Widevine Provisioning, License and Secure Playback Flow

Device trust is established before content entitlement; opaque licenses then govern key use, renewal and output

Widevine provisioning, content license and secure playback sequence The client first obtains or refreshes device credentials through provisioning, then relays a content license request through a partner proxy, and finally uses the resulting license in a CDM or secure media path. A. DEVICE TRUST / PROVISIONING - only when credentials are absent, stale or revoked B. CONTENT ENTITLEMENT / LICENSE - repeated per title, policy window or key period C. KEY USE / SECURE PLAYBACK - encrypted samples, policy enforcement and lifecycle events 1. create/open DRM session 2. not provisioned / individualization needed 3. Android getProvisionRequest() 4. opaque request + server URL 5a. app relay over HTTPS 5b. browser/CDM direct individualization may be internal 6. signed device certificate / credentials 7. provideProvisionResponse(); retry 8. PSSH + KID + session type 9. opaque License Request 10. HTTPS + account token + asset/playback context 11. verified request + policy 12. individualized license 13. opaque response; proxy cannot rewrite generated license 14. update() / provideKeyResponse() key handle + policy state; raw CK is not returned through the public app API 15. encrypted CENC samples + IV/subsample metadata 16. usable/expired/output-restricted status; frames remain in protected path when required 17. renewal, key rotation, offline restore/release loop OTT App / Browsertransport + account context CDM / MediaDrmcredential + license state Provisioning Servicedevice certificate lifecycle Partner License Proxyentitlement + risk policy Widevine Servicefulfillment + personalization OEMCrypto / DecoderTEE + protected output ENTITLEMENT GATEplan / geo / concurrency / risk LEGEND provisioning license request credential / license response encrypted media policy status / secure output

Provision Once, Refresh When Needed

  • Android surfaces NotProvisionedException and opaque provisioning APIs
  • Browser individualization may remain inside the user agent and CDM
  • Provisioning establishes device credentials; it does not authorize a title

Authorize Every Playback Context

  • The partner proxy binds account rights, asset, KID and device evidence
  • The Widevine service returns an opaque device-individualized license
  • Streaming, offline, renewal and release are separate lifecycle states

Enforce During Key Use

  • L1 can retain keys, decrypted samples and decode inside secure hardware
  • HDCP, resolution and expiration remain active playback gates
  • License success alone does not guarantee an allowed output path