Overview
ISO/IEC 23009-4:2018 - "Information technology - Dynamic adaptive streaming over HTTP (DASH) - Part 4: Segment encryption and authentication" specifies format‑independent mechanisms to encrypt DASH media segments and to verify their integrity and authenticity. The standard defines MPD signalling elements, out‑of‑band key resolution concepts, cryptoperiod management, and interoperable authentication approaches so that any DASH segment format (ISO/IEC 23009-1) can be protected consistently.
Keywords: ISO/IEC 23009-4:2018, DASH segment encryption, segment authentication, MPD security, content protection, cryptoperiod.
Key topics and technical requirements
- Scope and intent
- Format‑independent segment encryption and signalling for DASH.
- Mechanisms to ensure segment integrity and authenticity across DASH segments.
- Content protection framework
- Separation of key system (provides keys/licenses) and encryption system (applies encryption).
- MPD interfaces for out‑of‑band derivation of keys, IVs and other parameters.
- Signalling elements (MPD)
- Elements such as ContentProtection, SegmentEncryption, License, CryptoPeriod, and CryptoTimeline are defined for declaring encryption/authentication in the MPD.
- Encryption systems and algorithms
- Support for multiple systems including AES-128 CBC, AES-128 GCM, and Common encryption paradigms.
- Extensibility to add new encryption and key systems (e.g., support added for ISO/IEC 23001-7).
- Cryptoperiods and key derivation
- Definition of cryptoperiods (continuous segments using the same key/IV).
- Mechanisms for assigning segments to cryptoperiods and deriving keys, IVs and additional authenticated data (AAD).
- Segment authentication
- Support for authentication tags and algorithms (e.g., SHA-256, HMAC‑SHA1) to verify integrity and authenticity.
- Normative references
- Uses established cryptographic and protocol references such as FIPS‑197 (AES), NIST SP 800‑38D (GCM), RFC 2104 (HMAC), RFC 7230 (HTTP).
Practical applications
- Protecting on‑demand and live DASH streams against tampering and unauthorized access.
- Enabling interoperable DRM and license workflows across players, CDNs and license servers.
- Signalling encryption/authentication metadata in MPDs for client implementations.
- Supporting secure content distribution pipelines for OTT platforms, broadcasters and media service providers.
Who should use this standard
- Streaming architects and platform engineers designing DASH delivery systems.
- DRM and license server vendors implementing key systems.
- Player and client developers implementing DASH decryption and authentication.
- CDN operators, content owners, compliance officers and standards implementers.
Related standards
- ISO/IEC 23009-1 (DASH Part 1: MPD and segment formats)
- ISO/IEC 23001-7 (additional encryption system support)
- FIPS‑197 (AES), NIST SP 800‑38D (GCM), RFC 2104 (HMAC), RFC 7230 (HTTP)
For implementers, ISO/IEC 23009-4:2018 provides the MPD signalling and cryptographic framework needed to deploy secure, interoperable DASH streaming with segment encryption and authentication.