Netflix MSL Entity, Session and Risk Binding

MSL 不靠一个更长的 device_id,而是把实体能力、会话、用户与本次控制消息放进同一个密码学上下文

Netflix MSL entity session user and licensed manifest binding architecture A client entity capability establishes an MSL session, a user token binds to the master token, protected messages bind control actions, and Netflix policy returns a licensed manifest and Widevine license response. CLIENT AND ENTITY MSL SESSION PROTECTED MESSAGE NETFLIX CONTROL AND POLICY playback outcome, token renewal, concurrency and device/session telemetry feed later policy decisions Device and App ContextESN / profile / client capabilityobservations inform policy; not proof alone Entity Crypto CapabilityRSA keypair OR Widevine CryptoSessionproof strength depends on selected route User and Playback Intentaccount / viewable / profiles / challengemust be authorized inside session context Key Exchange RequestASYMMETRIC_WRAPPED or WIDEVINEentityauthdata + keyrequestdata MasterToken and Session KeysKenc / Khmac OR key IDs in CDMserial + sequence + renewal + expiration Proof of Possessionencrypt / sign / decrypt capabilitynon-exportable key does not stop oracle abuse MasterTokenserver-issued session contexttoken alone is not message capability UserIdToken BindingUIT.mtserialnumber == MT.serialnumberprevents cross-session token splicing Encrypted Header and Payloadencrypt-then-MAC / messageid / chunksoptional nonreplayableid requires server state MSL Verification Boundarytoken / proof / HMAC / binding / freshnessverify before decrypt and business parsing Playback Authorization Policyaccount / title / plan / region / device classhousehold, concurrency and risk are service policy licensedManifest Responsetracks + CDN streams + Widevine licenseone protected per-play control exchange protocol and local log evidence service policy integration: architecture inference session trust verification / policy Binding chain: entity capability -> MasterToken -> UserIdToken -> protected message -> licensedManifest policy decision. Security boundary: MSL limits token splicing and detached replay; it does not make a controlled authorized endpoint honest or protect decoded frames. Device-risk lesson: stable identity is only an input. Netflix adds proof of possession, short-lived session context and per-play authorization.

不是超级设备 ID

  • ESN、profile 和设备观察负责提供上下文
  • 真正的协议强度来自实体能力与会话证明
  • 软件 RSA 与 Widevine CDM 路线不能同级评价

四层绑定逐步收窄复用

  • MasterToken 绑定会话,UserIdToken 再绑定用户
  • 消息绑定 key、HMAC、messageid 与可选非重放状态
  • licensedManifest 把播放参数和 License challenge 合并授权

合法端点仍可能被滥用

  • 不可导出密钥降低克隆,不阻止 CryptoSession oracle
  • 完整消息可重放性仍取决于服务端窗口与业务幂等
  • 最终要靠账号、并发、策略和播放反馈限制规模