Cancelled on Friday, still watching on Sunday
One library, played on phones, in browsers, on consoles and on five brands of television — each of which accepts only its own vendor's protection system. The library is encrypted once and the same bytes serve all of them, which is the part the team got right.
Support has a run of tickets that are all the same ticket. An account cancels, the card is never charged again, and the titles keep playing. One of them plays on a handset that has never been near the account.
- R1A device may be given the means to decrypt only if the account behind it has the right to watch that title, in that country, at that moment. The system that mints permissions must never be reachable by a device directly — a player that can ask it is a player that can be modified to ask it differently.
- R2What a device is given must be usable only on that device. Copied off it — out of browser storage, off a rooted handset, out of a download shared between friends — it must not play anywhere else. The account holder being genuine is not the question; which machine is asking is.
- R3The people who operate the encrypting pipeline must not be able to read the content keys the pipeline is given. They run the machines the keys arrive on and they terminate the connection the keys arrive over, so securing the transport does not answer this.
Boundaries, outermost first: RUN BY THE PIPELINE TEAM: Packager (encrypts once), an empty slot for the how the keys reach the packager, tier 2 Outside every boundary: Subscription state (who may watch), Encrypted library (one copy), DRM key provider (issues the keys), Delivery network (encrypted bytes), Player device (its own module), Vendor licence service (mints licences), an empty slot for the what the device presents, tier 1, an empty slot for the what stands before the vendor, tier 1 Connections: Packager calls how the keys reach the packager — asks for keys how the keys reach the packager calls DRM key provider — forwards it Packager calls Encrypted library — one copy Encrypted library calls Delivery network — origin Delivery network calls Player device — encrypted bytes Player device calls what the device presents — asks to play what the device presents calls what stands before the vendor — with its proof what stands before the vendor calls Subscription state — may they, now? what stands before the vendor calls Vendor licence service — with the rules