`

Next go two bytes that represent the type of the box:

`01 00`

which stands for the record that contains a rights management header. You now have the PlayReady record ready, but the PRO is not finished yet. We continue adding to our array. Add two more bytes for the number of PlayReady records that we have:

`01 00`

And we finish with 4 bytes – the complete PRO size:

`C8 03 00 00`

Here is the resulting PRO:

```
C8 03 00 00 01 00 01 00 BE 03 3C 00 57 00 52 00 4D 00 48 0045 00 41 00 44 00 45 00 52 00 20 00 78 00 6D 00 6C 00 6E 0073 00 3D 00 22 00 68 00 74 00 74 00 70 00 3A 00 2F 00 2F 0073 00 63 00 68 00 65 00 6D 00 61 00 73 00 2E 00 6D 00 69 0063 00 72 00 6F 00 73 00 6F 00 66 00 74 00 2E 00 63 00 6F 006D 00 2F 00 44 00 52 00 4D 00 2F 00 32 00 30 00 30 00 37 002F 00 30 00 33 00 2F 00 50 00 6C 00 61 00 79 00 52 00 65 0061 00 64 00 79 00 48 00 65 00 61 00 64 00 65 00 72 00 22 0020 00 76 00 65 00 72 00 73 00 69 00 6F 00 6E 00 3D 00 22 0034 00 2E 00 30 00 2E 00 30 00 2E 00 30 00 22 00 3E 00 3C 0044 00 41 00 54 00 41 00 3E 00 3C 00 50 00 52 00 4F 00 54 0045 00 43 00 54 00 49 00 4E 00 46 00 4F 00 3E 00 3C 00 4B 0045 00 59 00 4C 00 45 00 4E 00 3E 00 31 00 36 00 0D 00 0A 003C 00 2F 00 4B 00 45 00 59 00 4C 00 45 00 4E 00 3E 00 3C 0041 00 4C 00 47 00 49 00 44 00 3E 00 41 00 45 00 53 00 43 0054 00 52 00 3C 00 2F 00 41 00 4C 00 47 00 49 00 44 00 3E 003C 00 2F 00 50 00 52 00 4F 00 54 00 45 00 43 00 54 00 49 004E 00 46 00 4F 00 3E 00 3C 00 4B 00 49 00 44 00 3E 00 2B 0072 00 62 00 71 00 56 00 67 00 50 00 6F 00 61 00 30 00 69 0041 00 6B 00 4C 00 6C 00 45 00 4B 00 43 00 51 00 55 00 63 0041 00 3D 00 3D 00 3C 00 2F 00 4B 00 49 00 44 00 3E 00 3C 004C 00 41 00 5F 00 55 00 52 00 4C 00 3E 00 68 00 74 00 74 0070 00 3A 00 2F 00 2F 00 73 00 6C 00 64 00 72 00 6D 00 2E 006C 00 69 00 63 00 65 00 6E 00 73 00 65 00 6B 00 65 00 79 0073 00 65 00 72 00 76 00 65 00 72 00 2E 00 63 00 6F 00 6D 002F 00 63 00 6F 00 72 00 65 00 2F 00 72 00 69 00 67 00 68 0074 00 73 00 6D 00 61 00 6E 00 61 00 67 00 65 00 72 00 2E 0061 00 73 00 6D 00 78 00 0D 00 0A 00 3C 00 2F 00 4C 00 41 005F 00 55 00 52 00 4C 00 3E 00 3C 00 44 00 53 00 5F 00 49 0044 00 3E 00 56 00 6C 00 52 00 37 00 49 00 64 00 73 00 49 004A 00 45 00 75 00 52 00 64 00 30 00 36 00 4C 00 61 00 71 0073 00 32 00 6A 00 77 00 3D 00 3D 00 3C 00 2F 00 44 00 53 005F 00 49 00 44 00 3E 00 3C 00 43 00 55 00 53 00 54 00 4F 004D 00 41 00 54 00 54 00 52 00 49 00 42 00 55 00 54 00 45 0053 00 20 00 78 00 6D 00 6C 00 6E 00 73 00 3D 00 22 00 22 003E 00 3C 00 43 00 49 00 44 00 3E 00 45 00 33 00 36 00 33 006A 00 2B 00 77 00 6F 00 73 00 30 00 4F 00 34 00 4B 00 47 0035 00 42 00 58 00 44 00 74 00 39 00 35 00 41 00 3D 00 3D 003C 00 2F 00 43 00 49 00 44 00 3E 00 3C 00 44 00 52 00 4D 0054 00 59 00 50 00 45 00 3E 00 73 00 6D 00 6F 00 6F 00 74 0068 00 3C 00 2F 00 44 00 52 00 4D 00 54 00 59 00 50 00 45 003E 00 3C 00 2F 00 43 00 55 00 53 00 54 00 4F 00 4D 00 41 000D 00 0A 00 54 00 54 00 52 00 49 00 42 00 55 00 54 00 45 0053 00 3E 00 3C 00 43 00 48 00 45 00 43 00 4B 00 53 00 55 004D 00 3E 00 52 00 56 00 31 00 79 00 48 00 48 00 69 00 4C 0050 00 61 00 6B 00 3D 00 3C 00 2F 00 43 00 48 00 45 00 43 004B 00 53 00 55 00 4D 00 3E 00 3C 00 2F 00 44 00 41 00 54 0041 00 3E 00 3C 00 2F 00 57 00 52 00 4D 00 48 00 45 00 41 0044 00 45 00 52 00 3E 00
```

Yellow bytes specify the size of the PRO header. Two bytes (green) define number of PlayReady records. Two more bytes (blue) define the type of the PlayReady record and based on the specification the *00 01* means that the record contains the record with rights management header inside. Last two bytes (grey) specify the size of the rights management header, which follows in UTF-16 LE. Here is how it looks like in HEX editor:

![pr\_header\_obj.png](https://go.buydrm.com/hs-fs/hubfs/Docs%20And%20Guides/2017/102517_advanced_encryption_tech/pr_header_obj.png?width=851&height=672&name=pr_header_obj.png)

Figure 1. PlayReady Header Object

 

### Building a Complete PSSH Box.

The PRO is done. We now need to create the PSSH box so our Common Encryption scenario would work and client would know that the asset could play back the asset after getting the PlayReady license. For this, according to the [\[CENC\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#CENC) specification we need to create the “*\<cenc:pssh\>”* tag inside the MPEG-DASH manifest. We already have the PRO, all is left is to wrap it into complete PSSH box, which has the following structure if we will look on it under the microscope, which is our hex editor:

- 4 bytes – the size of the PSSH box
- 4 bytes – the constant “PSSH”
- 4 bytes – flags based on the [\[ISOBMFF\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#ISOBMFF) specification
- 16 bytes – unique key system identifier
- 4 bytes – size of the data inside the PSSH box
- byte array – data itself

Considering we already have the PRO, we just keep prepending (move from bottom to the top in the structure list mentioned above) into the byte array to get our PSSH box. First, add 4 bytes to define the size of the data inside the PSSH box. This is the size of the entire PRO. Please, note that that now we do not use Little Endian notation:

`00 00 03 C8`

Then 16 bytes that uniquely identify the PlayReady Key System [\[SYSTEM-IDS\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#SYSTEM). This value may be considered a constant:

`9A 04 F0 79 98 40 42 86 AB 92 E6 5B E0 88 5F 95`

The value of the flags map and the version for this box is zero, so, add 4 empty bytes:

`00 00 00 00`

And 4 more with another constant – “PSSH”, which looks like this in HEX:

`70 73 73 68`

We finish with adding 4 bytes that define the size of the complete PSSH box:

`00 00 03 E8`

The complete PSSH box looks like this.

```
00 00 03 E8 70 73 73 68 00 00 00 00 9A 04 F0 79 98 40 42 86AB 92 E6 5B E0 88 5F 95 00 00 03 C8 C8 03 00 00 01 00 01 00BE 03 3C 00 57 00 52 00 4D 00 48 00 45 00 41 00 44 00 45 0052 00 20 00 78 00 6D 00 6C 00 6E 00 73 00 3D 00 22 00 68 0074 00 74 00 70 00 3A 00 2F 00 2F 00 73 00 63 00 68 00 65 006D 00 61 00 73 00 2E 00 6D 00 69 00 63 00 72 00 6F 00 73 006F 00 66 00 74 00 2E 00 63 00 6F 00 6D 00 2F 00 44 00 52 004D 00 2F 00 32 00 30 00 30 00 37 00 2F 00 30 00 33 00 2F 0050 00 6C 00 61 00 79 00 52 00 65 00 61 00 64 00 79 00 48 0065 00 61 00 64 00 65 00 72 00 22 00 20 00 76 00 65 00 72 0073 00 69 00 6F 00 6E 00 3D 00 22 00 34 00 2E 00 30 00 2E 0030 00 2E 00 30 00 22 00 3E 00 3C 00 44 00 41 00 54 00 41 003E 00 3C 00 50 00 52 00 4F 00 54 00 45 00 43 00 54 00 49 004E 00 46 00 4F 00 3E 00 3C 00 4B 00 45 00 59 00 4C 00 45 004E 00 3E 00 31 00 36 00 0D 00 0A 00 3C 00 2F 00 4B 00 45 0059 00 4C 00 45 00 4E 00 3E 00 3C 00 41 00 4C 00 47 00 49 0044 00 3E 00 41 00 45 00 53 00 43 00 54 00 52 00 3C 00 2F 0041 00 4C 00 47 00 49 00 44 00 3E 00 3C 00 2F 00 50 00 52 004F 00 54 00 45 00 43 00 54 00 49 00 4E 00 46 00 4F 00 3E 003C 00 4B 00 49 00 44 00 3E 00 2B 00 72 00 62 00 71 00 56 0067 00 50 00 6F 00 61 00 30 00 69 00 41 00 6B 00 4C 00 6C 0045 00 4B 00 43 00 51 00 55 00 63 00 41 00 3D 00 3D 00 3C 002F 00 4B 00 49 00 44 00 3E 00 3C 00 4C 00 41 00 5F 00 55 0052 00 4C 00 3E 00 68 00 74 00 74 00 70 00 3A 00 2F 00 2F 0073 00 6C 00 64 00 72 00 6D 00 2E 00 6C 00 69 00 63 00 65 006E 00 73 00 65 00 6B 00 65 00 79 00 73 00 65 00 72 00 76 0065 00 72 00 2E 00 63 00 6F 00 6D 00 2F 00 63 00 6F 00 72 0065 00 2F 00 72 00 69 00 67 00 68 00 74 00 73 00 6D 00 61 006E 00 61 00 67 00 65 00 72 00 2E 00 61 00 73 00 6D 00 78 000D 00 0A 00 3C 00 2F 00 4C 00 41 00 5F 00 55 00 52 00 4C 003E 00 3C 00 44 00 53 00 5F 00 49 00 44 00 3E 00 56 00 6C 0052 00 37 00 49 00 64 00 73 00 49 00 4A 00 45 00 75 00 52 0064 00 30 00 36 00 4C 00 61 00 71 00 73 00 32 00 6A 00 77 003D 00 3D 00 3C 00 2F 00 44 00 53 00 5F 00 49 00 44 00 3E 003C 00 43 00 55 00 53 00 54 00 4F 00 4D 00 41 00 54 00 54 0052 00 49 00 42 00 55 00 54 00 45 00 53 00 20 00 78 00 6D 006C 00 6E 00 73 00 3D 00 22 00 22 00 3E 00 3C 00 43 00 49 0044 00 3E 00 45 00 33 00 36 00 33 00 6A 00 2B 00 77 00 6F 0073 00 30 00 4F 00 34 00 4B 00 47 00 35 00 42 00 58 00 44 0074 00 39 00 35 00 41 00 3D 00 3D 00 3C 00 2F 00 43 00 49 0044 00 3E 00 3C 00 44 00 52 00 4D 00 54 00 59 00 50 00 45 003E 00 73 00 6D 00 6F 00 6F 00 74 00 68 00 3C 00 2F 00 44 0052 00 4D 00 54 00 59 00 50 00 45 00 3E 00 3C 00 2F 00 43 0055 00 53 00 54 00 4F 00 4D 00 41 00 0D 00 0A 00 54 00 54 0052 00 49 00 42 00 55 00 54 00 45 00 53 00 3E 00 3C 00 43 0048 00 45 00 43 00 4B 00 53 00 55 00 4D 00 3E 00 52 00 56 0031 00 79 00 48 00 48 00 69 00 4C 00 50 00 61 00 6B 00 3D 003C 00 2F 00 43 00 48 00 45 00 43 00 4B 00 53 00 55 00 4D 003E 00 3C 00 2F 00 44 00 41 00 54 00 41 00 3E 00 3C 00 2F 0057 00 52 00 4D 00 48 00 45 00 41 00 44 00 45 00 52 00 3E 00
```

First 4 bytes (yellow) specify the box of the complete PSSH box. Next 4 bytes define the type of the box which is PSSH in our case. 4 zero bytes (blue). 16 bytes (pink) that define the unique key system ID. In our case it is PlayReady. Last 4 bytes (grey) define the size of the data of the PSSH box. The data then follows. And here is how it looks like in the hex editor:

![ppsh\_box.png](https://go.buydrm.com/hs-fs/hubfs/Docs%20And%20Guides/2017/102517_advanced_encryption_tech/ppsh_box.png?width=851&height=667&name=ppsh_box.png)

Figure 2. Complete PSSH box with PRO inside for MPEG-DASH CENC (w/ PlayReady)

 

## Building PSSH box for Widevine

Building PSSH box for Widevine to include into the MPEG-DASH manifest and into the encrypted file is not that different from building one for PlayReady. The structure of the box is the same. What changes is the Key System ID and the data of the PSSH box.

For Widevine PSSH box you will require the contents of the “*WVHeader”* field which you can find in a response from the KeyOS Encryption Key API. You can request this field by specifying *“\<fl\_GenerateWVHeader\>true\</fl\_GenerateWVHeader\>”* when making a call to the API.

Let’s presume you got this value as a response from the API:

`CAESEFbqtvroA0hrgJC5RCgkFHAaC2J1eWRybWtleW9zIhCPt34TKOxDs7gobkFcO33kKgJIRA==`

It is the Base64 representation of the following byte array:

```
08 01 12 10 56 ea b6 fa e8 03 48 6b 80 90 b9 44 28 24 14 70 1a 0b 62 75 79 64 72 6d 6b 65 79 6f 73
22 10 8f b7 7e 13 28 ec 43 b3 b8 28 6e 41 5c 3b 7d e4 2a 02 48 44
```

Let’s prepend it with all required PSSH box bytes and we get this as a result:

```
00 00 00 57
```

First 4 bytes (yellow) specify the box of the complete PSSH box. Next 4 bytes define the type of the box which is PSSH in our case. 4 zero bytes (blue). 16 bytes (pink) that define the unique key system ID which is *“ED EF 8B A9 79 D6 4A CE A3 C8 27 DC D5 1D 21 ED”* [\[SYSTEM-IDS\]](https://go.buydrm.com/thedrmblog/advanced-encryption-techniques#SYSTEM) in case of Widevine and uniquely identifies it. Last 4 bytes (grey) define the size of the data of the PSSH box. The data then follows. And here is how it looks like in the hex editor:

Figure 3. Complete PSSH box with Widevine header inside for MPEG-DASH CENC (w/ Widevine)

Congratulations, you now have values for *ContentProtection* tags inside the MPEG-DASH manifest:

```
<ContentProtection schemeIdUri="urn:mpeg:dash:mp4protection:2011" value="cenc" cenc:default_KID="CD90DC4F-5592-4573-8990-9C6A4D7199B2" />
<ContentProtection xmlns:mspr="urn:microsoft:playready" schemeIdUri="urn:uuid:9A04F079-9840-4286-AB92-E65BE0885F95" value="Microsoft PlayReady">
    <mspr:pro> vAMAAAEAAQCyAzwAVwBSAE0ASABFAEEARABFAFIAIAB4AG0AbABuAHMAPQAiAGgAdAB0AHAAOgAvAC8AcwBjAGgAZQBtAGEAcwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBEAFIATQAvADIAMAAwADcALwAwADMALwBQAGwAYQB5AFIAZQBhAGQAeQBIAGUAYQBkAGUAcgAiACAAdgBlAHIAcwBpAG8AbgA9ACIANAAuADAALgAwAC4AMAAiAD4APABEAEEAVABBAD4APABQAFIATwBUAEUAQwBUAEkATgBGAE8APgA8AEsARQBZAEwARQBOAD4AMQA2ADwALwBLAEUAWQBMAEUATgA+ADwAQQBMAEcASQBEAD4AQQBFAFMAQwBUAFIAPAAvAEEATABHAEkARAA+ADwALwBQAFIATwBUAEUAQwBUAEkATgBGAE8APgA8AEsASQBEAD4AVAA5AHkAUQB6AFoASgBWAGMAMABXAEoAawBKAHgAcQBUAFgARwBaAHMAZwA9AD0APAAvAEsASQBEAD4APABMAEEAXwBVAFIATAA+AGgAdAB0AHAAOgAvAC8AcwBsAGQAcgBtAC4AbABpAGMAZQBuAHMAZQBrAGUAeQBzAGUAcgB2AGUAcgAuAGMAbwBtAC8AYwBvAHIAZQAvAHIAaQBnAGgAdABzAG0AYQBuAGEAZwBlAHIALgBhAHMAbQB4ADwALwBMAEEAXwBVAFIATAA+ADwARABTAF8ASQBEAD4AVgBsAFIANwBJAGQAcwBJAEoARQB1AFIAZAAwADYATABhAHEAcwAyAGoAdwA9AD0APAAvAEQAUwBfAEkARAA+ADwAQwBVAFMAVABPAE0AQQBUAFQAUgBJAEIAVQBUAEUAUwAgAHgAbQBsAG4AcwA9ACIAIgA+ADwAQwBJAEQAPgBUADkAeQBRAHoAWgBKAFYAYwAwAFcASgBrAEoAeABxAFQAWABHAFoAcwBnAD0APQA8AC8AQwBJAEQAPgA8AEQAUgBNAFQAWQBQAEUAPgBzAG0AbwBvAHQAaAA8AC8ARABSAE0AVABZAFAARQA+ADwALwBDAFUAUwBUAE8ATQBBAFQAVABSAEkAQgBVAFQARQBTAD4APABDAEgARQBDAEsAUwBVAE0APgB4AFYAQQBXAG8AagBhAEoAcgB6AEUAPQA8AC8AQwBIAEUAQwBLAFMAVQBNAD4APAAvAEQAQQBUAEEAPgA8AC8AVwBSAE0ASABFAEEARABFAFIAPgA=</mspr:pro>
    <cenc:pssh>AAAD3HBzc2gAAAAAmgTweZhAQoarkuZb4IhflQAAA7y8AwAAAQABALIDPABXAFIATQBIAEUAQQBEAEUAUgAgAHgAbQBsAG4AcwA9ACIAaAB0AHQAcAA6AC8ALwBzAGMAaABlAG0AYQBzAC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEQAUgBNAC8AMgAwADAANwAvADAAMwAvAFAAbABhAHkAUgBlAGEAZAB5AEgAZQBhAGQAZQByACIAIAB2AGUAcgBzAGkAbwBuAD0AIgA0AC4AMAAuADAALgAwACIAPgA8AEQAQQBUAEEAPgA8AFAAUgBPAFQARQBDAFQASQBOAEYATwA+ADwASwBFAFkATABFAE4APgAxADYAPAAvAEsARQBZAEwARQBOAD4APABBAEwARwBJAEQAPgBBAEUAUwBDAFQAUgA8AC8AQQBMAEcASQBEAD4APAAvAFAAUgBPAFQARQBDAFQASQBOAEYATwA+ADwASwBJAEQAPgBUADkAeQBRAHoAWgBKAFYAYwAwAFcASgBrAEoAeABxAFQAWABHAFoAcwBnAD0APQA8AC8ASwBJAEQAPgA8AEwAQQBfAFUAUgBMAD4AaAB0AHQAcAA6AC8ALwBzAGwAZAByAG0ALgBsAGkAYwBlAG4AcwBlAGsAZQB5AHMAZQByAHYAZQByAC4AYwBvAG0ALwBjAG8AcgBlAC8AcgBpAGcAaAB0AHMAbQBhAG4AYQBnAGUAcgAuAGEAcwBtAHgAPAAvAEwAQQBfAFUAUgBMAD4APABEAFMAXwBJAEQAPgBWAGwAUgA3AEkAZABzAEkASgBFAHUAUgBkADAANgBMAGEAcQBzADIAagB3AD0APQA8AC8ARABTAF8ASQBEAD4APABDAFUAUwBUAE8ATQBBAFQAVABSAEkAQgBVAFQARQBTACAAeABtAGwAbgBzAD0AIgAiAD4APABDAEkARAA+AFQAOQB5AFEAegBaAEoAVgBjADAAVwBKAGsASgB4AHEAVABYAEcAWgBzAGcAPQA9ADwALwBDAEkARAA+ADwARABSAE0AVABZAFAARQA+AHMAbQBvAG8AdABoADwALwBEAFIATQBUAFkAUABFAD4APAAvAEMAVQBTAFQATwBNAEEAVABUAFIASQBCAFUAVABFAFMAPgA8AEMASABFAEMASwBTAFUATQA+AHgAVgBBAFcAbwBqAGEASgByAHoARQA9ADwALwBDAEgARQBDAEsAUwBVAE0APgA8AC8ARABBAFQAQQA+ADwALwBXAFIATQBIAEUAQQBEAEUAUgA+AA==</cenc:pssh>
</ContentProtection>
<ContentProtection schemeIdUri="urn:uuid:edef8ba9-79d6-4ace-a3c8-27dcd51d21ed" value="Widevine">
    <cenc:pssh>AAAAV3Bzc2gAAAAA7e+LqXnWSs6jyCfc1R0h7QAAADcIARIQVuq2+ugDSGuAkLlEKCQUcBoLYnV5ZHJta2V5b3MiEI+3fhMo7EOzuChuQVw7feQqAkhE</cenc:pssh>
</ContentProtection>
```

and PSSH boxes to include into the encrypted chunks.

## Summary and the future

As you saw from the above examples, little work needs to be done in order to implement with KeyOS Encryption API.

- Make a request to the KeyOS Encryption Key API and request both PlayReady and Widevine headers in a response.
- To create PRO and PSSH for PlayReady signaling, make sure you convert returned PlayReady header into UTF-16 LE before creating PRO based on it. When PRO is created, you can go a bit further and create PSSH.
- To create PSSH for Widevine signaling, make sure you request the PSSH data from the KeyOS Encryption Key API. When returned, just build complete PSSH structure around it.

We are looking into extending our APIs to include complete PSSH boxes and PRO objects and will be notifying our customers and encoding partners as soon as it is implemented.

Nevertheless, we also understand that standards are a must if you want to survive in a constantly changing world. Those add organization and structure to otherwise chaotic implementations and random data models flying around in the internet. This is why we started looking into Content Protection Information Exchange Format (CPIX). CPIX allow exchanging content keys and DRM information among entities needing it in many possibly different workflows for preparing DASH content and applying protection to it. We are currently implementing CPIX support through our existing APIs.

While there is no information on the release dates or potentially supported features, we will move forward in this direction to make the KeyOS Platform even more flexible for our partners and customers.

## References

**\[ISOBMFF\]**

ISO/IEC. *Information technology — Coding of audio-visual objects — Part 12: ISO Base Media File Format*. December 2015. International Standard. URL: [http://standards.iso.org/ittf/PubliclyAvailableStandards/c068960\_ISO\_IEC\_14496-12\_2015.zip](http://standards.iso.org/ittf/PubliclyAvailableStandards/c068960_ISO_IEC_14496-12_2015.zip)

**\[CENC\]**

ISO/IEC. *ISO/IEC 23001-7:2016, Information technology — MPEG systems technologies — Part 7: Common encryption in ISO base media file format files. International Standard*. URL: [https://www.iso.org/obp/ui/#iso:std:iso-iec:23001:-7:ed-3:v1:en](https://www.iso.org/obp/ui/#iso:std:iso-iec:23001:-7:ed-3:v1:en)

**\[PRHEADER\]**

Microsoft Corporation. *PlayReady Header Object*. URL: [http://download.microsoft.com/download/5/4/3/543E5DDF-750B-496D-BE35-6BF45E7E0476/PlayReady%20Header%20Specification%202017-10-10.pdf](http://download.microsoft.com/download/2/3/8/238F67D9-1B8B-48D3-AB83-9C00112268B2/PlayReady%20Header%20Object%202015-08-13-FINAL-CL.PDF)

**\[DASH-CENC\]**

Microsoft Corporation. *DASH Content Protection using Microsoft PlayReady*. URL: [http://download.microsoft.com/download/7/7/6/7762455C-D254-4C84-BE17-16B0C60E31FD/MPEG%20DASH%20PlayReady%201.2%20-%202014-10-08.pdf](http://download.microsoft.com/download/7/7/6/7762455C-D254-4C84-BE17-16B0C60E31FD/MPEG%20DASH%20PlayReady%201.2%20-%202014-10-08.pdf)

**\[SYSTEM-IDS\]**

DASH-IF. *Protection, Generic Identifiers.* URL: [http://dashif.org/identifiers/protection/](http://dashif.org/identifiers/protection/)

---

**Introducing the KeyOS Widevine Everywhere Program**

*Find out more by clicking below*

[![widevine\_everywhere](https://go.buydrm.com/hs-fs/hubfs/hubspot_wv_everywhere(1024x480).png?width=851&name=hubspot_wv_everywhere(1024x480).png "widevine_everywhere")](http://widevineeverywhere.com/)

---

 **Subscribe to The DRM Blog and get the 2016 DRM Deployment Guide**

**![TheDRMBlog](https://go.buydrm.com/hs-fs/hubfs/TheDRMBlog%20Images/TheDRMBlog%20Logos/TheDRMBlog_BlueSphere%20-1.png?width=159&name=TheDRMBlog_BlueSphere%20-1.png "TheDRMBlog")**

[![SUBSCRIBE](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/2212554/99b11ebb-f392-43bd-8538-6c07a30cb980.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/2212554/99b11ebb-f392-43bd-8538-6c07a30cb980)

---

**View Past Episodes From Our "Spotlight On DRM" Webinar Series**

**[![New Call-to-action](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/2212554/ad4c2d30-664a-4a4f-b1a2-1961bcf58093.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/2212554/ad4c2d30-664a-4a4f-b1a2-1961bcf58093)**

 

---

### **BuyDRM – Your Single Source for Multi-DRM Solutions**

### **![Playready Widevine Fairplay](https://go.buydrm.com/hs-fs/hubfs/DRM%20Flavors%20Image-1.png?width=853&name=DRM%20Flavors%20Image-1.png "Playready Widevine Fairplay")**

**Offering PlayReady, Widevine, and FairPlay, we can help you deliver protected content to any device in any situation whether online or offline or both.**

Established in 2001, we are a market-leading Multi-DRM service provider. Over the last fifteen years we have seen drastic changes in the content protection arena as a variety of new technologies have entered the marketplace. Through our pioneering efforts in this field and decades of experience in digital media, we have your bases covered with the KeyOS Multi-DRM Platform supporting PlayReady, Widevine, and FairPlay DRMs. KeyOS supports all of the popular consumer platforms and business models.

### **Want to Learn More?**

If you are either just beginning your search or are a seasoned streaming media pro, we think our team can help you. 

[Contact us](https://buydrm.com/contact/) to learn more about our solution.  We would be happy to set up a call to evaluate your scenario and find out how we can help you.  Our consultations are always free. Our KeyOS platform powers the biggest names in media across the globe and we are eager to assist you as well. 

Here is more content that you might be interested in:  
\- \[BLOG\]<https://go.buydrm.com/thedrmblog/batch-vs.-jit-encryption>[Batch vs. JIT Encryption](https://go.buydrm.com/thedrmblog/batch-vs.-jit-encryption)  
\- \[BLOG\] [Every Stream Unique: The Rise of Watermarking with DRM for OTT Streaming](https://go.buydrm.com/thedrmblog/every-stream-unique-the-rise-of-watermarking-with-drm-for-ott-streaming)- \[PARTNER\] [Bitmovin: Encoding & Player Partner](https://go.buydrm.com/thedrmblog/esp-partner-spotlight-bitmovin)

 Topics: [Blog](https://go.buydrm.com/thedrmblog/topic/blog), [Multi-DRM](https://go.buydrm.com/thedrmblog/topic/multi-drm), [DRM](https://go.buydrm.com/thedrmblog/topic/drm), [encryption](https://go.buydrm.com/thedrmblog/topic/encryption), [PSSH](https://go.buydrm.com/thedrmblog/topic/pssh)

### Subscribe for Instant Notifications

###### Popular Posts

- [![Managing Widevine DRM for Preventing Screen Capture and Recording on Android Devices](https://go.buydrm.com/hubfs/BuyDRM_Managing%20Widevine%20DRM%20for%20Preventing%20Screen%20Capture%20and%20Recording%20on%20Android%20Devices_1200x628.png)](https://go.buydrm.com/thedrmblog/managing-widevine-drm-for-preventing-screen-capture-and-recording-on-android-devices)
  
  [Managing Widevine DRM for Preventing Screen Capture and Recording on Android Devices](https://go.buydrm.com/thedrmblog/managing-widevine-drm-for-preventing-screen-capture-and-recording-on-android-devices)
  
   January 14, 2026
- [![BuyDRM Launches FairPlay Streaming SDK 26](https://go.buydrm.com/hubfs/BuyDRM_FairPlayv26_PressRelease_1200x628.png)](https://go.buydrm.com/thedrmblog/buydrm-launches-apple-fairplay-v26)
  
  [BuyDRM Launches FairPlay Streaming SDK 26](https://go.buydrm.com/thedrmblog/buydrm-launches-apple-fairplay-v26)
  
   June 16, 2026
- [![Forensic Watermarking + DRM: The Dynamic Duo for Bulletproof Content Security in 2026](https://go.buydrm.com/hubfs/BuyDRM_Forensic%20Watermarking%20%2B%20DRM-%20The%20Dynamic%20Duo%20for%20Bulletproof%20Content%20Security%20in%202026_1200x628-Recovered-1.png)](https://go.buydrm.com/thedrmblog/forensic-watermarking-drm-the-dynamic-duo-for-bulletproof-content-security-in-2026)
  
  [Forensic Watermarking + DRM: The Dynamic Duo for Bulletproof Content Security in 2026](https://go.buydrm.com/thedrmblog/forensic-watermarking-drm-the-dynamic-duo-for-bulletproof-content-security-in-2026)
  
   April 30, 2026
- [![Counting the Cost of Insecure Streaming: Why Multi-DRM Matters More Than Ever](https://go.buydrm.com/hubfs/BuyDRM_Counting%20the%20Cost%20of%20Insecure%20Streaming_Why%20Multi-DRM%20Matters%20More%20Than%20Ever_1200x628.png)](https://go.buydrm.com/thedrmblog/counting-the-cost-of-insecure-streaming-why-multi-drm-matters-more-than-ever)
  
  [Counting the Cost of Insecure Streaming: Why Multi-DRM Matters More Than Ever](https://go.buydrm.com/thedrmblog/counting-the-cost-of-insecure-streaming-why-multi-drm-matters-more-than-ever)
  
   November 12, 2025
- [![Safeguarding the Game: How DRM and Watermarking Protected World Cup Live Streams](https://go.buydrm.com/hubfs/BuyDRM_WorldCup_BlogPost_1200x628-1.png)](https://go.buydrm.com/thedrmblog/safeguarding-the-game-how-drm-and-watermarking-protected-world-cup-live-streams)
  
  [Safeguarding the Game: How DRM and Watermarking Protected World Cup Live Streams](https://go.buydrm.com/thedrmblog/safeguarding-the-game-how-drm-and-watermarking-protected-world-cup-live-streams)
  
   July 16, 2026

[![New call-to-action](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/2212554/154f7632-cceb-490e-864a-83df5ff18042.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/2212554/154f7632-cceb-490e-864a-83df5ff18042)

### Posts by Topic

- [DRM (95)](https://go.buydrm.com/thedrmblog/topic/drm)
- [Multi-DRM (26)](https://go.buydrm.com/thedrmblog/topic/multi-drm)
- [Content Security (16)](https://go.buydrm.com/thedrmblog/topic/content-security)
- [esp partner program (15)](https://go.buydrm.com/thedrmblog/topic/esp-partner-program)
- [Content Protection (13)](https://go.buydrm.com/thedrmblog/topic/content-protection)
- [Digital Rights Management (11)](https://go.buydrm.com/thedrmblog/topic/digital-rights-management)
- [Blog (9)](https://go.buydrm.com/thedrmblog/topic/blog)
- [Google Widevine DRM (9)](https://go.buydrm.com/thedrmblog/topic/google-widevine-drm)
- [anti-piracy (9)](https://go.buydrm.com/thedrmblog/topic/anti-piracy)
- [encryption (9)](https://go.buydrm.com/thedrmblog/topic/encryption)
- [BuyDRM (8)](https://go.buydrm.com/thedrmblog/topic/buydrm)
- [KeyOS (8)](https://go.buydrm.com/thedrmblog/topic/keyos)
- [OVHcloud (8)](https://go.buydrm.com/thedrmblog/topic/ovhcloud)
- [Piracy (8)](https://go.buydrm.com/thedrmblog/topic/piracy)
- [Apple FairPlay DRM (7)](https://go.buydrm.com/thedrmblog/topic/apple-fairplay-drm)
- [IBC (7)](https://go.buydrm.com/thedrmblog/topic/ibc)
- [partnerspotlight (7)](https://go.buydrm.com/thedrmblog/topic/partnerspotlight)
- [Bitmovin (6)](https://go.buydrm.com/thedrmblog/topic/bitmovin)
- [Streaming Media (6)](https://go.buydrm.com/thedrmblog/topic/streaming-media)
- [watermarking (6)](https://go.buydrm.com/thedrmblog/topic/watermarking)
- [webinar (6)](https://go.buydrm.com/thedrmblog/topic/webinar)
- [forensic watermarking (5)](https://go.buydrm.com/thedrmblog/topic/forensic-watermarking)
- [partners (5)](https://go.buydrm.com/thedrmblog/topic/partners)
- [CMAF (4)](https://go.buydrm.com/thedrmblog/topic/cmaf)
- [DRM workflow (4)](https://go.buydrm.com/thedrmblog/topic/drm-workflow)
- [Glossary (4)](https://go.buydrm.com/thedrmblog/topic/glossary)
- [What is DRM (3)](https://go.buydrm.com/thedrmblog/topic/what-is-drm)
- [Widevine (3)](https://go.buydrm.com/thedrmblog/topic/widevine)
- [esp program (3)](https://go.buydrm.com/thedrmblog/topic/esp-program)
- [3rd party server solutions (2)](https://go.buydrm.com/thedrmblog/topic/3rd-party-server-solutions)
- [4K (2)](https://go.buydrm.com/thedrmblog/topic/4k)
- [AWS Elemental (2)](https://go.buydrm.com/thedrmblog/topic/aws-elemental)
- [Adding DRM (2)](https://go.buydrm.com/thedrmblog/topic/adding-drm)
- [AppleTV (2)](https://go.buydrm.com/thedrmblog/topic/appletv)
- [CENC (2)](https://go.buydrm.com/thedrmblog/topic/cenc)
- [DRM Lifecycle (2)](https://go.buydrm.com/thedrmblog/topic/drm-lifecycle)
- [IBC Show (2)](https://go.buydrm.com/thedrmblog/topic/ibc-show)
- [Innovation (2)](https://go.buydrm.com/thedrmblog/topic/innovation)
- [Lifecycle DRM (2)](https://go.buydrm.com/thedrmblog/topic/lifecycle-drm)
- [Multi-Cloud (2)](https://go.buydrm.com/thedrmblog/topic/multi-cloud)
- [MultiKey Service (2)](https://go.buydrm.com/thedrmblog/topic/multikey-service)
- [NAB (2)](https://go.buydrm.com/thedrmblog/topic/nab)
- [OTT (2)](https://go.buydrm.com/thedrmblog/topic/ott)
- [PSSH (2)](https://go.buydrm.com/thedrmblog/topic/pssh)
- [W3C (2)](https://go.buydrm.com/thedrmblog/topic/w3c)
- [Zype (2)](https://go.buydrm.com/thedrmblog/topic/zype)
- [amazon (2)](https://go.buydrm.com/thedrmblog/topic/amazon)
- [authentication xml (2)](https://go.buydrm.com/thedrmblog/topic/authentication-xml)
- [concurrency limiting (2)](https://go.buydrm.com/thedrmblog/topic/concurrency-limiting)
- [encoder (2)](https://go.buydrm.com/thedrmblog/topic/encoder)
- [epix (2)](https://go.buydrm.com/thedrmblog/topic/epix)
- [flussonic (2)](https://go.buydrm.com/thedrmblog/topic/flussonic)
- [fuboTV (2)](https://go.buydrm.com/thedrmblog/topic/fubotv)
- [google (2)](https://go.buydrm.com/thedrmblog/topic/google)
- [ott content (2)](https://go.buydrm.com/thedrmblog/topic/ott-content)
- [server (2)](https://go.buydrm.com/thedrmblog/topic/server)
- [video streaming (2)](https://go.buydrm.com/thedrmblog/topic/video-streaming)
- [video.js (2)](https://go.buydrm.com/thedrmblog/topic/video-js)
- [2016 DRM Deployment Guide (1)](https://go.buydrm.com/thedrmblog/topic/2016-drm-deployment-guide)
- [3rd party cloud encryption solutions (1)](https://go.buydrm.com/thedrmblog/topic/3rd-party-cloud-encryption-solutions)
- [3rd party encoders (1)](https://go.buydrm.com/thedrmblog/topic/3rd-party-encoders)
- [ABC (1)](https://go.buydrm.com/thedrmblog/topic/abc)
- [API (1)](https://go.buydrm.com/thedrmblog/topic/api)
- [AV1 (1)](https://go.buydrm.com/thedrmblog/topic/av1)
- [Bento 4 (1)](https://go.buydrm.com/thedrmblog/topic/bento-4)
- [C2PA (1)](https://go.buydrm.com/thedrmblog/topic/c2pa)
- [CORS (1)](https://go.buydrm.com/thedrmblog/topic/cors)
- [COVID19 (1)](https://go.buydrm.com/thedrmblog/topic/covid19)
- [Cinedigm (1)](https://go.buydrm.com/thedrmblog/topic/cinedigm)
- [Cloud Security (1)](https://go.buydrm.com/thedrmblog/topic/cloud-security)
- [Common Encryption (1)](https://go.buydrm.com/thedrmblog/topic/common-encryption)
- [Content Encryption Keys (1)](https://go.buydrm.com/thedrmblog/topic/content-encryption-keys)
- [Cross-Origin Reference Sharing (1)](https://go.buydrm.com/thedrmblog/topic/cross-origin-reference-sharing)
- [DRM Acronyms (1)](https://go.buydrm.com/thedrmblog/topic/drm-acronyms)
- [DRM Capable Player (1)](https://go.buydrm.com/thedrmblog/topic/drm-capable-player)
- [DRM Playback (1)](https://go.buydrm.com/thedrmblog/topic/drm-playback)
- [Device DRM (1)](https://go.buydrm.com/thedrmblog/topic/device-drm)
- [Digital Element (1)](https://go.buydrm.com/thedrmblog/topic/digital-element)
- [EFF (1)](https://go.buydrm.com/thedrmblog/topic/eff)
- [EME (1)](https://go.buydrm.com/thedrmblog/topic/eme)
- [Encrypted Media Extension (1)](https://go.buydrm.com/thedrmblog/topic/encrypted-media-extension)
- [FFMpeg (1)](https://go.buydrm.com/thedrmblog/topic/ffmpeg)
- [Fall Special (1)](https://go.buydrm.com/thedrmblog/topic/fall-special)
- [GCP (1)](https://go.buydrm.com/thedrmblog/topic/gcp)
- [Google Cloud (1)](https://go.buydrm.com/thedrmblog/topic/google-cloud)
- [HEVC DRM (1)](https://go.buydrm.com/thedrmblog/topic/hevc-drm)
- [HTML5 (1)](https://go.buydrm.com/thedrmblog/topic/html5)
- [HTML5 Player with DRM Support (1)](https://go.buydrm.com/thedrmblog/topic/html5-player-with-drm-support)
- [HTML5Player (1)](https://go.buydrm.com/thedrmblog/topic/html5player)
- [Hollywood (1)](https://go.buydrm.com/thedrmblog/topic/hollywood)
- [IBC 2019 (1)](https://go.buydrm.com/thedrmblog/topic/ibc-2019)
- [IFE (1)](https://go.buydrm.com/thedrmblog/topic/ife)
- [Immergo (1)](https://go.buydrm.com/thedrmblog/topic/immergo)
- [Interra Systems (1)](https://go.buydrm.com/thedrmblog/topic/interra-systems)
- [JIT (1)](https://go.buydrm.com/thedrmblog/topic/jit)
- [License Request (1)](https://go.buydrm.com/thedrmblog/topic/license-request)
- [Live Stream Crash (1)](https://go.buydrm.com/thedrmblog/topic/live-stream-crash)
- [Live Stream Crash Solution (1)](https://go.buydrm.com/thedrmblog/topic/live-stream-crash-solution)
- [Live Streams (1)](https://go.buydrm.com/thedrmblog/topic/live-streams)
- [Live and VOD (1)](https://go.buydrm.com/thedrmblog/topic/live-and-vod)
- [MPEG DASH (1)](https://go.buydrm.com/thedrmblog/topic/mpeg-dash)
- [MWC (1)](https://go.buydrm.com/thedrmblog/topic/mwc)
- [Microsoft PlayReady DRM (1)](https://go.buydrm.com/thedrmblog/topic/microsoft-playready-drm)
- [Mobile World Congress (1)](https://go.buydrm.com/thedrmblog/topic/mobile-world-congress)
- [MultiBlock (1)](https://go.buydrm.com/thedrmblog/topic/multiblock)
- [MultiPack (1)](https://go.buydrm.com/thedrmblog/topic/multipack)
- [Multiple Keys (1)](https://go.buydrm.com/thedrmblog/topic/multiple-keys)
- [NAB 2024 (1)](https://go.buydrm.com/thedrmblog/topic/nab-2024)
- [Netflix (1)](https://go.buydrm.com/thedrmblog/topic/netflix)
- [OfflineDRM (1)](https://go.buydrm.com/thedrmblog/topic/offlinedrm)
- [Press Release (1)](https://go.buydrm.com/thedrmblog/topic/press-release)
- [R.I.P. (1)](https://go.buydrm.com/thedrmblog/topic/r-i-p)
- [Radiant Media Player (1)](https://go.buydrm.com/thedrmblog/topic/radiant-media-player)
- [Redspace (1)](https://go.buydrm.com/thedrmblog/topic/redspace)
- [SMConnect (1)](https://go.buydrm.com/thedrmblog/topic/smconnect)
- [Screen Recording (1)](https://go.buydrm.com/thedrmblog/topic/screen-recording)
- [Secure Player (1)](https://go.buydrm.com/thedrmblog/topic/secure-player)
- [Shaka Player (1)](https://go.buydrm.com/thedrmblog/topic/shaka-player)
- [Soundcloud (1)](https://go.buydrm.com/thedrmblog/topic/soundcloud)
- [Streamingmedia.com (1)](https://go.buydrm.com/thedrmblog/topic/streamingmedia-com)
- [Telestream (1)](https://go.buydrm.com/thedrmblog/topic/telestream)
- [UV (1)](https://go.buydrm.com/thedrmblog/topic/uv)
- [UltraViolet (1)](https://go.buydrm.com/thedrmblog/topic/ultraviolet)
- [Unified Streaming (1)](https://go.buydrm.com/thedrmblog/topic/unified-streaming)
- [Update (1)](https://go.buydrm.com/thedrmblog/topic/update)
- [WebRTC (1)](https://go.buydrm.com/thedrmblog/topic/webrtc)
- [XML (1)](https://go.buydrm.com/thedrmblog/topic/xml)
- [a/b watermarking (1)](https://go.buydrm.com/thedrmblog/topic/a-b-watermarking)
- [accurate player (1)](https://go.buydrm.com/thedrmblog/topic/accurate-player)
- [analytics (1)](https://go.buydrm.com/thedrmblog/topic/analytics)
- [australian broadcasting corporation (1)](https://go.buydrm.com/thedrmblog/topic/australian-broadcasting-corporation)
- [authentication (1)](https://go.buydrm.com/thedrmblog/topic/authentication)
- [batch encryption (1)](https://go.buydrm.com/thedrmblog/topic/batch-encryption)
- [best practices (1)](https://go.buydrm.com/thedrmblog/topic/best-practices)
- [building a drm platform (1)](https://go.buydrm.com/thedrmblog/topic/building-a-drm-platform)
- [case study (1)](https://go.buydrm.com/thedrmblog/topic/case-study)
- [client-side watermarking (1)](https://go.buydrm.com/thedrmblog/topic/client-side-watermarking)
- [compatability (1)](https://go.buydrm.com/thedrmblog/topic/compatability)
- [content licensing (1)](https://go.buydrm.com/thedrmblog/topic/content-licensing)
- [cpix (1)](https://go.buydrm.com/thedrmblog/topic/cpix)
- [data (1)](https://go.buydrm.com/thedrmblog/topic/data)
- [deploying (1)](https://go.buydrm.com/thedrmblog/topic/deploying)
- [drm licensing (1)](https://go.buydrm.com/thedrmblog/topic/drm-licensing)
- [drm pricing (1)](https://go.buydrm.com/thedrmblog/topic/drm-pricing)
- [drm report (1)](https://go.buydrm.com/thedrmblog/topic/drm-report)
- [encoding (1)](https://go.buydrm.com/thedrmblog/topic/encoding)
- [encoding.com (1)](https://go.buydrm.com/thedrmblog/topic/encoding-com)
- [encryption solutions (1)](https://go.buydrm.com/thedrmblog/topic/encryption-solutions)
- [harmonic (1)](https://go.buydrm.com/thedrmblog/topic/harmonic)
- [integration (1)](https://go.buydrm.com/thedrmblog/topic/integration)
- [kodi (1)](https://go.buydrm.com/thedrmblog/topic/kodi)
- [license acquisition (1)](https://go.buydrm.com/thedrmblog/topic/license-acquisition)
- [live events (1)](https://go.buydrm.com/thedrmblog/topic/live-events)
- [live sports (1)](https://go.buydrm.com/thedrmblog/topic/live-sports)
- [low-latency (1)](https://go.buydrm.com/thedrmblog/topic/low-latency)
- [low-latency drm (1)](https://go.buydrm.com/thedrmblog/topic/low-latency-drm)
- [major movie studios (1)](https://go.buydrm.com/thedrmblog/topic/major-movie-studios)
- [multiscreener (1)](https://go.buydrm.com/thedrmblog/topic/multiscreener)
- [native drm (1)](https://go.buydrm.com/thedrmblog/topic/native-drm)
- [non-persistent license (1)](https://go.buydrm.com/thedrmblog/topic/non-persistent-license)
- [os (1)](https://go.buydrm.com/thedrmblog/topic/os)
- [packaging (1)](https://go.buydrm.com/thedrmblog/topic/packaging)
- [partner program (1)](https://go.buydrm.com/thedrmblog/topic/partner-program)
- [persistent license (1)](https://go.buydrm.com/thedrmblog/topic/persistent-license)
- [proxy (1)](https://go.buydrm.com/thedrmblog/topic/proxy)
- [questionnaire (1)](https://go.buydrm.com/thedrmblog/topic/questionnaire)
- [radiant player (1)](https://go.buydrm.com/thedrmblog/topic/radiant-player)
- [roku (1)](https://go.buydrm.com/thedrmblog/topic/roku)
- [screen capture (1)](https://go.buydrm.com/thedrmblog/topic/screen-capture)
- [screener (1)](https://go.buydrm.com/thedrmblog/topic/screener)
- [server-side watermarking (1)](https://go.buydrm.com/thedrmblog/topic/server-side-watermarking)
- [strategy (1)](https://go.buydrm.com/thedrmblog/topic/strategy)
- [streaming (1)](https://go.buydrm.com/thedrmblog/topic/streaming)
- [theoplayer (1)](https://go.buydrm.com/thedrmblog/topic/theoplayer)
- [video player (1)](https://go.buydrm.com/thedrmblog/topic/video-player)
- [watermark (1)](https://go.buydrm.com/thedrmblog/topic/watermark)
- [watermarked (1)](https://go.buydrm.com/thedrmblog/topic/watermarked)
- [webplay (1)](https://go.buydrm.com/thedrmblog/topic/webplay)
- [zee5 (1)](https://go.buydrm.com/thedrmblog/topic/zee5)

see all

###### Follow Us

[![Share on Facebook](https://static.hubspot.com/final/img/common/icons/social/facebook-24x24.png)](https://www.facebook.com/buydrm) [![Share on LinkedIn](https://static.hubspot.com/final/img/common/icons/social/linkedin-24x24.png)](http://www.linkedin.com/company/buydrm) [![Share on Twitter](https://static.hubspot.com/final/img/common/icons/social/twitter-24x24.png)](https://twitter.com/buydrm)

### Subscribe to The DRM Blog for Instant Notications

![](https://go.buydrm.com/hs-fs/hubfs/BuyDRM_KeyOS_Logos/images/buydrm-logo.png?width=207&name=buydrm-logo.png "buydrm-logo.png")

Founded in 2001, BuyDRM is a leading provider of Digital Rights Management and Content Security Services for the entertainment, enterprise and education industries.

[![Share on Facebook](https://static.hubspot.com/final/img/common/icons/social/facebook-24x24.png)](https://www.facebook.com/buydrm) [![Share on LinkedIn](https://static.hubspot.com/final/img/common/icons/social/linkedin-24x24.png)](http://www.linkedin.com/company/buydrm) [![Share on Twitter](https://static.hubspot.com/final/img/common/icons/social/twitter-24x24.png)](https://twitter.com/buydrm)