- The app receives and transports an opaque request
- The partner proxy applies entitlement before fulfillment
- The opaque response returns to the originating DRM session
- Desktop Chrome routes library CDM calls through Mojo
- Android crosses MediaDrm, Binder and an AIDL DRM HAL
- Neither public app API promises an exportable content key
- Chrome decode/output protection depends on host platform
- Android L1 can keep decrypt and decode inside secure hardware
- License success and secure output remain independent gates