Overview
ISO/IEC 23001-9:2016 defines a common encryption format for encrypted content carried in MPEG‑2 transport streams (MPEG‑2 TS). The standard enables interoperable content protection that is compatible with the common-encryption model used for ISO Base Media File Format (ISO‑BMFF) in ISO/IEC 23001‑7, allowing conversion (re‑encapsulation) between encrypted MPEG‑2 TS and encrypted ISO‑BMFF without needing to re‑encrypt the media. This facilitates end‑to‑end content protection across production, packaging, delivery and playback workflows.
Key topics and requirements
- Per‑access‑unit encryption model: Each access unit (AU) is encrypted separately and requires a key and an initialization vector (IV). Key resolution itself is out of scope; the standard assumes a key system returns the actual key given a key identifier.
- Encryption parameter signalling:
- CETS ECM (Entitlement Control Message): Carries key identifiers and IVs for encrypted AUs. ECMs typically appear frequently because encryption is applied per AU.
- CETS PSSH: A private PID mechanism to carry vendor-specific license or PSSH‑style data for DRM systems (one PID per DRM system).
- CA_descriptor and cets_byte_range_descriptor: Used to signal algorithm-related parameters and byte‑range encryption for partially encrypted payloads.
- Transport mapping:
- Use of the MPEG‑2 TS field transport_scrambling_control to indicate whether packet payloads are clear or encrypted and to map packets to the appropriate key/IV via the nearest ECM.
- Special handling for CA_System_ID values (examples in the standard include identifiers ‘ce’ and ‘cf’) to distinguish full‑packet encryption vs. byte‑range signalling.
- Re‑encapsulation without re‑encryption: If encrypted byte ranges and parameters remain consistent and are signalled in the clear, MPEG‑2 TS and ISO‑BMFF files can be remultiplexed or converted without decrypting/re‑encrypting content.
Applications and users
- Content owners and studios seeking interoperable, container‑independent content protection.
- DRM vendors implementing key signalling and license exchange compatible with MPEG‑2 TS delivery.
- Encoder, packager and muxing vendors enabling re‑encapsulation between MPEG‑2 TS and ISO‑BMFF in CDN and broadcast workflows.
- Broadcast and OTT service providers, CDN operators and device manufacturers (set‑top boxes, STBs, OTT apps) that must handle protected MPEG‑2 TS streams and interoperate with ISO‑BMFF ecosystems.
Related standards
Keywords: ISO/IEC 23001-9:2016, common encryption, MPEG-2 transport streams, CETS, ECM, PSSH, re-encapsulation, ISO-BMFF, DRM, content protection.