Widevine CENC ISO BMFF Box Structure

Initialization defaults, per-fragment sample metadata, auxiliary encryption records and encrypted media bytes

Widevine CENC ISO BMFF box hierarchy and references The initialization segment defines codec and default encryption state while each media segment maps sample timing and auxiliary encryption records to encrypted bytes in mdat. INITIALIZATION SEGMENT stable track metadata and default encryption context MEDIA SEGMENT / FRAGMENT sample timing, byte locations, IVs, subsamples and encrypted payload then sample entry codec protection tenc default KID / IV size / crypt-skip pattern indexes range trun data_offset + sizes maps seig override sizes offset IV + clear/encrypted ranges ftyp brands / compatibility moov movie metadata container - no encrypted sample payload moov children mvhd movie timebase pssh SystemID + init data CDM session signaling mvex / trex fragment defaults duration / size / flags trak / mdia / minf / stbl / stsd track - media - sample table - sample descriptions encv / enca protected sample entry video / audio wrapper codec config avcC / hvcC / av1C / esds decode configuration, not DRM sinf - protection scheme information frma original codec 4CC schm cenc / cbcs 4CC schi / tenc isProtected default KID IV size / const IV crypt / skip pattern track defaults styp segment brands sidx optional byte/time index emsg / prft (optional) timed events / producer time - not key material moof - movie fragment metadata mfhd sequence number fragment identity traf - one track fragment tfhd track + defaults tfdt base decode time trun count / size / duration / offset sgpd (seig) alternate KID / IV encryption group entry sbgp sample range -> group key rotation mapping saiz aux entry sizes per sample saio aux data offsets locates records senc sample IV + subsamples clear/encrypted byte counts mdat encrypted sample bytes - ciphertext, not License or metadata LEGEND container / timing DRM signaling encryption context index / group map auxiliary metadata media / byte ranges

Initialization Defaults

  • stsd selects the protected encv/enca sample entry
  • sinf restores codec identity and names cenc/cbcs
  • tenc provides the default KID, IV and pattern state

Per-Fragment Layout

  • trun maps sample count, timing, sizes and mdat offsets
  • saiz/saio locate auxiliary encryption records
  • senc supplies per-sample IVs and subsample byte ranges

Rotation Overrides

  • sgpd seig entries describe alternate encryption state
  • sbgp maps sample runs to those group descriptions
  • the effective KID may therefore differ from tenc default