Content over USB
You can take content to a screen with a USB drive, with no network and without touching the panel. So nobody can plug in just any drive and change what's on air, RDS signs the drives you generate: the screen only plays the ones carrying your company's signature, and only the files they were generated with.
Requires the RDS app 2.4.0 or newer on the screen. Older versions ignore USB security and play any drive you connect. Check the version in Devices → Version, and update from Downloads if needed.
How it works
- You enable USB security in your account and RDS creates a signing key for your company. Its private part never leaves our server.
- You download a signed drive from the panel, loaded with a playlist. The ZIP contains an
rds-contentfolder with the files, a list of those files (manifest.v2.json) and its signature (manifest.v2.sig). - You copy it to the root of the USB and plug it into the screen.
- The screen checks the signature and every file before using anything: if the drive belongs to your company and nothing has been changed, it plays it; if not, it rejects it and logs the reason.
Screens only carry the public part of the key, which can check signatures but cannot create them. They receive it from RDS when you link them and every time they sync.
Enabling USB security
Profile → USB → USB content security
- Tick Allow content over USB (signed drives only).
- Click Save. The first time, your company's signing key is generated (you'll see Signing key active: e1 and the fingerprint of the public key).
While it's off, screens behave as before: they play any USB drive. Once it's on, they only accept signed ones.
Generating the USB drive
In Profile → USB → Generate signed USB, choose Restrict to a playlist: the drive is downloaded already loaded with that playlist's files.
Unzip the ZIP and copy the rds-content folder to the root of the USB drive. Don't add, rename or edit anything inside it: the screen only plays the files listed in the signature, and rejects any file that has been changed. To change the content, edit the playlist and download the drive again.
Drives contain no key, only a signature. Someone who gets hold of a drive can play its content, but cannot create new drives for your screens.
Screens with no connection
A screen learns your company's public key when you link it, and on every sync. Link a screen at least once before installing it without a connection. A drive cannot give a key to a screen.
Playing and copying
- Play from the USB — in Offline mode, the screen plays the content straight from the drive as long as it stays connected.
- Copy to internal storage — the Copy USB content to the local folder option (the app's admin menu) keeps the content when you remove the drive. Copying always requires a valid signed drive, even if USB security is disabled, because the files stay on the device.
Drives created before the signing change
Drives generated before RDS moved to the current signature keep working until the date shown in Profile → USB. Download them again before then.
Regenerating the key
Profile → USB → Regenerate key
Use this if you believe the key has been compromised. Losing a drive does not require it: the drive contains no key. Bear in mind that:
- Drives created beforehand stop being valid: download them again.
- Drives created before the signing change stop being accepted immediately.
- Screens pick up the new key on their next sync. A screen with no connection needs to connect once, or be linked again.
If a drive doesn't play
The screen logs the reason (visible in the device logs and in the panel):
| Reason | What it means | What to do |
|---|---|---|
unsigned |
The drive has no signed rds-content folder |
Generate the drive from the panel and copy the whole folder |
bad_sig |
The signature doesn't match: the file list has been edited or damaged | Copy the rds-content folder again without modifying it |
bad_hash |
A file has been changed or replaced | Copy the rds-content folder again without modifying it |
key_mismatch |
The drive is signed with a different key from the screen's (you've regenerated the key) | Download the drive again, and let the screen sync |
no_public_key |
The screen doesn't have your company's key yet | Connect the screen to the network once, or link it again |
legacy_expired |
The drive was created before the signing change, and its deadline has passed | Download the drive again |
foreign_empresa |
The drive belongs to another company | Use a drive generated from your own account |
If the content is on the drive but nothing shows up, also check that the files are in a supported format. The screen displays a warning when it skips a file it can't decode (for example .avif on older devices).