Apple Reference Image signs pixels at the camera sensor and develops them inside Private Cloud Compute, bypassing C2PA's after-the-fact metadata
Apple's security blog details Reference Image, an opt-in capture mode on iPhone 18 Pro and Pro Max where the camera sensor gets its own cryptographic signing identity at manufacture and signs raw pixel data immediately on capture, with the Secure Enclave signing everything originating outside the sensor and an Apple timestamp service bounding capture time. The signed digital negative is then uploaded to Private Cloud Compute, which performs demosaicing, tone mapping and compression in a verifiable environment, runs a neural network authenticity confidence score, and signs the result with a hybrid MLDSA87-RSA-3072-PSS-SHA512 scheme for quantum resistance. Apple explicitly contrasts this with the C2PA industry approach, which attaches provenance metadata after capture rather than protecting the pipeline from the sensor forward.
↳ Follow the thread