Google Widevine End-to-End Trust Architecture

CENC signaling, partner-controlled licensing, device identity and L1 protected media path

Widevine end-to-end data and trust flow Service, delivery, application, CDM, TEE and protected output boundaries from packaging through individualized licensing. SERVICE TRUST DOMAIN UNTRUSTED DELIVERY CLIENT TRUST BOUNDARY TEE / L1 PROTECTED MEDIA PATH rights rules key service KID / CK policy publish PSSH cache MPD + CENC init data IPC 1. opaque license request + device/client evidence 4. individualized immutable license + policy 2. signed request 3. fulfilled license bind / load samples secure buffer HDCP / output Entitlement Service account / asset / region risk + concurrency Partner License Proxy validate + append rules the client-facing endpoint Widevine License Service Cloud Service or hosted SDK verify + individualize + sign KMS / Content Key API secret: track KID -> CK separate packaging/license roles CENC Packager Widevine PSSH / KIDs cenc / cbcs / crypto periods Policy Catalog duration / renewal / output track tier / security minimum Provisioning / Revocation Control device credentials, implementation status and emergency downgrade Manifest + Init Data SystemID / KID / PSSH public routing metadata CDN / Object Store encrypted CMAF segments no CK required Web App / Media3 MSE / player orchestration forwards opaque messages EME / MediaDrm session + capability API no raw key API Widevine CDM / Plugin request + license verification session / device-bound state OEMCrypto / TEE device secret / CK use policy + secure state non-exportable handles Secure Decoder protected surfaces Protected Output LEGEND client / public data service policy secret / security boundary license / control flow media / metadata flow

Public Signaling

  • MPD, KID and Widevine PSSH route a DRM session
  • CENC media remains safely CDN-cacheable
  • PSSH protobuf contains identifiers, not the CK

Partner Control Plane

  • The client talks to the partner proxy, never cloud directly
  • Entitlement and device rules are applied before fulfillment
  • The generated license is individualized and immutable

L1 Trust Anchors

  • Provisioned device identity and protected key use
  • OEMCrypto, secure decoder and protected buffers
  • Output capability remains an independent policy gate