Quantum-safe signature

Apple Presents Tamper-Proof Photo Format

Apple, Kamera
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Apple

With Apple Reference Image, iPhone photos are intended to be cryptographically verifiably authentic and unedited in the future.

Apple has presented a new, optional camera mode called “Apple Reference Image,” which is designed to make photos from the iPhone tamper-proof. The feature debuts on the main camera sensor of the iPhone 18 Pro and iPhone 18 Pro Max. According to Apple, the background is that freely available AI tools have become so powerful that real photos can hardly be distinguished from artificially generated or subsequently modified images – which is particularly problematic when a photo is intended to prove that an event actually took place.

Ad

Differentiation from previous approaches

Previous industry approaches, such as the C2PA standard, attach provenance information only after the shot is taken and document subsequent editing steps. In Apple’s assessment, this approach is vulnerable, as the chain can be manipulated retroactively at any point without viewers being able to detect it; additionally, associating a photo with a specific device or person could pose privacy risks, for example for photographers in dangerous situations.

Two protected processing steps

Instead, Apple Reference Image starts at the exact moment of capture. To achieve this, the image sensor is placed in a special, secured capture mode and cryptographically signs the captured image data immediately after capture, before manipulation by the firmware or the operating system is possible. In addition to the image data, metadata and a time window for the capture timestamp are also signed; the latter originates from a proprietary cryptographic timestamping service that the device fetches every 15 minutes on average via an existing connection mechanism.

A so-called secure digital negative is created from this data, which remains stored on the device. If the user wishes to generate a visible reference image from it, this negative is transmitted to Apple’s “Private Cloud Compute” (PCC) – a cloud infrastructure operated by Apple that the company claims is publicly verifiable, where neither Apple nor third parties can access the actual image data. There, the processing steps necessary for a visible photo, such as demosaicing and color correction, are carried out before the final image is digitally signed.

Ad

Quantum-safe signature and revocation option

For the final signature, Apple states that it uses a combined process of the classic RSA-3072 algorithm and ML-DSA-87, which is considered quantum-safe, in order to permanently ensure the integrity of the images even in the face of future, more powerful computers. Should it subsequently turn out that a sensor has been compromised, Apple states that both individual photos and all images from a specific sensor can be revoked; for this purpose, devices regularly download updated revocation lists against which every reference image is checked prior to display.

Anonymity for photographers

Unlike other systems, using Apple Reference Image does not require a public identity of a photographing person or institution to vouch for authenticity, according to the company. Instead, the signature takes place exclusively via Apple’s own signing service. Requests to the timestamping service also run via a procedure that hides the requesting device’s IP address, according to Apple. After processing, the original digital negative is automatically moved to the “Recently Deleted” folder and permanently removed after 30 days at the latest, unless it is backed up beforehand.

(Editorial Team)

Ad

Weitere Artikel