Digital rights management (DRM) solutions aim to prevent the copying or distribution of copyrighted material. On mobile devices, a variety of DRM technologies have become widely deployed. However, a detailed security study comparing their internal workings, and their strengths and weaknesses, remains missing in the existing literature. In this paper, we present the first detailed security analysis of mobile DRM systems, addressing the modern paradigm of cloud-based content delivery followed by major platforms, such as Netflix, Disney+, and Amazon Prime. We extensively analyse the security of three widely used DRM solutions -- Google Widevine, Apple FairPlay, and Microsoft PlayReady -- deployed on billions of devices worldwide. We then consolidate their features and capabilities, deriving common features and security properties for their evaluation. Furthermore, we identify some design-level shortcomings that render them vulnerable to emerging attacks within the state of the art, including micro-architectural side-channel vulnerabilities and an absence of post-quantum security. Lastly, we propose mitigations and suggest future directions of research.
翻译:数字版权管理(DRM)解决方案旨在防止对受版权保护材料的复制或分发。在移动设备上,各种DRM技术已被广泛部署。然而,现有文献中仍缺乏对其内部工作原理、优点及缺点进行详尽对比的安全性研究。本文首次对移动DRM系统进行详细的安全性分析,探讨了主流平台(如Netflix、Disney+和Amazon Prime)采用的现代基于云的内容分发范式。我们广泛分析了三种广泛使用的DRM解决方案——Google Widevine、Apple FairPlay和Microsoft PlayReady——这些方案已部署在全球数十亿台设备上。随后,我们整合了它们的特性与能力,并归纳出共性特征及安全属性以供评估。此外,我们识别出一些设计层面的缺陷,这些缺陷使其易受当前技术前沿中的新兴攻击(包括微架构侧信道漏洞和缺乏后量子安全性)的影响。最后,我们提出了缓解措施,并指出了未来的研究方向。