AS/NZS ISO/IEC 23078.3:2025 identically adopts ISO/IEC 23078-3:2024, which defines a technical solution for encrypting resources in digital publications (especially EPUB), effectively registering a device certificate to providers and securely delivering decryption keys to reading systems included in licenses tailored to specific devices
Table of contents
Header
About this publication
Preface
Foreword
Introduction
1 Scope
2 Normative references
3 Terms and definitions
4 Abbreviated terms
5 Overview
5.1 General
5.2 Protecting the publication
5.3 Licensing the publication
5.4 Reading the publication
5.4.1 General
5.4.2 Registering a device
5.4.3 Acquiring a device key-based license document
5.4.4 Decrypting a resource
5.5 Licensing workflows
5.5.1 General
5.5.2 Getting a protected publication
5.5.3 Transferring a protected publication
5.5.4 Register device certificate and update license document
6 License document
6.1 General
6.2 Content conformance
6.3 License information
6.3.1 General
6.3.2 Encryption (transmitting keys)
6.3.2.1 General
6.3.2.2 Profile
6.3.2.3 Content key
6.3.2.4 User key
6.3.2.5 Device key
6.3.3 Links (pointing to external resources)
6.3.3.1 General
6.3.3.2 Link object
6.3.3.3 Link relationships
6.3.4 Rights (identifying rights and restrictions)
6.3.5 User (identifying the user)
6.3.6 Signature (signing the license)
6.4 User key
6.4.1 General
6.4.2 Calculating the user key
6.4.3 Hints
6.4.4 Requirements for the user key and user passphrase
6.5 Signature and public key infrastructure
6.5.1 General
6.5.1.1 Validity of license document
6.5.1.2 Validity of a device certificate
6.5.2 Certificates
6.5.2.1 Provider certificates
6.5.2.2 Root certificate
6.5.2.3 Developer certificates
6.5.2.4 Device certificates
6.5.3 Canonical form of the license document
6.5.4 Generating the signature
6.5.5 Validating the certificate and signature
6.5.5.1 Validating the certificate
6.5.5.2 Validating the signature
6.6 Device key
6.6.1 General
6.6.2 Generating the device key
6.6.3 Recommendations for the device private key protection