Microsoft PlayReady End-to-End Trust Architecture

CENC signaling, client-bound licenses, SL3000 execution and protected output

PlayReady end-to-end data and trust flow Service, distribution, and client trust domains from packaging through license acquisition to protected rendering. SERVICE TRUST DOMAIN UNTRUSTED DELIVERY CLIENT TRUST BOUNDARY TEE / SL3000 PROTECTED PATH policy CK by KID policy template {KID, CK} publish cache MPD + CENC init data EME / IPC 1. signed challenge + client certificate + requested KIDs 2. signed client-bound XMR license + policy bind samples HDCP / OPL CENC samples Entitlement Service account / device / region rights + policy profile KMS / Key Store secret: CK / key seed KID -> CK mapping License Server XMR + signature client binding CENC Packager PRO / PSSH cenc / cbcs License Policy MinimumSecurityLevel - OPL - expiration persistence - secure clock - secure stop Policy is visible; enforcement is trusted-client work Manifest + Init Data KID / PSSH / PRO / LA_URL public routing metadata CDN / Object Store encrypted CMAF segments no content key required Web App / Player MSE + EME session routing cannot export CK by API Browser / MediaDrm Key System negotiation REE orchestration PlayReady Client certificate + challenge SL / feature evidence License Bind + Crypto private key / CK / secure clock MSL, OPL, expiry enforcement non-exportable state Secure Decoder protected surfaces Protected Output LEGEND client / public data service policy secret / security boundary control / license flow media / metadata flow

Signaling Is Not Enforcement

  • PRO and PSSH identify KIDs and license routing
  • Encrypted media remains CDN-cacheable
  • EME exposes sessions, never raw content keys

Trust Anchors

  • Server-side KMS and license signing material
  • Client certificate and protected private keys
  • TEE, secure clock, decoder and output path

Independent Failure Gates

  • Entitlement, certificate and revocation checks
  • Minimum Security Level and time policy
  • OPL, HDCP and protected rendering capability