Overview
ISO/IEC 23078-2:2024 specifies a user key–based DRM solution for protecting digital publications (especially EPUB). It defines how resources in a publication are encrypted and how decryption keys are securely delivered to reading systems via user-tailored licenses. The document also describes a simple passphrase-based authentication method that reading systems can use to verify licenses and unlock encrypted content, improving interoperability and long‑term access.
Key topics and requirements
- Encryption of resources: Defines an encryption profile and requirements for encrypting publication assets and packaging encrypted resources in EPUB containers (use of META-INF/encryption.xml is specified).
- License document: Specifies the structure and mandatory fields of license files used to transmit decryption keys, links, rights, user identity, and signatures.
- User key and passphrase: Describes how a user key is calculated from user credentials, requirements for passphrase strength, and optional hints to assist user authentication.
- License status document: Covers status checking, events, timestamps, and workflows such as registering devices, returning publications, and renewing licenses.
- Signature and PKI: Requires signed license documents and defines certificate handling, canonicalization, signature generation and validation to ensure integrity and non‑repudiation.
- Reading system behavior: Provides rules for detecting protected publications, validating licenses, processing user keys, handling errors, and enforcing rights and restrictions.
- Encryption profiles and interoperability: Includes a baseline Basic Encryption Profile 1.0 and guidance for interoperability between issuers and reading systems.
- Examples and extensions: Informative annexes illustrate use cases (including library lending models) and an extension for PDF.
Practical applications and who uses it
- Publishers and aggregators: to protect EPUBs and other digital publications while preserving interoperability and portability.
- Library systems and consortia: to implement lending workflows, status checks, returns, and renewals in a standards-based DRM model.
- Reading system and device developers: to implement license parsing, passphrase-based user authentication, signature validation, and license-status interactions.
- Platform integrators and accessibility teams: to ensure protected publications remain accessible across compliant readers and to reduce vendor lock‑in risk.
- Standards bodies and archivists: to reference an interoperable DRM standard for long‑term access and preservation planning.
Related standards
- ISO/IEC 23078 series (DRM for digital publications)
- EPUB packaging conventions (integration guidance)
- XML Signature 1.1 and XML Encryption 1.1 (normative references)
- RFC 6901, RFC 6570 (referenced for data addressing and URI templates)
- LCP-related registries and ecosystem specifications (referenced within the document)
Keywords: DRM, digital publications, EPUB, user key, license document, encryption, passphrase authentication, reading system, interoperability, library lending.