HLS or DASH over CMAF
Below are the parameters accessed in the HLS or DASH over CMAF output.
General
General
Related information HLS or DASH over CMAF output configuration
Dash
Manifest
Filtering - Stream characteristics
HLS
Playlist
Important: The manifest name must be unique and different from any other manifest name.
Filtering - Stream characteristics
Delivery
General parameters
Common encryption (CENC)
Fixed key generation mode
PlayReady mode enabled:
Widevine mode enabled:
Compatible CPIX ext. key
Key rotation
Key usage rules
Related information See CPIX key rotation and track keys below for details on how these settings shape the key requests sent to the key server.
Common encryption (CBCS)
Fixed key generation mode
PlayReady mode enabled:
Widevine mode enabled:
Fairplay mode enabled:
Key usage rules
Compatible CPIX ext. key
Key rotation
Key usage rules
CPIX key rotation and track keys
The Compatible CPIX ext. key provider (CENC or CBCS) delegates key generation to an external key server through the DASH-IF CPIX protocol. Two independent CPIX mechanisms are available on top of a single fixed key: key rotation, which periodically requests a new key over time, and track keys, which requests distinct keys for different tracks of the same output.
Key rotation
When key rotation is enabled, the packager requests a new key from the key server for every crypto period instead of a single key for the whole output:
-
The period and its unit set the crypto period duration (converted to seconds for the key request).
-
The start time anchors the period grid: period boundaries fall at
start time + n × period, for every integern. Only the start time’s position within one period matters. -
The time spread adds jitter on top of that grid. Rather than requesting a key exactly on the period boundary, the packager offsets the request by a pseudo-random duration somewhere inside the spread window. This avoids many outputs sharing the same period and start time from all hitting the key server at the same instant, while keeping the offset stable for a given output.
-
The period mode controls how the current crypto period is identified in the CPIX exchange:
Index — the request/response carries an integer period number.
-
Start/end (default) — the request/response carries the period’s actual validity window.
-
The number of key periods to request lets the packager fetch more than the current key in one CPIX round trip — the current key plus one or more upcoming (lookahead) keys.
Setting the crypto period to 0 (or leaving key rotation disabled) means a single key is requested and used for the entire output — none of the other key rotation parameters apply in that case.
Track keys
By default, a single CPIX key applies to every track of an output. Declaring one or more entries in Tracks requests one key per entry instead, so different tracks (e.g. UHD video vs. SD video vs. audio) can be encrypted with different keys — a common requirement for tiered DRM policies (for example restricting 4K playback to devices with a stronger security level).
Each track entry combines two independent things:
-
Track type and Labels are sent to the key server as the CPIX usage rule for that track’s key. Both are free-form strings with no built-in normalization — their meaning is a convention agreed with the key server.
-
Filtering is evaluated locally by the packager only — it is never sent to the key server — to decide which of the output’s actual streams that track key applies to. It supports
streamType(video or audio),widthandheight(in pixels), andcodec(H.264 or HEVC). The first track whose filter matches a given stream wins; a track without any filtering has no local restriction.
Important: the key server may return a different key ID and key periods than the one the packager sent for a given track — always match tracks and keys on the identity returned in the CPIX response, not on the request.
Combining key rotation with track keys
Key rotation and track keys can be combined: the packager then requests one key per (track, crypto period) combination — for example, 2 tracks with 3 lookahead periods results in 6 keys in a single CPIX exchange. In that case, each <ContentKeyUsageRule> additionally carries a <KeyPeriodFilter periodId="…"/> element tying that specific track’s key to the crypto period it is valid for.
Related information HLS or DASH over CMAF output configuration HLS over TS output configuration