Using Azure Media Services to deliver DRM licenses with shaka packager?

Viewed 842

I am building a subscription based Video On Demand service. For content protection I choose Widevine & Azure Media Services for License delivery which costs US$0.20 for 100 licenses. Shaka Packager for media packaging.

I followed this guide & got :

Created key nb:kid:UUID:d2c69XXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX with key value XXXXXXXXXXXXXXXXf7Kc7g==
PlayReady License Key delivery URL: https://xxxxxxx.keydelivery.centralindia.media.azure.net/PlayReady/
Widevine License Key delivery URL: https://xxxxxxx.keydelivery.centralindia.media.azure.net/Widevine/?KID=d2c69XXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
Added authorization policy: nb:ckpid:UUID:5274f7da-XXXX-XXXX-XXXX-XXXXXXXXXXXX

Shaka Packager Documentation

$ packager <stream_descriptor> ... \
  --enable_widevine_encryption \
  --key_server_url <key_server_url> \
  --content_id <content_id> \
  --signer <signer> --aes_signing_key <aes_signing_key> \
  --aes_signing_iv <aes_signing_iv> \
  [Other options, e.g. DASH options, HLS options]

So I have key_server_url , content_id

where do I find aes_signing_key & aes_signing_iv ?

1 Answers

The link to the documentation and the example you have provided is for when you are using a Widevine Key Server, with the information returned from the API linked to on that page, the 'Common Encryption API for Widevine DRM'.

Note the link to that document may not work without permission but you can usually see a version as an example if you google for the title of the API.

In your case you probably want to use the instructions for 'Using Raw Key' in the Shaka documentation here: https://google.github.io/shaka-packager/html/tutorials/raw_key.html#using-raw-key

This includes examples like:

$ packager \
  in=h264_baseline_360p_600.mp4,stream=audio,output=audio.mp4,drm_label=AUDIO \
  in=h264_baseline_360p_600.mp4,stream=video,output=h264_360p.mp4,drm_label=SD \
  in=h264_main_480p_1000.mp4,stream=video,output=h264_480p.mp4,drm_label=SD \
  in=h264_main_720p_3000.mp4,stream=video,output=h264_720p.mp4,drm_label=HD \
  in=h264_high_1080p_6000.mp4,stream=video,output=h264_1080p.mp4,drm_label=HD \
  --enable_raw_key_encryption \
  --keys label=AUDIO:key_id=f3c5e0361e6654b28f8049c778b23946:key=a4631a153a443df9eed0593043db7519,label=SD:key_id=abba271e8bcf552bbd2e86a434a9a5d9:key=69eaa802a6763af979e8d1940fb88392,label=HD:key_id=6d76f25cb17f5e16b8eaef6bbf582d8e:key=cb541084c99731aef4fff74500c12ead \
  --mpd_output h264.mpd

For 'key_Id' you use the returned key UUID and for 'key=' the returned 'key value'.

Although it is not required as an input here, just to note for completeness, the Initialization Vector, 'aes_signing_iv' in the Widevine API, is typically not a secret value. It is simply a 'seed' value that is used to start the block initialisation for AES encryption. It can be created and passed to the packager, and is often simply a random 8 or 16 byte IV for each piece of content.

Related