What is CENC Encryption?
Common Encryption (CENC) specifies a shared way to encrypt media in ISO Base Media File Format containers. The resulting segments can be used with multiple compatible digital rights management systems.
How CENC Encryption works
CENC separates encrypted sample storage from the DRM-specific license exchange used by a player. Encryption metadata in an ISO Base Media File Format package identifies protected tracks, key identifiers, and the scheme needed to decrypt samples, while system-specific initialization data can accompany the presentation. It fits between encoding and streaming packaging, enabling compatible players to consume common media bytes even though their license protocols and DRM implementations differ.
An encoder creates several quality levels, and a packager divides them into aligned segments referenced by a manifest. During playback, the client estimates throughput and buffer health, then requests an appropriate segment from one rendition at a time.
Streaming quality depends on the relationship between renditions, segments, manifests, players, and the network. A valid encode can still perform poorly if keyframes are misaligned, the ladder is inefficient, or the player cannot switch cleanly.
Key facts
- 1A key identifier selects the content key but is not the secret key itself. Packages and license services must agree on that mapping or decryption fails after successful manifest loading.
- 2The `cenc` scheme uses counter-mode sample encryption, while `cbcs` uses pattern-based cipher-block chaining; device and DRM support must match the scheme chosen during packaging.
- 3CENC defines media encryption and signaling, not viewer entitlement or license policy. A valid package still needs a compatible DRM client and reachable license service.
When CENC Encryption matters
Choose CENC when one DASH or CMAF package must serve players that rely on different DRM providers. Player, encryption scheme, and key-management compatibility must still be verified.
- Delivering long-form, episodic, educational, live, or user-generated video over variable networks.
- Providing low-bandwidth through high-resolution renditions from one master.
- Combining captions, alternate audio, encryption, thumbnails, and ad markers with playback media.
Working with streaming at scale
Guidance that holds across every streaming term in this glossary, not just CENC Encryption.
What you gain
- Segmented delivery lets playback begin without downloading the entire program.
- Multiple renditions let a player adapt quality as network and device conditions change.
- HTTP-based protocols can reuse ordinary web caching and delivery infrastructure.
What it costs
- Short segments can reduce switching and live latency but increase request and packaging overhead.
- A dense rendition ladder offers finer adaptation while increasing encoding, storage, and cache cost.
- More aggressive quality selection can improve sharpness but raises rebuffering risk on unstable networks.
Answer these before production
- 1Test the rendition ladder on slow, changing, and high-latency connections.
- 2Align segments and keyframes, then validate manifests in the target players.
- 3Measure startup, rebuffering, quality switches, CDN efficiency, and playback failures.
How Transloadit helps with CENC Encryption
When CENC Encryption is relevant to your workflow, you can hand the surrounding streaming work to Transloadit instead of maintaining the processing stack yourself. Transloadit can encode source video into adaptive HLS or MPEG-DASH packages with multiple quality levels, generate thumbnails and subtitles, and store or deliver the complete playback set.
Support for a specific codec, container, parameter, or combination can vary by Robot and processing stack. Check the linked documentation for the exact inputs and outputs available for your use case.