Strategies for Secure OTT Video in a Multiscreen World

OTT video service providers are facing huge stresses on their business. Irdeto has laid out a strategy that takes as much advantage as possible of standards while minimizing and isolating complexity.

Life is not simple for providers of over-the-top (OTT) Internet video services – whether pay TV operators or new pure-internet players. Consumers have become conditioned to “all my media on all my devices all the time” from their experiences with digital music and e-book services, and they expect no less from video; meanwhile, Hollywood studios and other video content licensors have raised, not lowered, their expectations that their content be protected from unauthorized use.

In general, the technological complexity of building, maintaining, and scaling multiscreen OTT video services isn’t decreasing. Operators require a range of capabilities including streaming video, content protection, application development, and other technologies. Yet no single, “silver bullet” stack with all these capabilities has emerged that operators can rely on to build out their services in a future-proof, scalable, and interoperable manner.

A recommended strategy for OTT providers can be summarized as follows:

  • Implement apps in browsers wherever possible using HTML5 with EME. Chrome and Internet Explorer are currently the browsers with support for HTML5 EME that is best suited to third-party app developers. Therefore start with PCs and Macs, then move to tablets and mobile phones, game consoles, and finally other devices such as STBs and Smart TVs as HTML5 EME-compliant browsers become distributed with them. HTML5 enables app development with consistent user experience across platforms with minimum incremental development effort.
  • Adopt DASH for adaptive bitrate streaming wherever possible, but be prepared to support two adaptive bitrate streaming technologies – HLS as well as DASH – in order to support a sufficiently wide variety of client devices.
  • Be prepared to support a larger and varying number of DRMs and browsers. Take advantage of built-in support for certain DRMs on popular platforms to simplify implementation. Use CENC common encryption to minimize the number of encrypted content files that must be created and shipped to CDNs.

Support for multiple DRMs due to browser dependencies is the number one technological bottleneck to interoperability and scalability.

    Multiscreen Rights Management

    The best strategy for providers to minimize this complexity is to adopt a multiscreen rights management capability.

    The multiscreen rights management scheme acts as a single interface between a service provider’s back end systems and apps on all client platforms. It enables DRMs to be added and changed as the market evolves and needs dictate.

    At the center of the multiscreen rights management scheme is a Rights Manager, which abstracts away DRM-specific license parameters and manages much of the communication with apps when a user selects a content item. It also generates CENC encryption keys to include in DRM licenses and responds to requests for keys from the Encoder-Packager.

    The multiscreen rights management scheme also ideally includes an entitlements database, which integrates information about user accounts and content rights, so that it is efficient to get information about rights that a particular device (belonging to a user, who has an account) has to a particular piece of content in order to approve access to it. Some operators maintain separate entitlement management systems (e.g., so that they can support managed-network as well as OTT services), in which case the multiscreen rights management scheme can pull information from those systems.

    Finally, the multiscreen rights management scheme also maintains account-level business rules, such as limits on the number of concurrent streams or bitrates.

Of course, changes in these market positions will change the DRM market landscape as well – such as one of the up-and-coming niche browsers becoming a major player. All this is justification for the strategy recommended here. We expect this set of market dynamics and interdependencies to continue for the foreseeable future.

From a white paper authored by Bill Rosenblatt, founder of GiantSteps Media Technology Strategies for Irdeto

You might also like...

HDR & WCG For Broadcast: Part 3 - Achieving Simultaneous HDR-SDR Workflows

Welcome to Part 3 of ‘HDR & WCG For Broadcast’ - a major 10 article exploration of the science and practical applications of all aspects of High Dynamic Range and Wide Color Gamut for broadcast production. Part 3 discusses the creative challenges of HDR…

IP Security For Broadcasters: Part 4 - MACsec Explained

IPsec and VPN provide much improved security over untrusted networks such as the internet. However, security may need to improve within a local area network, and to achieve this we have MACsec in our arsenal of security solutions.

Standards: Part 23 - Media Types Vs MIME Types

Media Types describe the container and content format when delivering media over a network. Historically they were described as MIME Types.

Six Considerations For Transitioning To Cloud Based Video Distribution

There are many reasons why companies are transitioning from legacy video distribution workflows to ones hosted entirely in the public cloud, but it’s not a simple process and takes an enormous amount of planning. Many potential pitfalls can be a…

IP Security For Broadcasters: Part 3 - IPsec Explained

One of the great advantages of the internet is that it relies on open standards that promote routing of IP packets between multiple networks. But this provides many challenges when considering security. The good news is that we have solutions…