3.2.5.3 License Acquisition Keys and Certificates

The license acquisition process uses key pairs as follows:

  1. The device requests a license and sends its device certificate to the license issuer.

  2. The license issuer validates the device certificate and verifies that the device can enforce the rights required by the content license.

  3. The license issuer uses the device public key (located in the device certificate) and encrypts the content key. The license issuer then creates a license with the appropriate rights and includes the encrypted content key. Only the device with the matching device private key can decrypt the content key and play the content by using this license.

  4. The license is stored in the license store on the device.

The following diagram shows how the license issuer uses the device key pair to encrypt a license during license acquisition.

Using the device key pair to encrypt a license

Figure 2: Using the device key pair to encrypt a license