Video Protection Options in Boomstream: A Complete Guide

Boomstream offers several robust options for video protection. These settings are configured at the project level, meaning they automatically apply to all media files within that specific project.


1. DRM Video Protection (HLS AES-128 Encryption)

We use HLS AES-128 encryption to secure your content. This prevents downloaders from capturing the video file. Even if a file is intercepted, it cannot be played without the encrypted decryption key, which we deliver securely during playback.

Test our protection: You can try to download a video from our DRM video protection demo page to see how it works.


If you only embed the player code and do not use direct links to video files, you can disable them to complicate downloading and restreaming. To do this, activate the "Disable direct links" option in your project settings.

⚠️ Important: Once activated, all existing direct links will immediately stop working. Ensure you are not using direct links anywhere on your website before enabling this.


3. Protection from Restreaming

Restreaming protection restricts the playback of your media files on unauthorized third-party resources, helping to prevent bandwidth theft and save you money. The system provides three advanced types of protection:

Protection Type Description
Domain Name Restricts playback exclusively to your specified domains.
IP Address Generates unique, user-specific links based on the viewer's IP address.
Time-Based Generates temporary links that expire after a set duration.

3.1. Protection by Domain Name

You specify the exact domain names where media playback is allowed.

  • Enter domain names without the https:// or http:// prefix.
  • Specify your top-level domains; all subdomains will work automatically.

Examples of valid domain names:

Text
yandex.ru
google.com
video.mail.ru

3.2. Protection by IP Address

⚠️ Important: Implementing this protection requires backend changes on your website. You cannot simply copy and paste a static player code. Once enabled, all media file links and player codes will change, and previously published static videos will stop working.

⚠️ Note: This protection may conflict with services like Opera Turbo or other technologies that dynamically mask or change the user's IP address.

How it works: The system generates unique, hashed links for media files and player codes based on the viewer's IP address. If a user copies the player code or direct link to another site, it will not work for anyone else.

Parameters added to URLs:

HTML
<iframe width="640" height="356" src="https://play.boomstream.com/CODE?hash={{hash}}&width=640&height=356" frameborder="0" scrolling="no"></iframe>

Link formats:

Bash
https://bs.boomstream.com/balancer/hash:{{hash}}/CODE-CODE.mp4
https://bs.boomstream.com/balancer/hash:{{hash}}/CODE-CODE.flv
https://bs.boomstream.com/balancer/hash:{{hash}}/CODE-CODE/playlist.m3u8

Hash generation rule:

Text
md5(API-key + "|" + user-IP + "|" + media code)

PHP code example:

Bash
$mediaCode = 'CODE';
$apiKey = '618db9c3934872221497e0a4f3c6290a';
$hash = md5($apiKey . '|' . getenv('REMOTE_ADDR') . '|' . $mediaCode);
$playerCode = '<iframe width="640" height="356" src="https://play.boomstream.com/'
 . $mediaCode . '?hash=' . $hash
 . '" frameborder="0" scrolling="no"></iframe>';
echo $playerCode;

⚠️ Important: Implementing this protection requires backend changes on your website. You cannot simply copy and paste a static player code. Once enabled, all media file links and player codes will change, and previously published static videos will stop working.

How it works: The system generates temporary, time-limited links for media files and player codes. These links expire after a duration specified in your project settings. If a user copies the player code or direct link, it will become invalid and unplayable after the set time.

Parameters added to URLs:

HTML
<iframe width="640" height="356" src="https://play.boomstream.com/CODE?hash={{hash}}&time={{time}}&width=640&height=356" frameborder="0" scrolling="no"></iframe>

Link formats:

Bash
https://bs.boomstream.com/balancer/hash:{{hash}}/time:{{time}}/CODE-CODE.mp4
https://bs.boomstream.com/balancer/hash:{{hash}}/time:{{time}}/CODE-CODE.flv
https://bs.boomstream.com/balancer/hash:{{hash}}/time:{{time}}/CODE-CODE/playlist.m3u8

Hash generation rule:

Text
md5(API-key + "|" + UNIX-TIMESTAMP + "|" + media code)

PHP code example:

Bash
$mediaCode = 'CODE';
$apiKey = '618db9c3934872221497e0a4f3c6290a';
$time = time();
$hash = md5($apiKey . '|' . $time . '|' . $mediaCode);
$playerCode = '<iframe width="640" height="356" src="https://play.boomstream.com/'
 . $mediaCode . '?hash=' . $hash
 . '&time=' . $time
 . '" frameborder="0" scrolling="no"></iframe>';
echo $playerCode;

Summary of Protection Types

Protection Type How It Works Implementation Complexity
DRM (AES-128) Encrypts video files; requires key for playback Simple (activate in settings)
Disable direct links Prevents direct MP4 access Simple (activate in settings)
Domain name Restricts playback to specified domains Simple (configure domains)
IP-based Generates unique links per user IP Requires programming (hash based on IP)
Time-based Generates temporary links with expiration Requires programming (hash based on timestamp)

✅ Done!

You can now choose and implement the appropriate protection method(s) for your content based on your specific security and business needs.