Protect HLS CloudFront streams with signed cookies instead of per-chunk signed URLs
A company uses HTTP Live Streaming (HLS) to stream live video content to paying subscribers by using Amazon CloudFront. HLS splits the video content into chunks so that the user can request the right chunk based on different conditions. Because the video events last for several hours, the total video is made up of thousands of chunks. The origin URL is not disclosed, and every user is forced to access the CloudFront URL. The company has a web application that authenticates the paying users against an internal repository and a CloudFront key pair that is already issued. What is the simplest and MOST effective way to protect the content?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
For content composed of many objects (like HLS chunks), signed cookies are far more efficient than signed URLs: one cookie set authorizes all requests to a path/pattern, whereas signed URLs would require generating a unique signed URL for every chunk. With a CloudFront key pair already issued, the app only needs to mint signed cookies post-authentication.
An HLS live stream served through CloudFront is split into thousands of chunks, and only authenticated subscribers should fetch them. Because a single video session requests thousands of objects, signing each chunk URL individually is wasteful. CloudFront signed cookies let the application set a small set of cookies once after authenticating the user, authorizing all chunk requests under a path without per-request URL generation.
Using signed URLs (option A) for HLS—generating a signed URL per chunk adds heavy overhead and complexity across thousands of requests. Lambda@Edge token checks (option C) or KMS URL hiding (option D) are more complex than necessary for this access-control need.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.