Video Protection Options in Boomstream: A Complete Guide
Boomstream offers several robust options for video protection. These settings are configured at the project level, meaning they automatically apply to all media files within that specific project.
1. DRM Video Protection (HLS AES-128 Encryption)
We use HLS AES-128 encryption to secure your content. This prevents downloaders from capturing the video file. Even if a file is intercepted, it cannot be played without the encrypted decryption key, which we deliver securely during playback.
Test our protection: You can try to download a video from our DRM video protection demo page to see how it works.
2. Disable Direct Links
If you only embed the player code and do not use direct links to video files, you can disable them to complicate downloading and restreaming. To do this, activate the "Disable direct links" option in your project settings.
⚠️ Important: Once activated, all existing direct links will immediately stop working. Ensure you are not using direct links anywhere on your website before enabling this.
3. Protection from Restreaming
Restreaming protection restricts the playback of your media files on unauthorized third-party resources, helping to prevent bandwidth theft and save you money. The system provides three advanced types of protection:
| Protection Type | Description |
|---|---|
| Domain Name | Restricts playback exclusively to your specified domains. |
| IP Address | Generates unique, user-specific links based on the viewer's IP address. |
| Time-Based | Generates temporary links that expire after a set duration. |
3.1. Protection by Domain Name
You specify the exact domain names where media playback is allowed.
- Enter domain names without the
https://orhttp://prefix. - Specify your top-level domains; all subdomains will work automatically.
Examples of valid domain names:
yandex.ru
google.com
video.mail.ru
3.2. Protection by IP Address
⚠️ Important: Implementing this protection requires backend changes on your website. You cannot simply copy and paste a static player code. Once enabled, all media file links and player codes will change, and previously published static videos will stop working.
⚠️ Note: This protection may conflict with services like Opera Turbo or other technologies that dynamically mask or change the user's IP address.
How it works: The system generates unique, hashed links for media files and player codes based on the viewer's IP address. If a user copies the player code or direct link to another site, it will not work for anyone else.
Parameters added to URLs:
<iframe width="640" height="356" src="https://play.boomstream.com/CODE?hash={{hash}}&width=640&height=356" frameborder="0" scrolling="no"></iframe>
Link formats:
https://bs.boomstream.com/balancer/hash:{{hash}}/CODE-CODE.mp4
https://bs.boomstream.com/balancer/hash:{{hash}}/CODE-CODE.flv
https://bs.boomstream.com/balancer/hash:{{hash}}/CODE-CODE/playlist.m3u8
Hash generation rule:
md5(API-key + "|" + user-IP + "|" + media code)
PHP code example:
$mediaCode = 'CODE';
$apiKey = '618db9c3934872221497e0a4f3c6290a';
$hash = md5($apiKey . '|' . getenv('REMOTE_ADDR') . '|' . $mediaCode);
$playerCode = '<iframe width="640" height="356" src="https://play.boomstream.com/'
. $mediaCode . '?hash=' . $hash
. '" frameborder="0" scrolling="no"></iframe>';
echo $playerCode;
3.3. Protection by Time (Expiring Links)
⚠️ Important: Implementing this protection requires backend changes on your website. You cannot simply copy and paste a static player code. Once enabled, all media file links and player codes will change, and previously published static videos will stop working.
How it works: The system generates temporary, time-limited links for media files and player codes. These links expire after a duration specified in your project settings. If a user copies the player code or direct link, it will become invalid and unplayable after the set time.
Parameters added to URLs:
<iframe width="640" height="356" src="https://play.boomstream.com/CODE?hash={{hash}}&time={{time}}&width=640&height=356" frameborder="0" scrolling="no"></iframe>
Link formats:
https://bs.boomstream.com/balancer/hash:{{hash}}/time:{{time}}/CODE-CODE.mp4
https://bs.boomstream.com/balancer/hash:{{hash}}/time:{{time}}/CODE-CODE.flv
https://bs.boomstream.com/balancer/hash:{{hash}}/time:{{time}}/CODE-CODE/playlist.m3u8
Hash generation rule:
md5(API-key + "|" + UNIX-TIMESTAMP + "|" + media code)
PHP code example:
$mediaCode = 'CODE';
$apiKey = '618db9c3934872221497e0a4f3c6290a';
$time = time();
$hash = md5($apiKey . '|' . $time . '|' . $mediaCode);
$playerCode = '<iframe width="640" height="356" src="https://play.boomstream.com/'
. $mediaCode . '?hash=' . $hash
. '&time=' . $time
. '" frameborder="0" scrolling="no"></iframe>';
echo $playerCode;
Summary of Protection Types
| Protection Type | How It Works | Implementation Complexity |
|---|---|---|
| DRM (AES-128) | Encrypts video files; requires key for playback | Simple (activate in settings) |
| Disable direct links | Prevents direct MP4 access | Simple (activate in settings) |
| Domain name | Restricts playback to specified domains | Simple (configure domains) |
| IP-based | Generates unique links per user IP | Requires programming (hash based on IP) |
| Time-based | Generates temporary links with expiration | Requires programming (hash based on timestamp) |
✅ Done!
You can now choose and implement the appropriate protection method(s) for your content based on your specific security and business needs.
