USENIX Security2024Top-tier venue
Formal Security Analysis of Widevine through the W3C EME Standard
Stéphanie Delaune, Joseph Lallemand, Gwendal Patat, Florian Roudot, Mohamed Sabt
Abstract
Streaming services such as Netflix, Amazon Prime Video, or Disney+ rely on the widespread EME standard to deliver their content to end users on all major web browsers. While providing an abstraction layer to the underlying DRM protocols of each device, the security of this API has never been formally studied. In this paper, we provide the first formal analysis of Widevine, the most deployed DRM instantiating EME.
We define security goals for EME, focusing on media protection and usage control. Then, relying on the TAMARIN prover, we conduct a detailed security analysis of these goals on some Widevine EME implementations, reverse-engineered by us for this study. Our investigation highlights a vulnerability that could allow for unlimited media consumption. Additionally, we present a patched protocol that is suitable for both mobile and desktop platforms, and that we formally proved secure using TAMARIN. lemma CDMKeysInit[reuse, use_induction]: "∀ #i rID sID kAsset kMacS kMacC. Keys(rID, sID, kAsset, kMacS, kMacC)@#i ⇒ ( (∃ #j. (#j < #i) & Derive(rID, sID, kAsset, kMacS, kMacC)@#j) | (kAsset ='null' & kMacS = 'null' & kMacC = 'null'))"
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Secret State Leakage Attacks and Their Impacts on EMV Contactless Payment AppsJesse Chen, Rubin Yuchan Yang, Ahmad Musa, Syed Rafiul Hussain et al.S&P 2026
- GUIA uditor : Enabling Post-hoc Child Safety Forensics via Action-Guided GUI Provenance on Mobile DevicesJunlin Liu, Yifeng Cai, Shuai Wang, Zhineng Zhong et al.UbiComp 2026
- Narrowbeer: A Practical Replay Attack Against the Widevine DRMFlorian Roudot, Mohamed SabtUSENIX Security 2025
Builds on2
- ProVerif with Lemmas, Induction, Fast Subsumption, and Much MoreBruno Blanchet, Vincent Cheval, Véronique CortierS&P 2022 · 61 citations
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
Related papers
- Formal Analysis of SPDM: Security Protocol and Data Model version 1.2Cas Cremers, Alexander Dax, Aurora NaskaUSENIX Security 2023
- Digital Hole: Bypassing Commercial Audio DRM Solutions with DReaMcatcherBjörn Ruytenberg, Mohammad Sina Karvandi, Herbert Bos, Erik van der Kouwe et al.EuroSys 2026
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 69 citations
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu et al.S&P 2022 · 26 citations
- An In-Depth Symbolic Security Analysis of the ACME StandardKarthikeyan Bhargavan, Abhishek Bichhawat, Quoc Huy Do, Pedram Hosseyni et al.CCS 2021 · 12 citations
