The content provider’s application sends both the content ID and the SPC to the content provider’s server.
The server uses the content ID to fetch the appropriate content key and initialization vector. The content
provider opens the SPC to extract the session key, the anti-replay seed, the integrity information, and the
authentication materials. Additionally, the SPC includes a secured version of the content ID as provided by the
application for best practice server verification.