Lune

USENIX Security2024顶会

Formal Security Analysis of Widevine through the W3C EME Standard

Stéphanie Delaune, Joseph Lallemand, Gwendal Patat, Florian Roudot, Mohamed Sabt

出版方
2024年份
4被引次数
3顶会引用

摘要

Streaming services such as Netflix, Amazon Prime Video, or Disney+ rely on the widespread EME standard to deliver their content to end users on all major web browsers. While providing an abstraction layer to the underlying DRM protocols of each device, the security of this API has never been formally studied. In this paper, we provide the first formal analysis of Widevine, the most deployed DRM instantiating EME.

We define security goals for EME, focusing on media protection and usage control. Then, relying on the TAMARIN prover, we conduct a detailed security analysis of these goals on some Widevine EME implementations, reverse-engineered by us for this study. Our investigation highlights a vulnerability that could allow for unlimited media consumption. Additionally, we present a patched protocol that is suitable for both mobile and desktop platforms, and that we formally proved secure using TAMARIN. lemma CDMKeysInit[reuse, use_induction]: "∀ #i rID sID kAsset kMacS kMacC. Keys(rID, sID, kAsset, kMacS, kMacC)@#i ⇒ ( (∃ #j. (#j < #i) & Derive(rID, sID, kAsset, kMacS, kMacC)@#j) | (kAsset ='null' & kMacS = 'null' & kMacC = 'null'))"

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper3

问问它们各自怎么用它

它引用的顶会 Paper2

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖