Windows Media DRM
Windows Media DRM is a Digital Rights Management service for the Windows Media platform. It is designed to provide delivery of audio and/or video content over an IP network to a PC or other playback device in such a way that the distributor can control how that content is used.
WMDRM includes the following components:
- Windows Media Rights Manager (WMRM) SDK for packaging content and issuing licenses
- Windows Media Format SDK (WMF SDK) for building Windows applications which support DRM and the Windows Media format
- Windows Media DRM for Portable Devices (WMDRM-PD) for supporting offline playback on portable devices (Janus)
- Windows Media DRM for Network Devices (WMDRM-ND) for streaming protected content to devices attached to a home network (Cardea)
How it works
In May 2007 Microsoft published the network protocol behind its license acquisition mechanism. According to the specification, the client software obtains a 7 byte plain-text content key Kcontent from the license server. The server encrypts the key before transferring it to the client with a globally predefined 160-bit ECC key, ECC1. The server also sends a content key ID, unencrypted. The client then uses the Kcontent as an RC4 key to decrypt the licensed media stream.
As an anti-spoofing measure, additional fields such as playback rights and a random number are encrypted with three more predefined ECC key pairs either by the client or server software:
- client software ECC key pair KC,
- client machine ECC key pair KM,
- server software ECC key pair KS.
An analysis of version 2 of the DRM scheme in Windows Media Audio revealed that it was using a combination of elliptic curve cryptography key exchange, the DES block cipher, a custom block cipher dubbed MultiSwap (for MACs only), the RC4 stream cipher, and the SHA-1 hashing function.
Windows Media DRM is designed to be renewable, that is, it is designed on the assumption that it will be cracked and must be constantly updated by Microsoft. The result is that while the scheme has been cracked several times, it has usually not remained cracked for long.
Version 1 was released in April 1999 and supported basic business rules such as expiration dates. Version 2 was released in January 2003 and is also known as version 7.x and 9, to keep in sync with the equivalent versions of Windows Media Player. Version 3, better known as DRM v10, was released in 2004. Earlier versions of the system have cracks available, meaning content restricted with these versions can have the protections stripped. Version 10 was cracked in early 2005, but a software update was shortly pushed which sealed the relevant hole.
Generally, these sorts of cracks have all worked in the same way to a certain extent. Rather than break the encryption itself, which is infeasible, they hook or interfere with the "black box" component as it runs to dump out the content keys or the unencrypted content from memory. These sorts of techniques are countered by Microsoft via automated Windows Updates, which in turn the user may choose to avoid or cancel.
The content delivered with the WMDRM encryption is not universally accessible but limited to those users running Microsoft Windows. Microsoft has not reached other markets yet.
The open network protocol for digital rights management, [MS-DRM] from the MCPP collection, stipulates that software developers have a right to implement the protocol outside the Microsoft's development tools and environment.
Tools have been created to strip files of Windows Media DRM, enabling them to be played on non-Janus platforms. These tools typically were developed with one specific Individualized Blackbox Component (IBX) version in mind and rarely work on a version they were not explicitly designed for. Microsoft in addition to upgrading the IBX whenever it was cracked, also pursued legal action against those who developed and hosted these tools, driving the development and distribution even further underground and fragmenting it. These tools can be split into three categories: decrypter, key-finder, and all-in-one (finds the keys and then decrypts). Microsoft has been more successful in squashing the development and distribution of the tools capable of key finding than those that decrypt encoding, as is apparent by the continual existence of the SourceForge project FreeMe2.
Microsoft responded in several ways. First, on August 28, 2006 Microsoft released a new version of the IBX to prevent this particular tool from working. Microsoft also informed partners that they were working to further resolve this issue, given that allegedly the fix was also circumvented within days. Microsoft also issued takedown notices to Web site owners distributing FairUse4WM. Finally, on September 22, 2006, Microsoft filed a federal lawsuit against John Does 1–10 a/k/a "viodentia", hoping to identify the person or persons responsible. However, the operator of the highest-ranked mirror of the utility, James Holden, denies having received any such notices or threats. Unable to find the identity of Viodentia, in April 2007 Microsoft dropped the civil suits they had filed.
By October 16, 2006, distributors using the Windows Media DRM protection, such as Sky Anytime, were using a patched codec. On September 6, 2007, Microsoft updated IBX to version 11.0.6000.7000, in an attempt to thwart circumvention efforts by variants of the original program. And, as of November 28, 2007, DRM Removal under Windows XP on new installs or updated computers (i.e. those that already contain IBX version 11.0.6000.7000), is not possible without rolling back to Windows Media Player 10. In 2008 another patched version of FairUse4WM was released, allowing it to work with Windows Vista, and IBX versions lower than 11.0.6000.6324. In a ploy to confuse the abusers or software tools, Microsoft revisited the controversial 11.0.6000.6324 version number, releasing a new IBX version, but giving the file a deceptive older version number.
DRM Removal is a shareware software released in 2007, which allows to convert iTunes, WMA, WMV and other protected video and audio formats to their unprotected analogues. It runs under Windows XP/ Windows XP x64/Windows7/Windows 7 x64/Windows Vista/Windows Vista x64 and the trial limitation is 90 seconds of audio and 180 seconds of video conversion. It allows high speed conversion (in specifications it is mentioned that it can remove DRM from up to 16 audio files simultaneously).
DRMDBG is a key-finder, it extracts the keys by hooking an instance of Windows Media Player that it launches. There are several version available each targeting a specific version. The version released on March 3, 2009 supports IBX versions 11.0.6000.6324 and 11.0.6001.8000.
Mirakagi was one of the first key-finders; it is no longer in development.
- [MS-DRM]: Digital Rights Management License Acquisition Data Structure, Microsoft Development Network Library, rev. 2.0, March 14, 2008.
- Microsoft to Update Windows Media DRM, PC World, Aug 29, 2006 http://www.pcworld.com/article/126955/microsoft_to_update_windows_media_drm.html
- Hachman, Mark (August 26, 2006). "Microsoft To Issue Fix For DRM Stripper App". PC Magazine Online (Ziff Davis Publishing Holdings Inc.).
- "Engadget FairUse4WM strips Windows Media DRM!". Retrieved August 25, 2006.
- "Sky movies paused by DRM security flaw". Retrieved September 13, 2006.
- "Microsoft tells Web site owners to take down FairUse4WM". Retrieved September 17, 2006.
- "Microsoft sues Viodentia for copyright infringement". Retrieved September 26, 2006.
- "Microsoft Didn’t Issue Takedown Notices For FairUse4WM".
- "Microsoft drops case against FairUse4WM creator Viodentia". Retrieved April 23, 2007.
- "今的太鼓事情". October 22, 2009. Retrieved October 24, 2010.
- "Download the latest version of drmdbg.exe". Retrieved July 27, 2009.