Overview - ISO/IEC 23078-3:2024 (Device key-based protection)
ISO/IEC 23078-3:2024 specifies a device key-based digital rights management (DRM) solution for encrypting resources in digital publications (especially EPUB). The standard defines how a reading system registers a device certificate with content providers and how decryption keys are securely delivered inside licenses tailored to specific devices. It uses the passphrase-based authentication method defined in ISO/IEC 23078-2 for license acquisition and access to encrypted publication resources.
Key technical topics and requirements
- Protecting the publication: Technical rules for encrypting publication resources and embedding protection metadata so reading systems can detect protected publications.
- License document structure: Requirements for license content including:
- Encryption (key transport) - how decryption keys are transmitted in the license.
- Links - pointers to external resources (status endpoints, update URLs).
- Rights - machine-readable rights and restrictions for consumption.
- User - identifying the authorized user.
- Signature - canonical form and signing requirements to ensure integrity.
- User key and passphrase handling: Calculating user keys, hints, and constraints for secure passphrase-derived key material.
- Device key lifecycle: Generating device keys, device certificate registration, recommendations for protecting device private keys.
- License status document: Mechanisms to query license state (active, revoked, updated) and events such as renewals, returns, transfers.
- Encryption profiles: Defined profiles and minimum requirements for encryption algorithms and parameters.
- Reading system behaviors & workflows: Registering a device, acquiring device key-based licenses, decrypting resources, handling errors, transfers, returns and renewals.
- Integration and extensions: Integration guidance for EPUB and informative extension for PDF (Annex C).
Practical applications and target users
This standard is intended for organizations implementing DRM for digital publications:
- Publishers and distributors who need device-bound protection of EPUB content.
- DRM vendors and platform providers building license servers, key distribution, or device registration systems.
- Reading system and e-reader developers implementing license processing, device key management, and decryption.
- Libraries and content aggregators that require interoperable, standards-based license workflows for lending and timed access.
- Security architects designing PKI, signature validation, and passphrase-derived key handling.
Related standards
- ISO/IEC 23078-2 - passphrase-based authentication (used by this part).
- Other parts of the ISO/IEC 23078 series for DRM specifications.
- EPUB technical specifications (for integration guidance).
- Annex C of ISO/IEC 23078-3 provides an extension for PDF workflows.
Keywords: ISO/IEC 23078-3:2024, DRM for digital publications, device key-based protection, EPUB DRM, license document, device certificate, encryption profiles, reading system.