Multi-DRM explained: Widevine, FairPlay, PlayReady and CENC

How one library serves Widevine, FairPlay and PlayReady through CENC, where multi-DRM breaks down, the costs and approvals involved, and what to ask a vendor.

7 min read
On this page 13 sections
  1. Why multi-DRM exists
  2. What CENC does, and the catch
  3. Where multi-DRM breaks down
  4. The weakest device sets the bar
  5. Licences issued without real checks
  6. Side doors
  7. What no DRM can cover
  8. The hidden costs and hurdles
  9. What to ask a multi-DRM or video platform vendor
  10. The legal position
  11. Key takeaways
  12. Where VidSafe fits
  13. Frequently asked questions

Multi-DRM means protecting one video library so it plays under all three major DRM systems: Google's Widevine, Apple's FairPlay and Microsoft's PlayReady. Each video is encrypted once under the Common Encryption standard (CENC), and a licence service issues keys to whichever system a device uses. It solves a coverage problem, not a piracy problem: a multi-DRM setup is only as strong as the weakest device it serves and the checks behind its licences, and none of the three systems can stop someone filming the screen or sharing a password.

Why multi-DRM exists

Each platform supports its own DRM system, and no DRM system can read another's licences. To reach phones, laptops and TVs from one library, a service needs all three. In browsers, all of them are reached through the same W3C standard, Encrypted Media Extensions. Our explainer on how DRM works covers the basics.

Where the video playsDRM systemWorth knowing
Chrome, Firefox, Edge, Android phones and TVs, ChromeOSWidevineProtection ranges from hardware-backed to software-only, depending on the device
Safari, iPhone, iPad, Mac, Apple TVFairPlay StreamingBuilt around HLS; production use needs Apple's approval
Edge on Windows, Xbox, many smart TVsPlayReadyHas a hardware-backed level on devices with the right hardware, and a software level elsewhere

What CENC does, and the catch

Packaging every lecture three times would triple storage and effort. The ISO/IEC 23001-7 standard, Common Encryption, now in its fourth edition (2023), lets a video be encrypted once, with AES, and carry the information each DRM system needs alongside it. The key itself is never in the file; it arrives later, inside a licence.

The catch is that Common Encryption comes in variants, and two matter in practice. The cenc scheme is what older Widevine and PlayReady devices expect. The cbcs scheme is what FairPlay requires, and current Widevine and PlayReady devices support it too, so one set of files can serve all three on modern hardware. Serving older devices can mean keeping a second encrypted copy of the library, with the extra storage, processing and room for mistakes that brings. Our guide to HLS vs DASH explains the CMAF format behind a single shared copy.

Where multi-DRM breaks down

The weakest device sets the bar

Every DRM system has a software level for devices without the right hardware: Widevine's L3 and PlayReady's SL2000. Keys there are guarded by obfuscated code on a device the user controls, and Widevine's software level was publicly broken in 2019. If a service serves its best quality to software-only devices, that's where clean copies come from. Our comparison of Widevine security levels explains the difference.

Licences issued without real checks

DRM verifies devices, not people. Apple's FairPlay overview, for example, states that the framework doesn't authenticate the app to its key server; that's left to the service. If the licence server hands out licences to anyone who is logged in, or keeps honouring accounts whose access has ended, the whole DRM stack protects nothing that matters.

Side doors

A single unprotected route undoes the rest: a quality level that was never encrypted, a free preview cut from the full lecture, an old app version that plays plain files, or original recordings left downloadable in storage.

What no DRM can cover

  • screen recording on devices without a protected display path, including many desktop browsers;

  • a second phone filming the screen, the analogue hole that exists for every system;

  • shared logins, which get valid licences for everyone using them;

  • PDFs, notes and test papers.

These gaps are covered in why DRM alone can't stop piracy.

The hidden costs and hurdles

  • Apple's approval. Apple's FairPlay Streaming page says production credentials are approved only for teams that provide a streaming service to consumers, requested by the account holder of their Apple Developer Program membership, and not for third parties acting on a content owner's behalf. Even if you rent a licence service, your organisation applies.

  • Agreements and fees. Widevine needs a licence agreement with Google, which charges no fee for it, while running or renting licence servers for three systems costs money every month.

  • Testing. Every combination your students use, from budget Android phones to laptops, iPhones and smart TVs, has to be tested, including what students see when playback is refused.

  • Support. Students on software-only devices may get lower quality or no downloads, and they need clear explanations rather than cryptic errors.

  • Everything else. After all of this, camera recording, shared passwords and PDFs still need other answers, as our comparison of DRM vs encryption explains.

What to ask a multi-DRM or video platform vendor

  1. Which of our students' devices and browsers get hardware-backed protection, and which fall back to software?

  2. What quality and offline rights do software-only devices get?

  3. Is every quality level, preview and original file protected, on every app version?

  4. Who decides whether a student is entitled to a licence, and how quickly does revoked access take effect?

  5. Will older devices force a second encrypted copy of our library?

  6. Who holds the FairPlay credentials, and what happens to them if we change vendors?

  7. What covers screen recording, camera recording, account sharing and PDFs?

Getting around DRM to copy paid lectures can be a crime as well as a breach of terms. Circumventing an effective technological measure with the intention of infringing copyright is an offence under Section 65A of the Copyright Act, punishable with up to two years in prison and a fine; see our guide to copyright infringement punishment in India. This is general information, not legal advice. For your situation, speak to a lawyer.

Key takeaways

  • Multi-DRM lets one encrypted library play under Widevine, FairPlay and PlayReady.

  • Common Encryption makes that possible, but older devices can force a second copy.

  • Software-only devices are the weak point, and Widevine's software level was publicly broken in 2019.

  • Licences are only as safe as the entitlement checks behind them, and one side door undoes the rest.

  • No DRM stops screen filming, shared logins or leaked PDFs.

Where VidSafe fits

VidSafe protects course videos with VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention, PDF watermarking and RASP in the apps, and it adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. See our LMS for coaching institutes.

Frequently asked questions

What is multi DRM?

Multi-DRM is the practice of protecting one video library with several DRM systems at once, usually Widevine, FairPlay and PlayReady, so it can play on Android, Apple and Windows devices, browsers and TVs. The video is encrypted once using Common Encryption, and a licence service issues keys in the format each device's DRM system understands.

What is FairPlay DRM?

FairPlay Streaming is Apple's DRM system for video delivered over HLS. It protects the content key on its way from the provider's key server to iPhones, iPads, Macs and Apple TVs, and supports rules such as expiry, offline use and limits on simultaneous streams. Apple must approve an organisation before it can use FairPlay in production.

What is PlayReady DRM?

PlayReady is Microsoft's DRM system, used in Edge on Windows, on Xbox and on many smart TVs and set-top boxes. Its security levels include SL2000, which relies mainly on software, and SL3000, which keeps keys and processing inside a hardware trusted execution environment. It decrypts Common Encryption content, so it fits into a multi-DRM setup alongside Widevine and FairPlay.

What is encrypted media extensions?

Encrypted Media Extensions (EME) is a W3C standard that lets web pages play DRM-protected video. The page asks the browser for a DRM system such as Widevine, passes licence requests between the browser's built-in decryption module and a licence server, and the module decrypts the video. EME works only on HTTPS pages.

Share this article

Looking for something else?

Talk to Us