Rights Protection

Protect live playback. Preserve a path to investigate leaks.

Use Encrypted HLS or DASH with DRM to protect compatible playback, and add an invisible watermark to selected relayed output when later leak investigation matters. Enable only the protection each live route needs—and keep the CDN, player, and business systems that already fit your service.

CloudTV PlatformRoute-level protection
Enable only what each output needs
Compatible inputLive Media Core output
Encrypted HLSProtect HLS media deliveryCompatible playback and key-delivery flow
Keep your delivery choiceCloudTV CDN, your CDN, or another compatible destination
Independent controls

Encryption, DRM, and traceability remain separate choices on each live route.

Real-world protection needs

Start with the way your live content can be exposed.

A copied URL, an exposed media segment, an authorized playback session, and a leaked rebroadcast are different problems. Apply the control that matches the point where the risk appears.

01 · Protect HLS media delivery

Keep live HLS segments from being delivered in the clear.

When the playback format must remain HLS, but unencrypted media delivery is not acceptable.

A private or paid playback page can still expose the media requests made by its player. If the HLS output is delivered without encryption, copied segment requests can reveal the live media outside the intended viewing experience.

Enable Encrypted HLS on the selected Live Media Core output. The live route encrypts HLS media before delivery, while a compatible player uses the configured playback and key-delivery method to recover the stream. The protected output can continue through CloudTV CDN or another compatible CDN.

Best suited to Subscription live services, private events, licensed HLS delivery, education and enterprise streams, and services that must avoid unencrypted HLS media delivery.
  1. Live source
  2. Live Media Core
  3. Encrypted HLS output
  4. CloudTV or compatible CDN
  5. Compatible authorized player
02 · Control compatible DASH playback

Put a license-controlled playback path around premium live content.

When a reusable media address is not enough to express who and what may play the stream.

Premium, licensed, sports, broadcast, meeting, and enterprise services may need playback to follow a DRM and license policy supported by the target browser, device, or application—not just possession of a DASH address.

Enable DASH with DRM on a compatible live route. CloudTV prepares the protected DASH output for the configured DRM and license workflow, while the DRM-capable player completes the required license exchange before playback.

Best suited to Premium live services, licensed broadcasts, sports and event streaming, enterprise distribution, and applications with a defined DRM-capable device and player environment.
  1. Live source
  2. Live Media Core
  3. Protected DASH output
  4. DRM and license workflow
  5. DRM-capable player
03 · Investigate a leak after authorized playback

Keep a hidden trace when visible protection would damage the picture.

When a legitimate viewer, destination, or downstream partner may record, restream, or redistribute content after access has already been granted.

Encryption and DRM protect compatible delivery and playback, but they cannot make an authorized screen impossible to record or a downstream feed impossible to rebroadcast. A visible logo may also be unsuitable for premium, broadcast, education, or meeting content.

Add Invisible Watermarking to selected relayed output. Viewers receive a clean picture without a visible logo or overlay. If an unauthorized copy later appears, analysis of the redistributed signal and its delivery context can support investigation and help narrow the likely source.

Best suited to Licensed live events, premium broadcasts, confidential meetings, education, partner feeds, and any relayed live output where later leak investigation matters.
  1. Selected relay output
  2. Imperceptible trace added
  3. Authorized destination
  4. Redistributed copy appears
  5. Investigation support
04 · Apply the right control at each layer

Reduce access abuse without confusing it with content protection.

When a live service needs to address copied links, protected playback, and post-access redistribution at the same time.

A copied playback request is an access problem. An exposed HLS segment is a delivery problem. DRM-governed playback is a client and license problem. A recording made after valid access is a traceability problem. No single switch accurately covers all four.

Use Global Edge CDN Fingerprint authorization for selected playback requests, then add Encrypted HLS, DASH with DRM, or Invisible Watermarking only where the corresponding live route needs it. Each control remains independently configurable and visible in CloudTV Platform.

Best suited to Subscription and licensed services, premium live events, global distribution, reseller-operated services, and teams that need a clear separation between access control, protected playback, and leak investigation.
  1. Global Edge CDN access policyOptional Fingerprint authorization
  2. Compatible protected output
  3. Authorized playback
  4. Optional invisible trace
  5. Later investigation

Protect the right point

Different risks appear at different points in a live route.

Do not force every stream through the same security stack. Match the control to the part of delivery, playback, or redistribution that needs protection.

RiskControlWhere it actsProduct
HLS media delivered without encryptionEncrypted HLSOn a compatible Live Media Core HLS outputRights Protection
Playback must follow a DRM and license policyDASH with DRMAcross protected DASH output, license workflow, and compatible playerRights Protection
Authorized output is later recorded or redistributedInvisible WatermarkingInside selected Live Media Core relay outputRights Protection
These controls can be combined, but they do not replace one another. Authorization decides whether a request may continue. Encryption and DRM protect compatible delivery and playback. Invisible watermarking supports investigation after redistributed content is found.

Encrypted HLS

Protect HLS media while keeping the HLS delivery model.

Use Encrypted HLS when the service needs standard HLS-style segmented delivery but does not want the selected live media output delivered in the clear. Live Media Core produces the protected HLS output before it enters CloudTV CDN, an existing compatible CDN, or another destination.

  1. 01
    Select the live output

    Choose the HLS route that requires protected media delivery.

  2. 02
    Produce Encrypted HLS

    Live Media Core encrypts the selected live HLS output before delivery.

  3. 03
    Deliver through a compatible path

    Use CloudTV CDN or retain an existing CDN that supports the configured HLS delivery and key relationship.

  4. 04
    Play through the configured method

    The compatible authorized player obtains what it needs through the configured playback and key-delivery flow.

Selected live outputEncrypted HLS route
ManifestLive index
Media segments
Configured playbackCompatible player
CloudTV CDNorExisting compatible CDN

Encrypted HLS protects selected media delivery; it is not DRM and does not prevent screen recording, re-encoding, or redistribution after valid playback. Player and key-delivery compatibility must be confirmed for the project.

DASH with DRM

Connect compatible live playback to the license policy it requires.

Use DASH with DRM when the target browser, device, or application supports a defined DRM workflow and playback must follow a configured license policy. Live Media Core prepares the protected DASH output, and the compatible player completes the required license exchange before playback.

Protected mediaLive Media CoreDASH output
Configured controlDRM + license workflowProject-specific compatibility
Playback environmentDRM-capable playerBrowser · Device · Application

License request and response

  1. 01Confirm the playback environment

    Identify the target browsers, devices, applications, and DRM-capable players.

  2. 02Configure the protected DASH route

    Select the live output and connect it to the project’s compatible DRM and license workflow.

  3. 03Deliver the protected output

    Carry the protected DASH stream through CloudTV CDN or another compatible delivery network.

  4. 04Complete license-controlled playback

    The compatible player follows the configured license exchange before rendering the live stream.

DRM availability depends on the selected platform, player, device, license provider, and project configuration. DASH with DRM is not CDN Fingerprint authorization, and no DRM configuration can prevent every form of recording or redistribution after playback.

Invisible Watermarking

A hidden trace inside the live picture—not a logo on top of it.

Add an imperceptible traceability mark to selected relayed live output without changing the normal viewing experience. The mark is inserted inside the active Live Media Core route before the stream continues to CloudTV CDN, another CDN, or an authorized destination.

Clean live keynote broadcast frame with no visible watermark, logo, or overlay
No visible logo, corner mark, or overlay is added to the picture.

No visible logo, corner mark, or overlay is added to the picture.

  1. Selected relay output
  2. Invisible trace inside the live picture
  3. Authorized destination or viewer
  4. Redistributed sample found
  5. Trace analysis
  6. Investigation support

Invisible Watermarking is not visible branding, access authorization, or DRM. It supports investigation; it does not promise that every altered copy can be attributed automatically or that one mark alone identifies a specific viewer.

Build the protection route you actually need

Use one protection—or layer several without turning them into one opaque security switch.

Configure protection per live route in CloudTV Platform. One stream may need Encrypted HLS, another may use DASH with DRM, and a selected partner feed may require Invisible Watermarking. Global Edge CDN access policy can be added separately when copied or replayed playback requests are also a concern.

Private HLS event
  1. Live Media Core
  2. Encrypted HLS
  3. Existing compatible CDN
  4. Authorized HLS player
Premium application
  1. Live Media Core
  2. DASH with DRM
  3. CloudTV Global Edge CDN
  4. DRM-capable application
Licensed partner feed
  1. Selected Live Media Core relay
  2. Invisible Watermarking
  3. Partner destination
  4. Investigation path retained

Fit your existing delivery stack

Protect a compatible live output without replacing every system around it.

CloudTV Platform controls which protection is enabled on each route. Live Media Core produces the compatible protected output. Keep an existing CDN, player, application, license workflow, and business system where they remain suitable, or enable the corresponding CloudTV product only where the route needs it.

Required processing pathLive Media CoreProduces the compatible live output selected for protection
ProtectRights ProtectionEncrypted HLS · DASH with DRM · Invisible Watermarking
Delivery and playback choiceKeep compatible systems already in placeCloudTV CDN or another compatible CDN · Existing player, app, license workflow, or partner
CloudTV PlatformRoute configurationEnabled protectionHealthUsage
Required control plane

CloudTV Platform

Route configuration · Enabled protection · Health · Usage

Required processing path

Live Media Core

Compatible protected output · Selected relay watermarking

Optional CloudTV delivery

Global Edge CDN

Global delivery · Fingerprint authorization · Edge analytics

Optional client

Native SDK & Applications

Compatible playback · Application identity · Device policy

Optional business operations

Business Management

Content · Plans · Subscriptions · Customers · Devices

Optional transport

Resilient Transport

CloudTV RXT · TCP Boost for compatible playback routes

Optional subtitles

Live Subtitles

Speech recognition · Multilingual subtitle output

CloudTV Rights Protection does not require CloudTV Global Edge CDN. A protected output can continue through an existing compatible CDN or destination. A route that bypasses Live Media Core cannot add CloudTV encryption, DRM packaging, or invisible watermarking to that media. Customer-origin content that is already protected can still be delivered by Global Edge CDN without using CloudTV Rights Protection.

Plan the protection route

Tell us where the live content needs protection—and what must remain in place.

Share your live source, output format, target players and devices, existing CDN, DRM or license workflow, access model, content-rights requirements, and leak risks. We’ll help map Encrypted HLS, DASH with DRM, Invisible Watermarking, and any separate CDN access policy to the right points in the route.

Discuss your protection needs