Streaming Video Encoding & Packaging Pipeline  ·  View 21 of 22  ·  Assurance

Identity, Keys and Licence Flow

Thirteen messages in which the pipeline never ends up holding a key.

Editable source SVG draw.io All views
Packager Workload identity Key broker Cloud KMS Rendition store Player DRM licence service 1. attest workload 2. short-lived token 3. request key for (title, territory) 4. generate + wrap content key 5. key + key_id 6. key in memory, key_id to record 7. encrypt once, common encryption 8. segments + key_id reference 9. register key_id and policy 10. fetch segment (via CDN) 11. licence request for key_id 12. licence, or refusal on revoked key 13. takedown: revoke key_id Identity, Keys and Licence Flow One encrypted segment set serves three DRM systems, and the pipeline never holds a key past the packaging job. v 1.0 · owner Media Platform Architecture

Encrypt once, serve three DRM systems

  • Common encryption means one encrypted segment set satisfies every DRM system, so adding one is a licence-service integration rather than a re-packaging job.
  • The packager holds the content key in memory for the duration of one packaging job and records only the key id.

Takedown is a revocation, not a deletion

  • Withdrawing the manifest and revoking the key id takes effect independently of CDN cache expiry — a cached segment without a licence is inert.
  • That is the only mechanism in the design that acts faster than the 30-day segment cache, and it is the reason segments can be cached that long at all.

Assumption

  • Assumed three DRM systems and territory- or window-scoped key policies. Key rotation is supported without re-encoding or re-packaging, which is a requirement rather than an optimisation.