Apple has provided new information about its efforts to ensure authentic, untampered-with photos taken on iPhone handsets can be identified, amid the influx of Artificial Intelligence tools that include the ability to generate or alter images with photorealistic results.
The Apple Reference Image technology was announced for the iPhone 18 Pro models during last week’s keynote event, is an advanced form of photographic authentication that guarantees the photo is real, was taken with an iPhone at a certain time, and had not been tampered with.
Apple is likening the sensor-level technology to the creation and development of a negative from a film camera which cannot have been tampered with.
In a security blog post today, Apple says: “Our solution hinges on splitting the Apple Reference Image process into two phases: creating a secure digital negative, and developing that negative into a reference image. Each phase receives our strongest protections.
“The creation of a secure digital negative begins with a secure boot of the camera sensor into a specialized reference capture mode. The mode instructs the sensor to cryptographically sign pixel data immediately after capture, and prevents the sensor firmware from modifying the data. This creates a hardware-enforced assurance that the operating system receives pixel data exactly as the hardware sensor captured it, preventing injection or tampering attacks.”
The metadata created by the image, such as the timestamp, is also signed when the with the pixel data captured by the sensor. Off sensor data (zoom, boundaries, focal length) is signed off via the Secure Enclave Processor. That closes off another window for tampering.
Apple reckons the “real world assurance needed” beyond a timestamp is also catered for. “Apple Reference Image both a lower bound and an upper bound on capture time from Apple’s cryptographic timestamp service, and we guarantee the photo was taken between the two bounds,” the company said.
When it is time for the negative to be “developed” it is sent to Private Cloud Compute to render the image and verify its authenticity. “These are the same extraordinary guarantees we make for how PCC protects the privacy of Apple Intelligence requests,” Apple says.
The company explains further how the technology is resistant to compromise and how the privacy of photographers can be protected. It’s very detailed, so head over for a look.
Read the full article here
