DASH Media Packaging SDK
 All Classes Namespaces Functions Variables Typedefs Enumerator
widevine_key_source.cc
1 // Copyright 2014 Google Inc. All rights reserved.
2 //
3 // Use of this source code is governed by a BSD-style
4 // license that can be found in the LICENSE file or at
5 // https://developers.google.com/open-source/licenses/bsd
6 
7 #include "packager/media/base/widevine_key_source.h"
8 
9 #include "packager/base/base64.h"
10 #include "packager/base/bind.h"
11 #include "packager/base/json/json_reader.h"
12 #include "packager/base/json/json_writer.h"
13 #include "packager/base/memory/ref_counted.h"
14 #include "packager/base/stl_util.h"
15 #include "packager/media/base/http_key_fetcher.h"
16 #include "packager/media/base/producer_consumer_queue.h"
17 #include "packager/media/base/protection_system_specific_info.h"
18 #include "packager/media/base/request_signer.h"
19 #include "packager/media/base/widevine_pssh_data.pb.h"
20 
21 #define RCHECK(x) \
22  do { \
23  if (!(x)) { \
24  LOG(ERROR) << "Failure while processing: " << #x; \
25  return false; \
26  } \
27  } while (0)
28 
29 namespace edash_packager {
30 namespace {
31 
32 const bool kEnableKeyRotation = true;
33 
34 const char kLicenseStatusOK[] = "OK";
35 // Server may return INTERNAL_ERROR intermittently, which is a transient error
36 // and the next client request may succeed without problem.
37 const char kLicenseStatusTransientError[] = "INTERNAL_ERROR";
38 
39 // Number of times to retry requesting keys in case of a transient error from
40 // the server.
41 const int kNumTransientErrorRetries = 5;
42 const int kFirstRetryDelayMilliseconds = 1000;
43 
44 // Default crypto period count, which is the number of keys to fetch on every
45 // key rotation enabled request.
46 const int kDefaultCryptoPeriodCount = 10;
47 const int kGetKeyTimeoutInSeconds = 5 * 60; // 5 minutes.
48 const int kKeyFetchTimeoutInSeconds = 60; // 1 minute.
49 
50 bool Base64StringToBytes(const std::string& base64_string,
51  std::vector<uint8_t>* bytes) {
52  DCHECK(bytes);
53  std::string str;
54  if (!base::Base64Decode(base64_string, &str))
55  return false;
56  bytes->assign(str.begin(), str.end());
57  return true;
58 }
59 
60 void BytesToBase64String(const std::vector<uint8_t>& bytes,
61  std::string* base64_string) {
62  DCHECK(base64_string);
63  base::Base64Encode(base::StringPiece(reinterpret_cast<const char*>
64  (bytes.data()), bytes.size()),
65  base64_string);
66 }
67 
68 bool GetKeyFromTrack(const base::DictionaryValue& track_dict,
69  std::vector<uint8_t>* key) {
70  DCHECK(key);
71  std::string key_base64_string;
72  RCHECK(track_dict.GetString("key", &key_base64_string));
73  VLOG(2) << "Key:" << key_base64_string;
74  RCHECK(Base64StringToBytes(key_base64_string, key));
75  return true;
76 }
77 
78 bool GetKeyIdFromTrack(const base::DictionaryValue& track_dict,
79  std::vector<uint8_t>* key_id) {
80  DCHECK(key_id);
81  std::string key_id_base64_string;
82  RCHECK(track_dict.GetString("key_id", &key_id_base64_string));
83  VLOG(2) << "Keyid:" << key_id_base64_string;
84  RCHECK(Base64StringToBytes(key_id_base64_string, key_id));
85  return true;
86 }
87 
88 bool GetPsshDataFromTrack(const base::DictionaryValue& track_dict,
89  std::vector<uint8_t>* pssh_data) {
90  DCHECK(pssh_data);
91 
92  const base::ListValue* pssh_list;
93  RCHECK(track_dict.GetList("pssh", &pssh_list));
94  // Invariant check. We don't want to crash in release mode if possible.
95  // The following code handles it gracefully if GetSize() does not return 1.
96  DCHECK_EQ(1u, pssh_list->GetSize());
97 
98  const base::DictionaryValue* pssh_dict;
99  RCHECK(pssh_list->GetDictionary(0, &pssh_dict));
100  std::string drm_type;
101  RCHECK(pssh_dict->GetString("drm_type", &drm_type));
102  if (drm_type != "WIDEVINE") {
103  LOG(ERROR) << "Expecting drm_type 'WIDEVINE', get '" << drm_type << "'.";
104  return false;
105  }
106  std::string pssh_data_base64_string;
107  RCHECK(pssh_dict->GetString("data", &pssh_data_base64_string));
108 
109  VLOG(2) << "Pssh Data:" << pssh_data_base64_string;
110  RCHECK(Base64StringToBytes(pssh_data_base64_string, pssh_data));
111  return true;
112 }
113 
114 } // namespace
115 
116 namespace media {
117 
118 // A ref counted wrapper for EncryptionKeyMap.
119 class WidevineKeySource::RefCountedEncryptionKeyMap
120  : public base::RefCountedThreadSafe<RefCountedEncryptionKeyMap> {
121  public:
122  explicit RefCountedEncryptionKeyMap(EncryptionKeyMap* encryption_key_map) {
123  DCHECK(encryption_key_map);
124  encryption_key_map_.swap(*encryption_key_map);
125  }
126 
127  std::map<KeySource::TrackType, EncryptionKey*>& map() {
128  return encryption_key_map_;
129  }
130 
131  private:
132  friend class base::RefCountedThreadSafe<RefCountedEncryptionKeyMap>;
133 
134  ~RefCountedEncryptionKeyMap() { STLDeleteValues(&encryption_key_map_); }
135 
136  EncryptionKeyMap encryption_key_map_;
137 
138  DISALLOW_COPY_AND_ASSIGN(RefCountedEncryptionKeyMap);
139 };
140 
141 WidevineKeySource::WidevineKeySource(const std::string& server_url)
142  : key_production_thread_("KeyProductionThread",
143  base::Bind(&WidevineKeySource::FetchKeysTask,
144  base::Unretained(this))),
145  key_fetcher_(new HttpKeyFetcher(kKeyFetchTimeoutInSeconds)),
146  server_url_(server_url),
147  crypto_period_count_(kDefaultCryptoPeriodCount),
148  key_production_started_(false),
149  start_key_production_(false, false),
150  first_crypto_period_index_(0) {
151  key_production_thread_.Start();
152 }
153 
154 WidevineKeySource::~WidevineKeySource() {
155  if (key_pool_)
156  key_pool_->Stop();
157  if (key_production_thread_.HasBeenStarted()) {
158  // Signal the production thread to start key production if it is not
159  // signaled yet so the thread can be joined.
160  start_key_production_.Signal();
161  key_production_thread_.Join();
162  }
163  STLDeleteValues(&encryption_key_map_);
164 }
165 
166 Status WidevineKeySource::FetchKeys(const std::vector<uint8_t>& content_id,
167  const std::string& policy) {
168  base::AutoLock scoped_lock(lock_);
169  request_dict_.Clear();
170  std::string content_id_base64_string;
171  BytesToBase64String(content_id, &content_id_base64_string);
172  request_dict_.SetString("content_id", content_id_base64_string);
173  request_dict_.SetString("policy", policy);
174  return FetchKeysInternal(!kEnableKeyRotation, 0, false);
175 }
176 
177 Status WidevineKeySource::FetchKeys(const std::vector<uint8_t>& pssh_box) {
178  const std::vector<uint8_t> widevine_system_id(
179  kWidevineSystemId, kWidevineSystemId + arraysize(kWidevineSystemId));
180 
182  if (!info.Parse(pssh_box.data(), pssh_box.size()))
183  return Status(error::PARSER_FAILURE, "Error parsing the PSSH box.");
184 
185  if (info.system_id() == widevine_system_id) {
186  base::AutoLock scoped_lock(lock_);
187  request_dict_.Clear();
188  std::string pssh_data_base64_string;
189 
190  BytesToBase64String(info.pssh_data(), &pssh_data_base64_string);
191  request_dict_.SetString("pssh_data", pssh_data_base64_string);
192  return FetchKeysInternal(!kEnableKeyRotation, 0, false);
193  } else if (!info.key_ids().empty()) {
194  // This is not a Widevine PSSH box. Try making the request for the key-IDs.
195  // Even if this is a different key-system, it should still work. Either
196  // the server will not recognize it and return an error, or it will
197  // recognize it and the key must be correct (or the content is bad).
198  return FetchKeys(info.key_ids());
199  } else {
200  return Status(error::NOT_FOUND, "No key IDs given in PSSH box.");
201  }
202 }
203 
205  const std::vector<std::vector<uint8_t>>& key_ids) {
206  base::AutoLock scoped_lock(lock_);
207  request_dict_.Clear();
208  std::string pssh_data_base64_string;
209 
210  // Generate Widevine PSSH data from the key-IDs.
211  WidevinePsshData widevine_pssh_data;
212  for (size_t i = 0; i < key_ids.size(); i++) {
213  widevine_pssh_data.add_key_id(key_ids[i].data(), key_ids[i].size());
214  }
215 
216  const std::string serialized_string = widevine_pssh_data.SerializeAsString();
217  std::vector<uint8_t> pssh_data(serialized_string.begin(),
218  serialized_string.end());
219 
220  BytesToBase64String(pssh_data, &pssh_data_base64_string);
221  request_dict_.SetString("pssh_data", pssh_data_base64_string);
222  return FetchKeysInternal(!kEnableKeyRotation, 0, false);
223 }
224 
226  base::AutoLock scoped_lock(lock_);
227  request_dict_.Clear();
228  // Javascript/JSON does not support int64_t or unsigned numbers. Use double
229  // instead as 32-bit integer can be lossless represented using double.
230  request_dict_.SetDouble("asset_id", asset_id);
231  return FetchKeysInternal(!kEnableKeyRotation, 0, true);
232 }
233 
234 Status WidevineKeySource::GetKey(TrackType track_type, EncryptionKey* key) {
235  DCHECK(key);
236  if (encryption_key_map_.find(track_type) == encryption_key_map_.end()) {
237  return Status(error::INTERNAL_ERROR,
238  "Cannot find key of type " + TrackTypeToString(track_type));
239  }
240  *key = *encryption_key_map_[track_type];
241  return Status::OK;
242 }
243 
244 Status WidevineKeySource::GetKey(const std::vector<uint8_t>& key_id,
245  EncryptionKey* key) {
246  DCHECK(key);
247  for (std::map<TrackType, EncryptionKey*>::iterator iter =
248  encryption_key_map_.begin();
249  iter != encryption_key_map_.end();
250  ++iter) {
251  if (iter->second->key_id == key_id) {
252  *key = *iter->second;
253  return Status::OK;
254  }
255  }
256  return Status(error::INTERNAL_ERROR,
257  "Cannot find key with specified key ID");
258 }
259 
260 Status WidevineKeySource::GetCryptoPeriodKey(uint32_t crypto_period_index,
261  TrackType track_type,
262  EncryptionKey* key) {
263  DCHECK(key_production_thread_.HasBeenStarted());
264  // TODO(kqyang): This is not elegant. Consider refactoring later.
265  {
266  base::AutoLock scoped_lock(lock_);
267  if (!key_production_started_) {
268  // Another client may have a slightly smaller starting crypto period
269  // index. Set the initial value to account for that.
270  first_crypto_period_index_ =
271  crypto_period_index ? crypto_period_index - 1 : 0;
272  DCHECK(!key_pool_);
273  key_pool_.reset(new EncryptionKeyQueue(crypto_period_count_,
274  first_crypto_period_index_));
275  start_key_production_.Signal();
276  key_production_started_ = true;
277  }
278  }
279  return GetKeyInternal(crypto_period_index, track_type, key);
280 }
281 
282 std::string WidevineKeySource::UUID() {
283  return "edef8ba9-79d6-4ace-a3c8-27dcd51d21ed";
284 }
285 
286 void WidevineKeySource::set_signer(scoped_ptr<RequestSigner> signer) {
287  signer_ = signer.Pass();
288 }
289 
290 void WidevineKeySource::set_key_fetcher(scoped_ptr<KeyFetcher> key_fetcher) {
291  key_fetcher_ = key_fetcher.Pass();
292 }
293 
294 Status WidevineKeySource::GetKeyInternal(uint32_t crypto_period_index,
295  TrackType track_type,
296  EncryptionKey* key) {
297  DCHECK(key_pool_);
298  DCHECK(key);
299  DCHECK_LE(track_type, NUM_VALID_TRACK_TYPES);
300  DCHECK_NE(track_type, TRACK_TYPE_UNKNOWN);
301 
302  scoped_refptr<RefCountedEncryptionKeyMap> ref_counted_encryption_key_map;
303  Status status =
304  key_pool_->Peek(crypto_period_index, &ref_counted_encryption_key_map,
305  kGetKeyTimeoutInSeconds * 1000);
306  if (!status.ok()) {
307  if (status.error_code() == error::STOPPED) {
308  CHECK(!common_encryption_request_status_.ok());
309  return common_encryption_request_status_;
310  }
311  return status;
312  }
313 
314  EncryptionKeyMap& encryption_key_map = ref_counted_encryption_key_map->map();
315  if (encryption_key_map.find(track_type) == encryption_key_map.end()) {
316  return Status(error::INTERNAL_ERROR,
317  "Cannot find key of type " + TrackTypeToString(track_type));
318  }
319  *key = *encryption_key_map[track_type];
320  return Status::OK;
321 }
322 
323 void WidevineKeySource::FetchKeysTask() {
324  // Wait until key production is signaled.
325  start_key_production_.Wait();
326  if (!key_pool_ || key_pool_->Stopped())
327  return;
328 
329  Status status = FetchKeysInternal(kEnableKeyRotation,
330  first_crypto_period_index_,
331  false);
332  while (status.ok()) {
333  first_crypto_period_index_ += crypto_period_count_;
334  status = FetchKeysInternal(kEnableKeyRotation,
335  first_crypto_period_index_,
336  false);
337  }
338  common_encryption_request_status_ = status;
339  key_pool_->Stop();
340 }
341 
342 Status WidevineKeySource::FetchKeysInternal(bool enable_key_rotation,
343  uint32_t first_crypto_period_index,
344  bool widevine_classic) {
345  std::string request;
346  FillRequest(enable_key_rotation,
347  first_crypto_period_index,
348  &request);
349 
350  std::string message;
351  Status status = GenerateKeyMessage(request, &message);
352  if (!status.ok())
353  return status;
354  VLOG(1) << "Message: " << message;
355 
356  std::string raw_response;
357  int64_t sleep_duration = kFirstRetryDelayMilliseconds;
358 
359  // Perform client side retries if seeing server transient error to workaround
360  // server limitation.
361  for (int i = 0; i < kNumTransientErrorRetries; ++i) {
362  status = key_fetcher_->FetchKeys(server_url_, message, &raw_response);
363  if (status.ok()) {
364  VLOG(1) << "Retry [" << i << "] Response:" << raw_response;
365 
366  std::string response;
367  if (!DecodeResponse(raw_response, &response)) {
368  return Status(error::SERVER_ERROR,
369  "Failed to decode response '" + raw_response + "'.");
370  }
371 
372  bool transient_error = false;
373  if (ExtractEncryptionKey(enable_key_rotation,
374  widevine_classic,
375  response,
376  &transient_error))
377  return Status::OK;
378 
379  if (!transient_error) {
380  return Status(
381  error::SERVER_ERROR,
382  "Failed to extract encryption key from '" + response + "'.");
383  }
384  } else if (status.error_code() != error::TIME_OUT) {
385  return status;
386  }
387 
388  // Exponential backoff.
389  if (i != kNumTransientErrorRetries - 1) {
390  base::PlatformThread::Sleep(
391  base::TimeDelta::FromMilliseconds(sleep_duration));
392  sleep_duration *= 2;
393  }
394  }
395  return Status(error::SERVER_ERROR,
396  "Failed to recover from server internal error.");
397 }
398 
399 void WidevineKeySource::FillRequest(bool enable_key_rotation,
400  uint32_t first_crypto_period_index,
401  std::string* request) {
402  DCHECK(request);
403  DCHECK(!request_dict_.empty());
404 
405  // Build tracks.
406  base::ListValue* tracks = new base::ListValue();
407 
408  base::DictionaryValue* track_sd = new base::DictionaryValue();
409  track_sd->SetString("type", "SD");
410  tracks->Append(track_sd);
411  base::DictionaryValue* track_hd = new base::DictionaryValue();
412  track_hd->SetString("type", "HD");
413  tracks->Append(track_hd);
414  base::DictionaryValue* track_audio = new base::DictionaryValue();
415  track_audio->SetString("type", "AUDIO");
416  tracks->Append(track_audio);
417 
418  request_dict_.Set("tracks", tracks);
419 
420  // Build DRM types.
421  base::ListValue* drm_types = new base::ListValue();
422  drm_types->AppendString("WIDEVINE");
423  request_dict_.Set("drm_types", drm_types);
424 
425  // Build key rotation fields.
426  if (enable_key_rotation) {
427  // Javascript/JSON does not support int64_t or unsigned numbers. Use double
428  // instead as 32-bit integer can be lossless represented using double.
429  request_dict_.SetDouble("first_crypto_period_index",
430  first_crypto_period_index);
431  request_dict_.SetInteger("crypto_period_count", crypto_period_count_);
432  }
433 
434  base::JSONWriter::WriteWithOptions(
435  request_dict_,
436  // Write doubles that have no fractional part as a normal integer, i.e.
437  // without using exponential notation or appending a '.0'.
438  base::JSONWriter::OPTIONS_OMIT_DOUBLE_TYPE_PRESERVATION, request);
439 }
440 
441 Status WidevineKeySource::GenerateKeyMessage(const std::string& request,
442  std::string* message) {
443  DCHECK(message);
444 
445  std::string request_base64_string;
446  base::Base64Encode(request, &request_base64_string);
447 
448  base::DictionaryValue request_dict;
449  request_dict.SetString("request", request_base64_string);
450 
451  // Sign the request.
452  if (signer_) {
453  std::string signature;
454  if (!signer_->GenerateSignature(request, &signature))
455  return Status(error::INTERNAL_ERROR, "Signature generation failed.");
456 
457  std::string signature_base64_string;
458  base::Base64Encode(signature, &signature_base64_string);
459 
460  request_dict.SetString("signature", signature_base64_string);
461  request_dict.SetString("signer", signer_->signer_name());
462  }
463 
464  base::JSONWriter::Write(request_dict, message);
465  return Status::OK;
466 }
467 
468 bool WidevineKeySource::DecodeResponse(
469  const std::string& raw_response,
470  std::string* response) {
471  DCHECK(response);
472 
473  // Extract base64 formatted response from JSON formatted raw response.
474  scoped_ptr<base::Value> root(base::JSONReader::Read(raw_response));
475  if (!root) {
476  LOG(ERROR) << "'" << raw_response << "' is not in JSON format.";
477  return false;
478  }
479  const base::DictionaryValue* response_dict = NULL;
480  RCHECK(root->GetAsDictionary(&response_dict));
481 
482  std::string response_base64_string;
483  RCHECK(response_dict->GetString("response", &response_base64_string));
484  RCHECK(base::Base64Decode(response_base64_string, response));
485  return true;
486 }
487 
488 bool WidevineKeySource::ExtractEncryptionKey(
489  bool enable_key_rotation,
490  bool widevine_classic,
491  const std::string& response,
492  bool* transient_error) {
493  DCHECK(transient_error);
494  *transient_error = false;
495 
496  scoped_ptr<base::Value> root(base::JSONReader::Read(response));
497  if (!root) {
498  LOG(ERROR) << "'" << response << "' is not in JSON format.";
499  return false;
500  }
501 
502  const base::DictionaryValue* license_dict = NULL;
503  RCHECK(root->GetAsDictionary(&license_dict));
504 
505  std::string license_status;
506  RCHECK(license_dict->GetString("status", &license_status));
507  if (license_status != kLicenseStatusOK) {
508  LOG(ERROR) << "Received non-OK license response: " << response;
509  *transient_error = (license_status == kLicenseStatusTransientError);
510  return false;
511  }
512 
513  const base::ListValue* tracks;
514  RCHECK(license_dict->GetList("tracks", &tracks));
515  // Should have at least one track per crypto_period.
516  RCHECK(enable_key_rotation ? tracks->GetSize() >= 1 * crypto_period_count_
517  : tracks->GetSize() >= 1);
518 
519  int current_crypto_period_index = first_crypto_period_index_;
520 
521  EncryptionKeyMap encryption_key_map;
522  for (size_t i = 0; i < tracks->GetSize(); ++i) {
523  const base::DictionaryValue* track_dict;
524  RCHECK(tracks->GetDictionary(i, &track_dict));
525 
526  if (enable_key_rotation) {
527  int crypto_period_index;
528  RCHECK(
529  track_dict->GetInteger("crypto_period_index", &crypto_period_index));
530  if (crypto_period_index != current_crypto_period_index) {
531  if (crypto_period_index != current_crypto_period_index + 1) {
532  LOG(ERROR) << "Expecting crypto period index "
533  << current_crypto_period_index << " or "
534  << current_crypto_period_index + 1 << "; Seen "
535  << crypto_period_index << " at track " << i;
536  return false;
537  }
538  if (!PushToKeyPool(&encryption_key_map))
539  return false;
540  ++current_crypto_period_index;
541  }
542  }
543 
544  std::string track_type_str;
545  RCHECK(track_dict->GetString("type", &track_type_str));
546  TrackType track_type = GetTrackTypeFromString(track_type_str);
547  DCHECK_NE(TRACK_TYPE_UNKNOWN, track_type);
548  RCHECK(encryption_key_map.find(track_type) == encryption_key_map.end());
549 
550  scoped_ptr<EncryptionKey> encryption_key(new EncryptionKey());
551 
552  if (!GetKeyFromTrack(*track_dict, &encryption_key->key))
553  return false;
554 
555  // Get key ID and PSSH data for CENC content only.
556  if (!widevine_classic) {
557  if (!GetKeyIdFromTrack(*track_dict, &encryption_key->key_id))
558  return false;
559 
560  std::vector<uint8_t> pssh_data;
561  if (!GetPsshDataFromTrack(*track_dict, &pssh_data))
562  return false;
563  encryption_key->pssh = PsshBoxFromPsshData(pssh_data);
564  }
565  encryption_key_map[track_type] = encryption_key.release();
566  }
567 
568  DCHECK(!encryption_key_map.empty());
569  if (!enable_key_rotation) {
570  encryption_key_map_ = encryption_key_map;
571  return true;
572  }
573  return PushToKeyPool(&encryption_key_map);
574 }
575 
576 bool WidevineKeySource::PushToKeyPool(
577  EncryptionKeyMap* encryption_key_map) {
578  DCHECK(key_pool_);
579  DCHECK(encryption_key_map);
580  Status status =
581  key_pool_->Push(scoped_refptr<RefCountedEncryptionKeyMap>(
582  new RefCountedEncryptionKeyMap(encryption_key_map)),
583  kInfiniteTimeout);
584  encryption_key_map->clear();
585  if (!status.ok()) {
586  DCHECK_EQ(error::STOPPED, status.error_code());
587  return false;
588  }
589  return true;
590 }
591 
592 } // namespace media
593 } // namespace edash_packager
WidevineKeySource(const std::string &server_url)
void set_signer(scoped_ptr< RequestSigner > signer)
Status GetKey(TrackType track_type, EncryptionKey *key) override
void set_key_fetcher(scoped_ptr< KeyFetcher > key_fetcher)
Status FetchKeys(const std::vector< uint8_t > &content_id, const std::string &policy) override
static std::vector< uint8_t > PsshBoxFromPsshData(const std::vector< uint8_t > &pssh_data)
Definition: key_source.cc:166
Status GetCryptoPeriodKey(uint32_t crypto_period_index, TrackType track_type, EncryptionKey *key) override
static TrackType GetTrackTypeFromString(const std::string &track_type_string)
Convert string representation of track type to enum representation.
Definition: key_source.cc:138
static std::string TrackTypeToString(TrackType track_type)
Convert TrackType to string.
Definition: key_source.cc:152