Security for camera sensor manipulation

By cryptographically verifying camera identities and attributes, the system prevents unauthorized swaps, ensuring appropriate cameras are connected to specific ports, thereby enhancing security and maintaining operational integrity.

WO2026050036A1PCT designated stage Publication Date: 2026-03-05QUALCOMM INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/042474
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-25
Filing Date
2025-08-18
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Vehicle cameras are vulnerable to attacks involving physical swapping and software exploitation of camera credentials, leading to potential safety risks due to mismatched capabilities during critical operations.

Method used

Implement systems that cryptographically verify the identity of connected cameras by using stored keys and attributes to detect and reject unauthorized swaps, ensuring appropriate cameras are bound to specific ports.

Benefits of technology

Enhances security by preventing unauthorized camera swaps, maintaining operational integrity and safety in systems that rely on camera capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025042474_05032026_PF_FP_ABST
    Figure US2025042474_05032026_PF_FP_ABST
Patent Text Reader

Abstract

Systems and techniques are described for camera sensor security. For example, a computing device can receive, on a port of the computing device from a first camera, encrypted information and / or information associated with the first camera. In some cases, the computing device can determine that the computing device is unable to decrypt the encrypted information using a key stored at the computing device. In some cases, the computing device can determine the information does not match attributes of a second camera. The computing device can determine, based on determining that the computing device is unable to decrypt the encrypted information using the key and / or based on the information not matching the attributes of the second camera, that the first camera is connected to the port of the computing device that previously had the second camera connected. The computing device can reject the first camera for operation using the port.
Need to check novelty before this filing date? Find Prior Art

Description

PATENTQualcomm Ref. No. 2403790WO1SECURITY FOR CAMERA SENSOR MANIPULATIONFIELD

[0001] The present disclosure generally relates to camera sensor security. For example, aspects of the present disclosure relate to security systems and techniques for guarding against camera sensor manipulation (e.g., automotive camera sensor manipulation or other type of camera sensor manipulation).BACKGROUND

[0002] The increasing versatility of digital camera products has allowed digital cameras to be integrated into a wide array of devices and has expanded their use to different applications. For example, vehicles, drones, phones, computers, televisions, and many other devices today are often equipped with camera devices. The camera devices allow users to capture images and / or video (e.g., including frames of images) from any system equipped with a camera device. The images and / or videos can be captured for autonomous driving, recreational use, professional photography, surveillance, and automation, among other applications.

[0003] Vehicle cameras (e.g., image sensors) may be vulnerable to an attack that is a combination of physical attack, where the cameras connected to system on a chip (SOC) ports are physically swapped, and a software exploitation in camera sensor manager software that also swaps the cameras’ credentials in a way such that the SOC will still successfully authenticate the swapped cameras.SUMMARY

[0004] The following presents a simplified summary relating to one or more aspects disclosed herein. Thus, the following summary should not be considered an extensive overview relating to all contemplated aspects, nor should the following summary be considered to identify key or critical elements relating to all contemplated aspects or to delineate the scope associated with any particular aspect. Accordingly, the following summary has the sole purpose to present certain concepts relating to one or more aspects relating to the mechanisms disclosed herein in a simplified form to precede the detailed description presented below.PATENTQualcomm Ref. No. 2403790WO2

[0005] Systems and techniques are described herein for camera sensor security. In some aspects, an apparatus is provided for determining a camera swap at the apparatus. The apparatus includes a memory and a processor coupled to the memory and configured to: receive, on a port of the apparatus from a first camera, encrypted information; determine that the apparatus is unable to decrypt the encrypted information using a key stored at the apparatus; determine, based on determining that the apparatus is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the apparatus that previously had a second camera connected; and reject the first camera for operation using the port.

[0006] In some aspects, a method is provided for determining a camera swap at a device. The method includes: receiving, on a port of the device from a first camera, encrypted information; determining that the device is unable to decrypt the encrypted information using a key stored at the device; determining, based on determining that the device is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the device that previously had a second camera connected; and rejecting the first camera for operation using the port.

[0007] In some aspects, a non-transitory computer-readable medium of a device is provided having stored thereon instructions that, when executed by at least one processor, cause the at least one processor to: receive, on a port of the device from a first camera, encrypted information; determine that the device is unable to decrypt the encrypted information using a key stored at the device; determine, based on determining that the device is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the device that previously had a second camera connected; and reject the first camera for operation using the port.

[0008] In some aspects, an apparatus is provided for determining a camera swap at the apparatus. The apparatus includes: means for receiving, via a port of the device from a first camera, encrypted information; means for determining that the device is unable to decrypt the encrypted information using a key stored at the device; means for determining, based on determining that the device is unable to decrypt the encrypted information using the key, thatPATENTQualcomm Ref. No. 2403790WO3 the first camera is connected to the port of the device that previously had a second camera connected; and means for rejecting the first camera for operation using the port.

[0009] In some aspects, an apparatus is provided for determining a camera swap at the apparatus. The apparatus includes a memory and a processor coupled to the memory and configured to: receive, on a port of the apparatus from a first camera, information associated with the first camera; determine the information does not match attributes of a second camera; determine, based on the information not matching the attributes of the second camera, the first camera is connected to the port of the apparatus that previously had the second camera connected; and reject the first camera for operation using the port.

[0010] In some aspects, a method is provided for determining a camera swap at a device. The method includes: receiving, on a port of the device from a first camera, information associated with the first camera; determining the information does not match attributes of a second camera; determining, based on the information not matching the attributes of the second camera, the first camera is connected to the port of the device that previously had the second camera connected; and rejecting the first camera for operation using the port.

[0011] In some aspects, a non-transitory computer-readable medium of a device is provided having stored thereon instructions that, when executed by at least one processor, cause the at least one processor to: receive, on a port of the device from a first camera, information associated with the first camera; determine the information does not match attributes of a second camera; determine, based on the information not matching the attributes of the second camera, the first camera is connected to the port of the device that previously had the second camera connected; and reject the first camera for operation using the port.

[0012] In some aspects, an apparatus is provided for determining a camera swap at the apparatus. The apparatus includes: means for receiving, via a port of the device from a first camera, information associated with the first camera; means for determining the information does not match attributes of a second camera; means for determining, based on the information not matching the attributes of the second camera, the first camera is connected to the port ofPATENTQualcomm Ref. No. 2403790WO4 the device that previously had the second camera connected; and means for rejecting the first camera for operation using the port

[0013] Aspects generally include a method, apparatus, system, computer program product, non-transitory computer-readable medium, user device, user equipment, wireless communication device, and / or processing system as substantially described with reference to and as illustrated by the drawings and specification.

[0014] In some aspects, the apparatus is, includes, or is part of, a vehicle (e.g., an automobile, truck, etc., or a component or system of an automobile, truck, etc.), a mobile device (e.g., a mobile telephone or so-called “smart phone” or other mobile device), a wearable device, an extended reality device (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a personal computer, a laptop computer, a server computer, a robotics device, or other device. In some aspects, the apparatus includes at least one camera for capturing one or more images or video frames. In some aspects, the apparatus includes an image sensor (e.g., a camera) or multiple image sensors (e.g., multiple cameras) for capturing one or more images. In some aspects, the apparatus includes one or more displays for displaying one or more images, notifications, and / or other displayable data. In some aspects, the apparatus includes a transmitter configured to transmit one or more video frame and / or syntax data over a transmission medium to at least one device. In some aspects, the processor includes a neural processing unit (NPU), a central processing unit (CPU), a graphics processing unit (GPU), or other processing device or component.

[0015] While aspects are described in the present disclosure by illustration to some examples, those skilled in the art will understand that such aspects may be implemented in many different arrangements and scenarios. Techniques described herein may be implemented using different platform types, devices, systems, shapes, sizes, and / or packaging arrangements. For example, some aspects may be implemented via integrated chip embodiments or other nonmodule-component based devices (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, and / or artificial intelligence devices). Aspects may be implemented in chip-level components,PATENTQualcomm Ref. No. 2403790WO5 modular components, non-modular components, non-chip-level components, device-level components, and / or system-level components. Devices incorporating described aspects and features may include additional components and features for implementation and practice of claimed and described aspects. For example, transmission and reception of wireless signals may include one or more components for analog and digital purposes (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, adders, and / or summers). It is intended that aspects described herein may be practiced in a wide variety of devices, components, systems, distributed arrangements, and / or end-user devices of varying size, shape, and constitution.

[0016] The foregoing has outlined rather broadly the features and technical advantages of examples according to the disclosure in order that the detailed description that follows may be better understood. Additional features and advantages will be described hereinafter. The conception and specific examples disclosed may be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes of the present disclosure. Such equivalent constructions do not depart from the scope of the appended claims. Characteristics of the concepts disclosed herein, both their organization and method of operation, together with associated advantages will be better understood from the following description when considered in connection with the accompanying figures. Each of the figures is provided for the purposes of illustration and description, and not as a definition of the limits of the claims. The foregoing, together with other features and aspects, will become more apparent upon referring to the following specification, claims, and accompanying drawings.

[0017] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification of this patent, any or all drawings, and each claim.

[0018] The preceding, together with other features and embodiments, will become more apparent upon referring to the following specification, claims, and accompanying drawings.PATENTQualcomm Ref. No. 2403790WO6BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Illustrative aspects of the present application are described in detail below with reference to the following figures:

[0020] FIG. l is a block diagram illustrating an example architecture of an image capture and processing system, in accordance with some aspects of the disclosure.

[0021] FIG. 2 is a block diagram illustrating an example of interactions between components of an image capture and processing system, in accordance with some aspects of the disclosure.

[0022] FIG. 3 is a diagram illustrating an example of a system for guarding against camera sensor manipulation, where camera sensors are connected to their associated respective ports of an SOC, in accordance with some aspects of the disclosure.

[0023] FIG. 4 is a diagram illustrating an example of a system for guarding against camera sensor manipulation, where the camera sensors have been swapped and are not connected to their associated respective ports of an SOC, in accordance with some aspects of the disclosure.

[0024] FIG. 5A is a flow diagram illustrating an example of a process for camera sensor security, in accordance with some aspects of the disclosure.

[0025] FIG. 5B is a flow diagram illustrating another example of a process for camera sensor security, in accordance with some aspects of the disclosure.

[0026] FIG. 6 is a diagram illustrating an example of a system for implementing certain aspects described herein.DETAILED DESCRIPTION

[0027] Certain aspects of this disclosure are provided below for illustration purposes. Alternate aspects may be devised without departing from the scope of the disclosure. Additionally, well-known elements of the disclosure will not be described in detail or will be omitted so as not to obscure the relevant details of the disclosure. Some of the aspects describedPATENTQualcomm Ref. No. 2403790WO7 herein can be applied independently and some of them may be applied in combination as would be apparent to those of skill in the art. In the following description, for the purposes of explanation, specific details are set forth in order to provide a thorough understanding of aspects of the application. However, it will be apparent that various aspects may be practiced without these specific details. The figures and description are not intended to be restrictive.

[0028] The ensuing description provides example aspects only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the example aspects will provide those skilled in the art with an enabling description for implementing an example aspect. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the application as set forth in the appended claims.

[0029] The terms “exemplary” and / or “example” are used herein to mean “serving as an example, instance, or illustration.” Any aspect described herein as “exemplary” and / or “example” is not necessarily to be construed as preferred or advantageous over other aspects. Likewise, the term “aspects of the disclosure” does not require that all aspects of the disclosure include the discussed feature, advantage or mode of operation.

[0030] As previously mentioned, the increasing versatility of digital camera products has allowed for digital cameras to be implemented into a wide array of devices and has expanded their use to different applications. Currently, for example, vehicles, drones, phones, computers, televisions, and many other devices are generally equipped with camera devices. The camera devices allow users to capture images and / or video from any system (e.g., vehicle system) equipped with a camera device. The images and / or videos may be captured for autonomous driving, for safety purposes, recreational use, professional photography, surveillance, and automation, among other applications. For instance, vehicles can include multiple cameras that can capture images for driving purposes. In one example, cameras of a vehicle can capture images that are used to determine autonomous or semi-autonomous actions to perform, such as automatic braking, automating lane-change maneuvers, among others.PATENTQualcomm Ref. No. 2403790WO8

[0031] In an example scenario, a vehicle may include two cameras (e.g., two image sensors), including a first camera (e.g., Camera 1) and a second camera (e.g., Camera 2). The vehicle may also include additional cameras. Each of the first and second cameras can have its own respective capabilities such that Camera 1 has a first capability (e.g., capability 1) and Camera 2 has a second capability (e.g., capability 2). Each of the cameras may be connected to a respective associated port on an SOC such that Camera 1 is connected to SOC port 1 and Camera 2 is connected to SOC port 2. In one or more examples, each camera (e.g., Camera 1 and Camera 2) may be connected to their associated respective SOC port via in-vehiclenetwork or wired plumbing, such as via in-vehicle-network 1 and in-vehicle-network 2, respectively.

[0032] In some cases, the two cameras may appear identical and have near-identical features according to available documents (e.g., the cameras’ technical specifications). The configuration of the cameras (e.g., Camera 1 and Camera 2) attached to their associated respective SOC ports (e.g., SOC port 1 and SOC port 2) is typically fixed during the time of manufacture. However, the cameras (e.g., camera modules) may be removed from the ports and retrofitted as required (e.g., due to a camera failing as a result of its end of life). Each camera can have legitimate security credentials (e.g., a certificate and / or a pre-shared key (PSK)). During runtime, the SOC can set up separate secure camera security extension (CSE) sessions to each camera, which can include the establishment of traffic keys (TKs) (e.g., TK1 and TK2) in each camera (e.g., Camera 1 and Camera 2). Each camera can protect its own camera stream by using its own respective associated TK.

[0033] In one or more cases, the vehicle cameras (e.g., image sensors) can be vulnerable to an attack that is a combination of physical attack, where the cameras connected to the SOC ports are physically swapped, and a software attack, where the cameras’ credentials (e.g., certificates, PSKs, and / or TKs) are also swapped in the camera sensor manager software in a way such that the SOC will still successfully authenticate each of the swapped cameras. In some cases, the SOC may detect an unexpected operation (e.g., detect a lower data rate than expected) with a given camera attached to a given port. However, the SOC may not detect the camera swap. In particular, one camera attached to a specific port (e.g., behind which is aPATENTQualcomm Ref. No. 2403790WO9 safety-critical operation, such as an autonomous driving software stack) may be lacking a capability (e.g., not capable of high resolution) that only arises in a specific use case that is infrequent, and in that use case, the camera (e.g., lacking high resolution) can cause a safety concern.

[0034] As such, improved systems and techniques that allow for a SOC to identity the presence of a different and unexpected camera connected to one of the SOC’s ports can be benefici l.

[0035] In one or more aspects, systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively referred to herein as “systems and techniques”) are described herein for providing security guarding against camera sensor manipulation, such as automotive camera sensor manipulation or other type of camera sensor manipulation. In one or more examples, the systems and techniques allow for an SOC to be able to cryptographically identify the presence of a different and unexpected camera connected to one of the SOC’s physical ports. In such examples, the systems and techniques allow for the SOC to have the ability to bind an appropriate camera (e.g., a camera with appropriate capabilities for the software stack associated with a specific port) to a specific physical port of the SOC.

[0036] In one or more aspects, during operation of the systems and techniques for determining a camera swap at a device, a port of a device can receive, from a first camera, encrypted information. The device, based on a key stored at the device, can attempt to decrypt the encrypted information to produce decrypted information. The device, based on determining the key is unable to decrypt the encrypted information to produce the decrypted information, can determine that the first camera is connected to the port of the device that previously had a second camera connected.

[0037] In one or more examples, the key can be associated with the second camera. In some examples, the key can be a traffic key (TK), a random number, generated by the device using a key derivation function (KDF) based on the random number, or generated by the device using the KDF based on the random number and the TK. In one or more examples, the TK can bePATENTQualcomm Ref. No. 2403790WO10 pre-programmed into the device during manufacturing of the device. In some examples, the random number can be generated during runtime operation of the device.

[0038] In some examples, the device, based on one or more other keys stored at the device, can attempt to decrypt the encrypted information to produce decrypted information. In one or more examples, the device, based on determining one other key of the one or more other keys is able to decrypt the encrypted information to produce the decrypted information, can determine an identity of the first camera connected to the port of the device. In some examples, the decrypted information can include data obtained by the first camera and a message authentication code (MAC) associated with the first camera. In one or more examples, the device can be an SOC.

[0039] In one or more examples, during operation of the systems and techniques for determining a camera swap at a device, a port of the device can receive, from a first camera, information associated with the first camera. The device, based on the information not matching attributes of a second camera, can determine that the first camera is connected to the port of the device that previously had the second camera connected.

[0040] In some examples, the information associated with the first device can include sensor-specific information associated with the first camera or a certificate comprising the sensor-specific information associated with the first camera. In one or more examples, the sensor-specific information can include capabilities associated with the first camera, a manufacturer of the first camera, a make of the first camera, a model of the first camera, a serial number of the first camera, and / or a unique identifier UID) of the first camera. In some examples, the capabilities can include a resolution of the first camera and / or a maximum frame rate of the first camera.

[0041] In one or more examples, the information can include a random number. In some examples, fuses of the device and the first camera can be blown based on the random number. In one or more examples, the device can receive a license authorizing replacement of the first camera on the port of the device with another camera.PATENTQualcomm Ref. No. 2403790WO11

[0042] In some examples, the device, based on the information, can determine an identity of the first camera connected to the port of the device. In one or more examples, the device can send, to the first camera, a request for the information associated with the first camera. In some examples, the device can be an SOC.

[0043] Additional aspects of the present disclosure are described in more detail below.

[0044] FIG. 1 is a block diagram illustrating an architecture of an image capture and processing system 100. The image capture and processing system 100 includes various components that are used to capture and process images of scenes (e.g., an image of a scene 110). The image capture and processing system 100 can capture standalone images (or photographs) and / or can capture videos that include multiple images (or video frames) in a particular sequence. A lens 115 of the system 100 faces a scene 110 and receives light from the scene 110. The lens 115 bends the light toward the image sensor 130. The light received by the lens 115 passes through an aperture controlled by one or more control mechanisms 120 and is received by an image sensor 130.

[0045] The one or more control mechanisms 120 may control exposure, focus, and / or zoom based on information from the image sensor 130 and / or based on information from the image processor 150. The one or more control mechanisms 120 may include multiple mechanisms and components; for instance, the control mechanisms 120 may include one or more exposure control mechanisms 125A, one or more focus control mechanisms 125B, and / or one or more zoom control mechanisms 125C. The one or more control mechanisms 120 may also include additional control mechanisms besides those that are illustrated, such as control mechanisms controlling analog gain, flash, HDR, depth of field, and / or other image capture properties.

[0046] The focus control mechanism 125B of the control mechanisms 120 can obtain a focus setting. In some examples, focus control mechanism 125B store the focus setting in a memory register. Based on the focus setting, the focus control mechanism 125B can adjust the position of the lens 115 relative to the position of the image sensor 130. For example, based on the focus setting, the focus control mechanism 125B can move the lens 115 closer to the image sensor 130 or farther from the image sensor 130 by actuating a motor or servo, therebyPATENTQualcomm Ref. No. 2403790WO12 adjusting focus. In some cases, additional lenses may be included in the device 105 A, such as one or more microlenses over each photodiode of the image sensor 130, which each bend the light received from the lens 115 toward the corresponding photodiode before the light reaches the photodiode. The focus setting may be determined via contrast detection autofocus (CDAF), phase detection autofocus (PDAF), or some combination thereof. The focus setting may be determined using the control mechanism 120, the image sensor 130, and / or the image processor 150. The focus setting may be referred to as an image capture setting and / or an image processing setting.

[0047] The exposure control mechanism 125A of the control mechanisms 120 can obtain an exposure setting. In some cases, the exposure control mechanism 125 A stores the exposure setting in a memory register. Based on this exposure setting, the exposure control mechanism 125A can control a size of the aperture (e.g., aperture size or f / stop), a duration of time for which the aperture is open (e.g., exposure time or shutter speed), a sensitivity of the image sensor 130 (e.g., ISO speed or film speed), analog gain applied by the image sensor 130, or any combination thereof. The exposure setting may be referred to as an image capture setting and / or an image processing setting.

[0048] The zoom control mechanism 125C of the control mechanisms 120 can obtain a zoom setting. In some examples, the zoom control mechanism 125C stores the zoom setting in a memory register. Based on the zoom setting, the zoom control mechanism 125C can control a focal length of an assembly of lens elements (lens assembly) that includes the lens 115 and one or more additional lenses. For example, the zoom control mechanism 125C can control the focal length of the lens assembly by actuating one or more motors or servos to move one or more of the lenses relative to one another. The zoom setting may be referred to as an image capture setting and / or an image processing setting. In some examples, the lens assembly may include a parfocal zoom lens or a varifocal zoom lens. In some examples, the lens assembly may include a focusing lens (which can be lens 115 in some cases) that receives the light from the scene 110 first, with the light then passing through an afocal zoom system between the focusing lens (e.g., lens 115) and the image sensor 130 before the light reaches the image sensor 130. The afocal zoom system may, in some cases, include two positive (e.g., converging,PATENTQualcomm Ref. No. 2403790WO13 convex) lenses of equal or similar focal length (e.g., within a threshold difference) with a negative (e.g., diverging, concave) lens between them. In some cases, the zoom control mechanism 125C moves one or more of the lenses in the afocal zoom system, such as the negative lens and one or both of the positive lenses.

[0049] The image sensor 130 includes one or more arrays of photodiodes or other photosensitive elements. Each photodiode measures an amount of light that eventually corresponds to a particular pixel in the image produced by the image sensor 130. In some cases, different photodiodes may be covered by different color fdters, and may thus measure light, matching the color of the filter covering the photodiode. For instance, Bayer color filters include red color filters, blue color filters, and green color filters, with each pixel of the image generated based on red light data from at least one photodiode covered in a red color filter, blue light data from at least one photodiode covered in a blue color filter, and green light data from at least one photodiode covered in a green color filter. Other types of color filters may use yellow, magenta, and / or cyan (also referred to as “emerald”) color filters instead of or in addition to red, blue, and / or green color filters. Some image sensors may lack color filters altogether, and may instead use different photodiodes throughout the pixel array (in some cases vertically stacked). The different photodiodes throughout the pixel array can have different spectral sensitivity curves, therefore responding to different wavelengths of light. Monochrome image sensors may also lack color filters and therefore lack color depth.

[0050] In some cases, the image sensor 130 may alternately or additionally include opaque and / or reflective masks that block light from reaching certain photodiodes, or portions of certain photodiodes, at certain times and / or from certain angles, which may be used for phase detection autofocus (PDAF). The image sensor 130 may also include an analog gain amplifier to amplify the analog signals output by the photodiodes and / or an analog to digital converter (ADC) to convert the analog signals output of the photodiodes (and / or amplified by the analog gain amplifier) into digital signals. In some cases, certain components or functions discussed with respect to one or more of the control mechanisms 120 may be included instead or additionally in the image sensor 130. The image sensor 130 may be a charge-coupled device (CCD) sensor, an electron-multiplying CCD (EMCCD) sensor, an active-pixel sensor (APS),PATENTQualcomm Ref. No. 2403790WO14 a complimentary metal-oxide semiconductor (CMOS), an N-type metal-oxide semiconductor (NMOS), a hybrid CCD / CMOS sensor (e.g., sCMOS), or some other combination thereof.

[0051] The image processor 150 may include one or more processors, such as one or more image signal processors (ISPs) (including ISP 1 4), one or more host processors (including host processor 152), and / or one or more of any other type of processor 610 discussed with respect to the computing system 600. The host processor 152 can be a digital signal processor (DSP) and / or other type of processor. In some implementations, the image processor 150 is a single integrated circuit or chip (e g., referred to as a system-on-chip or SoC) that includes the host processor 152 and the ISP 154. In some cases, the chip can also include one or more input / output ports (e.g., input / output (I / O) ports 156), central processing units (CPUs), graphics processing units (GPUs), broadband modems (e.g., 3G, 4G or LTE, 5G, etc.), memory, connectivity components (e.g., Bluetooth™, Global Positioning System (GPS), etc.), any combination thereof, and / or other components. The I / O ports 156 can include any suitable input / output ports or interface according to one or more protocol or specification, such as an Inter-Integrated Circuit 2 (I2C) interface, an Inter-Integrated Circuit 3 (I3C) interface, a Serial Peripheral Interface (SPI) interface, a serial General Purpose Input / Output (GPIO) interface, a Mobile Industry Processor Interface (MIPI) (such as a MIPI CSI-2 physical (PHY) layer port or interface), an Advanced High-performance Bus (AHB) bus, any combination thereof, and / or other input / output port. In one illustrative example, the host processor 152 can communicate with the image sensor 130 using an I2C port, and the ISP 154 can communicate with the image sensor 130 using an MIPI port.

[0052] The image processor 150 may perform a number of tasks, such as de-mosaicing, color space conversion, image frame downsampling, pixel interpolation, automatic exposure (AE) control, automatic gain control (AGC), CDAF, PDAF, automatic white balance, merging of image frames to form an HDR image, image recognition, object recognition, feature recognition, receipt of inputs, managing outputs, managing memory, or some combination thereof. The image processor 150 may store image frames and / or processed images in random access memory (RAM) 140 / 625, read-only memory (ROM) 145 / 620, a cache 612, a memory unit 615, another storage device 630, or some combination thereof.PATENTQualcomm Ref. No. 2403790WO15

[0053] Various input / output (I / O) devices 160 may be connected to the image processor 150. The I / O devices 160 can include a display screen, a keyboard, a keypad, a touchscreen, a trackpad, a touch-sensitive surface, a printer, any other output devices 635, any other input devices 645, or some combination thereof. In some cases, a caption may be input into the image processing device 105B through a physical keyboard or keypad of the I / O devices 160, or through a virtual keyboard or keypad of a touchscreen of the I / O devices 160. The I / O 160 may include one or more ports, jacks, or other connectors that enable a wired connection between the device 105B and one or more peripheral devices, over which the device 105B may receive data from the one or more peripheral device and / or transmit data to the one or more peripheral devices. The I / O 160 may include one or more wireless transceivers that enable a wireless connection between the device 105B and one or more peripheral devices, over which the device 105B may receive data from the one or more peripheral device and / or transmit data to the one or more peripheral devices. The peripheral devices may include any of the previously-discussed types of I / O devices 160 and may themselves be considered I / O devices 160 once they are coupled to the ports, jacks, wireless transceivers, or other wired and / or wireless connectors.

[0054] In some cases, the image capture and processing system 100 may be a single device. In some cases, the image capture and processing system 100 may be two or more separate devices, including an image capture device 105A (e.g., a camera) and an image processing device 105B (e.g., a computing device coupled to the camera). In some implementations, the image capture device 105 A and the image processing device 105B may be coupled together, for example via one or more wires, cables, or other electrical connectors, and / or wirelessly via one or more wireless transceivers. In some implementations, the image capture device 105 A and the image processing device 105B may be disconnected from one another.

[0055] As shown in FIG. 1, a vertical dashed line divides the image capture and processing system 100 of FIG. 1 into two portions that represent the image capture device 105 A and the image processing device 105B, respectively. The image capture device 105 A includes the lens 115, control mechanisms 120, and the image sensor 130. The image processing device 105B includes the image processor 150 (including the ISP 154 and the host processor 152), the RAM 140, the ROM 145, and the I / O 160. In some cases, certain components illustrated in the imagePATENTQualcomm Ref. No. 2403790WO16 capture device 105 A, such as the ISP 154 and / or the host processor 152, may be included in the image capture device 105 A.

[0056] The image capture and processing system 100 can include an electronic device, such as a mobile or stationary telephone handset (e.g., smartphone, cellular telephone, or the like), a desktop computer, a laptop or notebook computer, a tablet computer, a set-top box, a television, a camera, a display device, a digital media player, a video gaming console, a video streaming device, an Internet Protocol (IP) camera, or any other suitable electronic device. In some examples, the image capture and processing system 100 can include one or more wireless transceivers for wireless communications, such as cellular network communications, 802.11 wi-fi communications, wireless local area network (WLAN) communications, or some combination thereof. In some implementations, the image capture device 105 A and the image processing device 105B can be different devices. For instance, the image capture device 105 A can include a camera device and the image processing device 105B can include a computing device, such as a mobile handset, a desktop computer, or other computing device.

[0057] While the image capture and processing system 100 is shown to include certain components, one of ordinary skill will appreciate that the image capture and processing system 100 can include more components than those shown in FIG. 1. The components of the image capture and processing system 100 can include software, hardware, or one or more combinations of software and hardware. For example, in some implementations, the components of the image capture and processing system 100 can include and / or can be implemented using electronic circuits or other electronic hardware, which can include one or more programmable electronic circuits (e.g., microprocessors, GPUs, DSPs, CPUs, and / or other suitable electronic circuits), and / or can include and / or be implemented using computer software, firmware, or any combination thereof, to perform the various operations described herein. The software and / or firmware can include one or more instructions stored on a computer-readable storage medium and executable by one or more processors of the electronic device implementing the image capture and processing system 100.PATENTQualcomm Ref. No. 2403790WO17

[0058] The host processor 152 can configure the image sensor 130 with new parameter settings (e.g., via an external control interface such as I2C, I3C, SPI, GPIO, and / or other interface). In one illustrative example, the host processor 152 can update exposure settings used by the image sensor 130 based on internal processing results of an exposure control algorithm from past image frames.

[0059] In some examples, the host processor 152 can perform electronic image stabilization (EIS). For instance, the host processor 152 can determine a motion vector corresponding to motion compensation for one or more image frames. In some aspects, host processor 152 can position a cropped pixel array (“the image window”) within the total array of pixels. The image window can include the pixels that are used to capture images. In some examples, the image window can include all of the pixels in the sensor, except for a portion of the rows and columns at the periphery of the sensor. In some cases, the image window can be in the center of the sensor while the image capture device 105 A is stationary. In some aspects, the peripheral pixels can surround the pixels of the image window and form a set of buffer pixel rows and buffer pixel columns around the image window. Host processor 152 can implement EIS and shift the image window from frame to frame of video, so that the image window tracks the same scene over successive frames (e.g., assuming that the subject does not move). In some examples in which the subject moves, host processor 152 can determine that the scene has changed.

[0060] In some examples, the image window can include at least 95% (e.g., 95% to 99%) of the pixels on the sensor. The first region of interest (ROI) (e.g., used for AE and / or AWB) may include the image data within the field of view of at least 95% (e.g., 95% to 99%) of the plurality of imaging pixels in the image sensor 130 of the image capture device 105A. In some aspects, a number of buffer pixels at the periphery of the sensor (outside of the image window) can be reserved as a buffer to allow the image window to shift to compensate for jitter. In some cases, the image window can be moved so that the subject remains at the same location within the adjusted image window, even though light from the subject may impinge on a different region of the sensor. In another example, the buffer pixels can include the ten topmost rows, ten bottommost rows, ten leftmost columns and ten rightmost columns of pixels on the sensor.PATENTQualcomm Ref. No. 2403790WO18In some configurations, the buffer pixels are not used for AF, AE or AWB when the image capture device 105 A is stationary and the buffer pixels not included in the image output. If jitter moves the sensor to the left by twice the width of a column of pixels between frames, the EIS algorithm can be used to shift the image window to the right by two columns of pixels, so the captured image shows the same scene in the next frame as in the current frame. Host processor 152 can use EIS to smoothen the transition from one frame to the next.

[0061] In some aspects, the host processor 152 can also dynamically configure the parameter settings of the internal pipelines or modules of the ISP 154 to match the settings of one or more input image frames from the image sensor 130 so that the image data is correctly processed by the ISP 154. Processing (or pipeline) blocks or modules of the ISP 154 can include modules for lens / sensor noise correction, de-mosaicing, color conversion, correction or enhancement / suppress! on of image attributes, denoising filters, sharpening filters, among others. The settings of different modules of the ISP 154 can be configured by the host processor 152. Each module may include a large number of tunable parameter settings. Additionally, modules may be co-dependent as different modules may affect similar aspects of an image. For example, denoising and texture correction or enhancement may both affect high frequency aspects of an image. As a result, a large number of parameters are used by an ISP to generate a final image from a captured raw image.

[0062] In some cases, the image capture and processing system 100 may perform one or more of the image processing functionalities described above automatically. For instance, one or more of the control mechanisms 120 may be configured to perform auto-focus operations, auto-exposure operations, and / or auto-white-balance operations. In some embodiments, an auto-focus functionality allows the image capture device 105 A to focus automatically prior to capturing the desired image. Various auto-focus technologies exist. For instance, active autofocus technologies determine a range between a camera and a subject of the image via a range sensor of the camera, typically by emitting infrared lasers or ultrasound signals and receiving reflections of those signals. In addition, passive auto-focus technologies use a camera’s own image sensor to focus the camera, and thus do not require additional sensors to be integrated into the camera. Passive AF techniques include Contrast Detection Auto FocusPATENTQualcomm Ref. No. 2403790WO19(CDAF), Phase Detection Auto Focus (PDAF), and in some cases hybrid systems that use both. The image capture and processing system 100 may be equipped with these or any additional type of auto-focus technology.

[0063] Synchronization between the image sensor 130 and the ISP 154 is important in order to provide an operational image capture system that generates high quality images without interruption and / or failure. FIG. 2 is a block diagram illustrating an example of an image capture and processing system 200 including an image processor 250 (including host processor 252 and ISP 254) in communication with an image sensor 230. The configuration shown in FIG. 2 is illustrative of traditional synchronization techniques used in camera systems. In general, the host processor 252 attempts to provide synchronization between the image sensor 230 and the ISP 254 using fixed periods of time by separately communicating with the image sensor 230 and the ISP 254. For example, in traditional camera systems, the host processor 252 communicates with the image sensor 230 (e.g., over an I2C port) and programs the image sensor 230 parameters with a first fixed period of time, such as 2-frame periods ahead of when that image frame will be processed by the ISP 254. The host processor 252 communicates with the ISP 254 (e.g., over an internal AHB bus or other interface) and programs the ISP 254 parameter settings with a second fixed period of time, such as 1 -frame period ahead of when that image frame will be processed by the ISP 254.

[0064] The image sensor 230 can send image frames to the ISP 254 (B-to-C in FIG. 2), such as over an MIPI CSI-2 PHY port or interface, or other suitable interface. However, the communication between the host processor 252 and the image sensor 230 (shown as from A to B) is indeterministic. Similarly, the communication between the image sensor 230 and the ISP 254 (shown as from B to C) and the communication the host processor 252 and the ISP 254 (shown as from A to C) are also indeterministic.

[0065] As previously mentioned, the increasing versatility of digital camera products has allowed for digital cameras to be implemented into a wide array of devices (e.g., vehicles) and has expanded their use to different applications (e.g., autonomous driving applications). The camera devices allow for the capture of images and / or video from any system (e.g., vehiclePATENTQualcomm Ref. No. 2403790WO20 system) equipped with a camera device. For example, the images and / or videos may be captured for autonomous driving.

[0066] FIG. 3 shows an example of a “nominal case” of a system (e.g., which may be implemented within a vehicle) including cameras connected to ports of an SOC. In particular, FIG. 3 is a diagram illustrating an example of a system 300 for guarding against camera sensor manipulation, where cameras 310, 315 (e.g., camera sensors) are shown to be connected (correctly) to their associated respective ports 330, 335 of an SOC 320. In FIG. 3, the system 300 is shown to include two cameras (e.g., two image sensors), which include Camera 1 (Cam- 1) 310 and Camera 2 (Cam-2) 315. Each camera can have its own respective capabilities such that Camera 1 (Cam-1) 310 has capability 1 (cap-1) and Camera 2 (Cam-2) 315 has capability 2 (cap-2).

[0067] In one or more examples, the cameras (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) can each include their own respective internal data. For example, Camera 1 (Cam-1) 310 can include internal data, which may include, but is not limited to, the manufacturer, make, and / or model 360a of Camera 1 (Cam-1) 310; the capabilities 360b (e.g., high resolution capability) associated with Camera 1 (Cam-1) 310; a certificate 360c associated with Camera 1 (Cam-1) 310; and / or SOC-originated security data 360d that is associated with Camera 1 (Cam-1) 310. In some examples, Camera 2 (Cam-2) 315 can include internal data, which can include, but is not limited to, the manufacturer, make, and / or model 365a of Camera 2 (Cam-2) 315; the capabilities 365b (e.g., low resolution capability) associated with Camera 2 (Cam-2) 315; a certificate 365c associated with Camera 2 (Cam-2) 315; and / or SOC- originated security data 365d that is associated with Camera 2 (Cam-2) 315.

[0068] Each of the cameras (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) is shown to be connected to a respective associated port on an SOC 320 such that Camera 1 (Cam- 1) 310 is connected to SOC port 1 (port-1) 330 and Camera 2 (Cam-2) 315 is connected to SOC port 2 (port-2) 335. In one or more examples, each camera (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) is shown to be connected to their associated respective SOC port via an in-vehicle-network connection or wired plumbing, such as via in-vehicle-network 1 (inv-PATENTQualcomm Ref. No. 2403790WO211) 350 and in-vehicle-network 2 (inv-2) 355, respectively. For example, Camera 1 (Cam-1) 310 is shown to be connected to SOC port 1 (port-1) 330 via in-vehicle-network 1 (inv-1) 350, and Camera 2 (Cam-2) 315 is shown to be connected to SOC port 2 (port-2) 335 via in-vehiclenetwork 2 (inv-2) 355.

[0069] In one or more examples, each port (e.g., SOC port 1 (port-1) 330 and SOC port 2 (port-2) 335) may be associated with a respective software stack 340, 345. Each software stack 340, 345 can process information that it receives from a camera that is connected to a port associated with that software stack 340, 345. For example, software stack 340 can process information that it receives from Camera 1 (Cam-1) 310 via SOC port 1 (port-1) 330, and software stack 345 can process information that it receives from Camera 2 (Cam-2) 315 via SOC port 2 (port-2) 335.

[0070] In some examples, each software stack 340, 345 may be associated with one or more applications (e.g., for different use cases). The software stacks 340, 345 may be associated with different applications from each other that have different levels of criticality and, as such, that software stacks 340, 345 may require cameras with different levels of capabilities. For example, the software stack 340 may be associated with advanced-drivers assistance systems (ADAS) applications used for autonomous driving of the vehicle, whereas the software stack 345 may be associated with driving monitoring system applications used to notify the driver of the vehicle of various things that that vehicle may be encountering (e g., by providing, to the driver, video for the side mirrors of the vehicle). Since the software stack 340 is utilized for ADAS applications (e.g., which involves critical driving features) and the software stack 345 is utilized for other less critical driving monitoring features, it can be necessary (for safety reasons) that the camera (e g., Camera 1 (Cam-1) 310) connected to the port (e.g., SOC port 1 (port-1) 330) associated with the software stack 340 has a higher level of capabilities (e.g., higher resolution) than the camera (e.g., Camera 2 (Cam-2) 315) connected to the port (e.g., SOC port 2 (port-2) 335) associated with the software stack 345.

[0071] In some cases, the two cameras (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) can appear identical and have near-identical features according to available documents,PATENTQualcomm Ref. No. 2403790WO22 such as the technical specifications of the cameras (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315). The configuration of the cameras (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) attached to their associated respective SOC ports (e.g., SOC port 1 (port-1) 330 and SOC port 2 (port-2) 335) is usually fixed during the time of manufacture. The cameras (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315), however, may be removed from the ports (e.g., SOC port 1 (port-1) 330 and SOC port 2 (port-2) 335) and retrofitted as required, such as due to a camera failing as a result of its end of life.

[0072] In one or more examples, each camera (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) can have legitimate security credentials (e.g., a certificate and / or a PSK). The SOC 320, during runtime, may set up separate CSE sessions to each camera (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315), which can include the establishment of TKs, such as TK1 and TK2, in each camera (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315). Each camera (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) can protect its own camera stream by using its own respective associated TK. For example, Camera 1 (Cam-1) 310 can protect its own camera stream by using TK1, and Camera 2 (Cam-2) 315 can protect its own camera stream by using TK2.

[0073] FIG. 4 shows an example of a “swap case” of a system (e.g., which may be implemented within a vehicle) including cameras (incorrectly) connected to ports of an SOC, where the cameras have been swapped. In particular, FIG. 4 is a diagram illustrating an example of a system 400 for guarding against camera sensor manipulation, where the camera sensors 315, 310 have been swapped and are not connected to their associated respective ports 335, 330. In FIG. 4, the cameras (e.g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) are shown to have been swapped such that Camera 1 (Cam-1) 310 is now connected to SOC port 2 (port- 2) 335 via in-vehicle-network 2 (inv-2) 355, and Camera 2 (Cam-2) 315 is now connected to SOC port 1 (port-1) 330 via in-vehicle-network 1 (inv-1) 350.

[0074] As previously mentioned, Camera 1 (Cam-1) 310 may have a higher level of capabilities than Camera 2 (Cam-2) 315. For example, Camera 1 (Cam-1) 310 may have a higher resolution than Camera 2 (Cam-2) 315. As such, since the software stack 340 is utilizedPATENTQualcomm Ref. No. 2403790WO23 for ADAS applications (e.g., which involves critical driving features) and the software stack 345 is utilized for other less critical driving monitoring features, it can be necessary (for safety reasons) that Camera 1 (Cam-1) 310, which has a higher level of capabilities than Camera 2 (Cam-2) 315, be connected to the SOC port 1 (port-1) 330, which is associated with the software stack 340.

[0075] In one or more examples, vehicle cameras (e g., Camera 1 (Cam-1) 310 and Camera 2 (Cam-2) 315) may be vulnerable to an attack that is a combination of physical attack, where the cameras connected to the SOC ports are physically swapped (e.g., as shown in FIG 4), and a software attack, where the cameras’ credentials (e.g., certificates, PSKs, and / or TKs) are also swapped in the camera sensor manager software in a way such that the SOC will still successfully authenticate each of the swapped cameras. In some cases, the SOC may detect an unexpected operation (e.g., detect a lower data rate than expected) with a given camera attached to a given port. However, the SOC may not be able to detect the camera swap. In particular, one camera attached to a specific port (e.g., behind which is a safety-critical operation, such as an autonomous driving software stack) may be lacking a capability (e.g., not capable of high resolution) that only arises in a specific use case that is infrequent, and in that use case, the camera (e.g., lacking high resolution) can lead to a safety concern (e.g., an unsafe operation).

[0076] Therefore, improved systems and techniques that allow for a SOC to identify the presence of a different and unexpected camera connected to one of the SOC’s ports can be useful

[0077] In one or more aspects, the systems and techniques provide for security methods guarding against automotive camera sensor manipulation. In one or more examples, the systems and techniques can allow for an SOC to be able to cryptographically identify the presence of a different (e.g., inappropriate) and unexpected camera connected to one of the physical ports of the SOC. In some examples, the systems and techniques allow for the SOC to be able to bind an appropriate camera (e g., a camera with appropriate capabilities for the software stack associated with a specific port) to a specific physical port of the SOC.PATENTQualcomm Ref. No. 2403790WO24

[0078] In one or more aspects, during operation of the systems and techniques for determining a camera swap at a device, a port of a device may receive, from a first camera, encrypted information. The device, based on a key stored at the device, may attempt to decrypt the encrypted information to produce decrypted information. The device, based on determining the key is unable to decrypt the encrypted information to produce the decrypted information, may determine that the first camera is connected to the port of the device that previously had a second camera connected.

[0079] In one or more examples, the key may be associated with the second camera. In some examples, the key may be a traffic key (TK), a random number, generated by the device using a key derivation function (KDF) based on the random number, or generated by the device using the KDF based on the random number and the TK. In one or more examples, the TK may be pre-programmed into the device during manufacturing of the device. In some examples, the random number may be generated during runtime operation of the device.

[0080] In some examples, the device, based on one or more other keys stored at the device, may attempt to decrypt the encrypted information to produce decrypted information. In one or more examples, the device, based on determining one other key of the one or more other keys is able to decrypt the encrypted information to produce the decrypted information, may determine an identity of the first camera connected to the port of the device. In some examples, the decrypted information may include data obtained by the first camera and a message authentication code (MAC) associated with the first camera. In one or more examples, the device may be an SOC.

[0081] In one or more examples, during operation of the systems and techniques for determining a camera swap at a device, a port of the device may receive, from a first camera, information associated with the first camera. The device, based on the information not matching attributes of a second camera, may determine that the first camera is connected to the port of the device that previously had the second camera connected.

[0082] In some examples, the information associated with the first camera may include sensor-specific information associated with the first camera or a certificate comprising thePATENTQualcomm Ref. No. 2403790WO25 sensor-specific information associated with the first camera. In one or more examples, the sensor-specific information may include capabilities associated with the first camera, a manufacturer of the first camera, a make of the first camera, a model of the first camera, a serial number of the first camera, and / or a unique identifier UID) of the first camera. In some examples, the capabilities may include a resolution of the first camera and / or a maximum frame rate of the first camera.

[0083] In one or more examples, the information may include a random number. In some examples, fuses of the device and the first camera may be blown based on the random number. In one or more examples, the device may receive a license authorizing replacement of the first camera on the port of the device with another camera.

[0084] In some examples, the device, based on the information, may determine an identity of the first camera connected to the port of the device. In one or more examples, the device may send, to the first camera, a request for the information associated with the first camera. In some examples, the device may be an SOC.

[0085] In some aspects, the systems and techniques can utilize traffic keys (TKs) that are preprogrammed at the production site for the SOC to be able to detect a swap of the cameras on the physical ports of the SOC. In one or more examples, at the production site during the manufacturing, a TK may be generated and pre-programmed in a secure manner such that the TK is known between the SOC, the camera, and the corresponding SOC port for that camera. For example, TK1 may be generated and pre-programmed between the SOC 320, Camera 1 (Cam-1) 310, and SOC port 1 (port-1) 330. TK2 may be generated and pre-programmed between the SOC 320, Camera 2 (Cam-2) 315, and SOC port 2 (port-2) 335.

[0086] During runtime operation, a camera may encrypt its associated message authentication code (MAC) and data (e g., data that the camera is sending to the SOC) based on (using) the TK associated with the camera to produce encrypted information. For example, Camera 1 (Cam-1) 310 may encrypt its associated MAC and data based on (using) TK1 to produce encrypted information. The camera may then send (e.g., in a CSE secure stream, such as a camera serial interface (CSI)-2 stream) the encrypted information to the SOC.PATENTQualcomm Ref. No. 2403790WO26

[0087] After the SOC receives the encrypted information, the SOC can perform a MAC check by attempting to decrypt the encrypted information by using the TK associated with the SOC port that the SOC received the encrypted information. For example, if the SOC 320 receives the encrypted information on SOC port 1 (port-1) 330, the SOC 320 will use TK1 (e.g., which is associated with Camera 1 (Cam-1) 310) to attempt to decrypt the encrypted information because the SOC assumes that Camera 1 (Cam-1) 310 is connected to SOC port 1 (port-1) 330. If the SOC is unable to decrypt the encrypted information using TK1, the MAC check will fail. When the MAC check fails, the SOC will be aware that Camera 1 (Cam-1) 310 is not connected to SOC port 1 (port-1) 330 as it should be and, as such, a camera swap has taken place.

[0088] In one or more examples, after the MAC check fails, the SOC may cycle through the TKs (e.g., the TKs stored on the SOC) attempting to decrypt the encrypted information in order to determine which camera is connected to the port the SOC received the encrypted information. For example, the SOC 320 may be able to decrypt the encrypted information by using TK2. As such, the SOC 320 can determine that Camera 2 (Cam-2) 315 (e.g., which is associated with TK2) is now connected to SOC port 1 (port-1) 330.

[0089] In one or more aspects, the systems and techniques can utilize sensor-specific information to be able to detect a swap of the cameras on the physical ports of the SOC. In one or more examples, the SOC may request a camera to send sensor-specific information associated with that camera in a CSI-2 stream (e.g., a CSE secure stream) to the SOC. In some examples, the camera may send the sensor-specific information associated with that camera (e.g., along with data) in a CSI-2 stream to the SOC without receiving a request from the SOC for the sensor-specific information. In one or more examples, the sensor-specific information may include, but is not limited to, capabilities (e.g., resolution, maximum frame rate, etc.) of the camera, the manufacturer of the camera, make of the camera, model of the camera, serial number of the camera, and / or a unique identifier (UID) of the camera.

[0090] In some examples, the CSI-2 stream may be read at the CSE receiver (RX) of the SOC (or even within the in-vehicle-network’s aggregators and / or bridges) before the CSEPATENTQualcomm Ref. No. 2403790WO27 receiver processing occurs. Unexpected fields within the CSI-2 stream (e.g., the sensor-specific information in the CSI-2 stream suddenly changes from a high resolution capability to a low resolution capability) can be flagged by the SOC as a camera swap scenario (e.g., to avert a safety issue). For example, the SOC 320 may be receiving a CSI-2 stream on SOC port 1 (port- 1) 330 and, as such, the SOC 320 assumes that the CSI-2 stream is being sent by Camera 1 (Cam-1) 310 (e.g., a high resolution capability camera) that is associated with SOC port 1 (port- 1) 330. However, the SOC 320 may suddenly detect mid-stream that the sensor-specific information in the CSI-2 stream changes from a high resolution capability to a low resolution capability. As such, the SOC may determine (e g., flag) that a camera swap has occurred (e.g., where Camera 2 (Cam-2) 315, which is a low resolution capability camera, may have been connected to SOC port 1 (port-1) 330).

[0091] In some aspects, the systems and techniques can utilize SOC-originated identifier data (e.g., in the form of a random number) to be able to detect a swap of the cameras on the physical ports of the SOC. In one or more examples, during runtime operation, when the SOC establishes a first communication with a camera, the SOC can determine (check) whether a key (e.g., a random number key) is available for use with that particular camera or not. If the SOC determines that a key is not available for use with that camera, the SOC can generate a random number and create a key based on that random number. In one or more examples, the random number itself may be used as the key. In some examples, the key may be generated using a key derivation function (KDF) based on the random number. In one or more examples, the key may be generated using a KDF based on the random number and a TK (e.g., TK1) associated with that particular camera.

[0092] After generating the key, the SOC can then associate the generated key with the specific camera (e.g., Camera 1 (Cam-1) 310) and the specific port (e.g., SOC port 1 (port-1) 330) associated with that camera. The SOC can then send (e.g., transmit in secure object, such as a CSE secure stream, for example a CSI-2 stream) the key to the camera (e.g., Camera 1 (Cam-1) 310) to use as an encryption key.PATENTQualcomm Ref. No. 2403790WO28

[0093] During runtime operation, a camera may encrypt its associated MAC and data (e.g., data that the camera is sending to the SOC) based on (using) the key (e.g., the key that the camera received from the SOC) to produce encrypted information. For example, Camera 1 (Cam-1) 310 may encrypt its associated MAC and data based on (using) the key it received from the SOC 320 to produce encrypted information. The camera can then send (e.g., in a CSE secure stream, such as a CSI-2 stream) the encrypted information to the SOC.

[0094] After the SOC receives the encrypted information, the SOC can perform a MAC check by attempting to decrypt the encrypted information by using the key associated with the SOC port that the SOC received the encrypted information. For example, if the SOC 320 receives the encrypted information on SOC port 1 (port-1) 330, the SOC 320 will use the key (e.g., which the SOC 320 sent to Camera 1 (Cam-1) 310) to attempt to decrypt the encrypted information because the SOC assumes that Camera 1 (Cam-1) 310 is connected to SOC port 1 (port-1) 330. If the SOC is unable to decrypt the encrypted information using the key, the MAC check fails. Once the MAC check fails, the SOC can be aware that Camera 1 (Cam-1) 310 is not connected to SOC port 1 (port-1) 330 as it should be and, as such, a camera swap has occurred. In one or more examples, after the MAC check fails, the SOC may cycle through keys (e.g., any random number generated keys stored on the SOC) attempting to decrypt the encrypted information in order to determine which camera is connected to the port the SOC received the encrypted information.

[0095] In one or more aspects, the systems and techniques can utilize a certificate that includes an identification (ID) of a specific SOC port to be able to detect a swap of the cameras on the physical ports of the SOC. In one or more examples, camera manufacturers may work with certificate authorities (CAs) to generate public key certificates that include an additional field for specification of a specific SOC port.

[0096] In one or more examples, each camera has a hardware key (e.g., a private key) that is a random key (e.g., a chip random base key (CRBK)) that is unique and embedded within the hardware of the camera. A CA (e.g., an original equipment manufacturer (OEM)) can create a certificate (e.g., a digital certificate) for a public key associated with a camera (e.g., the publicPATENTQualcomm Ref. No. 2403790WO29 key becomes the certificate). The public key can correspond to the private key such that the public key (e.g., a software key) and the private key (e.g., a hardware key) form a public-private key pair, such as an asymmetric key pair (e.g., elliptic curve cryptography (ECC)). In one or more examples, a certificate for a camera may include, in an additional field of the certificate, an indication of a specific SOC port, such as an ID for a CSI decoder (CSID) port, that is associated with that camera. For example, a certificate for Camera 1 (Cam-1) 310 may include, in an additional field of the certificate, an indication of SOC port 1 (port-1) 330, which is associated with Camera 1 (Cam-1) 310.

[0097] In some examples, cameras can send their certificates (e.g., public keys) to the SOC. When the SOC is going to establish a communication with a particular camera, the SOC can use the certificate (e.g., public key) associated with that camera to authenticate and establish the communications. For example, during a security protocols and data models (SPDM) handshake between the SOC and a particular camera to establish communications, the SOC can receive a certificate (e.g., public key) from the camera. After receiving the certificate (e.g., which includes the SOC port associated with that camera), the SOC can be aware of the intended SOC port forthat camera and can provide this information to the CSI-2 receiver within the SOC. If the SOC determines that the camera is connected to a SOC port that is different than the port designated within the certificate for that camera, the SOC can determine that a camera swap has occurred.

[0098] In some aspects, the systems and techniques can utilize a common random number that is preprogrammed at the production site for the SOC to be able to detect a swap of the cameras on the physical ports of the SOC. In one or more examples, at the production site during the manufacturing, a common random number may be generated and pre-programmed in a secure manner such that the common random number is known between the SOC, the camera, and the corresponding SOC port for that camera. For example, a common random number may be generated and pre-programmed between the SOC 320, Camera 1 (Cam-1) 310, and SOC port 1 (port-1) 330. In one or more examples, during production, fuses (e.g., one time programmable (OTP) fuses) within the camera and fuses within the SOC may be blown based on the common random number. In some examples, the common random number may bePATENTQualcomm Ref. No. 2403790WO30 stored securely within the SOC, such as within a rely protected memory block (RPMB) that is accessible only from the secure world.

[0099] In one or more examples, when an SOC is going to establish a communication with a particular camera, the SOC can use the common random number associated with that camera to authenticate and establish the communications. For example, during a SPDM handshake between the SOC and a particular camera to establish communications, the SOC can receive a common random number from the camera. After receiving the common random number, if the SOC determines that the camera is connected to a SOC port that is different than the port designated within the common random number for that camera, the SOC can determine that a camera swap has occurred.

[0100] In one or more aspects, the systems and techniques can utilize license-based access for component (camera) replacement on a SOC port. In one or more examples, component replacement can be supported through license-based access to RPMB to replace a camera and to blow fuses for a new common random number on the replacement camera and the SOC. In some examples, the licenses can be provided (e.g., by an OEM of the cameras) only to authorized service centers to replace the cameras.

[0101] In one or more examples, when a camera (e.g., Camera 1 (Cam-1) 310) connected to a specific SOC port (e.g., SOC port 1 (port-1) 330) needs to be replaced (e.g., due to camera failure), an authorized service center can first disconnect the camera from an SOC port. The authorized service center can then install a replacement camera onto that SOC port and install a license for that replacement camera onto the SOC. The license can be validated to install the replacement camera and to establish an association between the replacement camera and the SOC port.

[0102] FIG. 5A is a flow chart illustrating an example of a process 500 for a camera sensor security. The process 500 can be performed by a computing device (e.g., a computing device or computing system 600 of FIG. 6) or by a component or system (e.g., the system 300 of FIG. 3, an SOC such as SOC 320 of FIG. 3, a chipset, one or more processors central processing units (CPUs), digital signal processors (DSPs), graphics processing units (GPUs), anyPATENTQualcomm Ref. No. 2403790WO31 combination thereof, and / or other type of processor(s), or other component or system) of the computing device. The operations of the process 500 may be implemented as software components that are executed and run on one or more processors (e.g., processor 610 of FIG. 6, or other processor(s)). Further, the transmission and reception of signals by the computing device in the process 500 may be enabled, for example, by one or more antennas and / or one or more transceivers (e.g., wireless transceiver(s)).

[0103] At block 510, the computing device (or component thereof) can receive, on a port of the device (e.g., port-1 330 and / or port-2 335 of SOC 320 of FIG. 3 and / or FIG. 4) from a first camera (e.g., one of the camera 315 and / or the camera 310 of FIG. 3 and / or FIG. 4), encrypted information.

[0104] At block 520, the computing device (or component thereof) can determine that the device is unable to decrypt the encrypted information using a key stored at the device. In some aspects, the key is associated with a second camera (e.g., the other of the camera 315 and / or the camera 310 of FIG. 3 and / or FIG. 4). In some cases, the key is a traffic key (TK), is a random number, is generated by the device using a key derivation function (KDF) based on the random number, or is generated by the device using the KDF based on the random number and the TK. In some examples, the TK is pre-programmed into the device during manufacturing of the device. In some cases, the random number is generated during runtime operation of the device.

[0105] At block 530, the computing device (or component thereof) can determine, based on determining that the device is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the device that previously had the second camera connected.

[0106] At block 540, the computing device (or component thereof) can reject the first camera for operation using the port. In some aspects, the computing device (or component thereof) can output an alert or alarm indicating rejection of the first camera for operation using the port.PATENTQualcomm Ref. No. 2403790WO32

[0107] In some aspects, the computing device (or component thereof) can determine that the device is able to decrypt the encrypted information using a key of one or more additional keys stored at the device to produce decrypted information. In such aspects, the computing device (or component thereof) can determine, based on determining that the device is able to decrypt the encrypted information using the key of the one or more additional keys to produce the decrypted information, an identity of the first camera connected to the port of the device. In some cases, the decrypted information includes data obtained by the first camera and a message authentication code (MAC) associated with the first camera.

[0108] FIG. 5B is a flow chart illustrating an example of a process 550 for a camera sensor security. The process 550 can be performed by a computing device (e.g., a computing device or computing system 600 of FIG. 6) or by a component or system (e.g., the system 300 of FIG. 3, an SOC such as SOC 320 of FIG. 3, a chipset, one or more processors central processing units (CPUs), digital signal processors (DSPs), graphics processing units (GPUs), any combination thereof, and / or other type of processor(s), or other component or system) of the computing device. The operations of the process 550 may be implemented as software components that are executed and run on one or more processors (e.g., processor 610 of FIG. 6, or other processor(s)). Further, the transmission and reception of signals by the computing device in the process 550 may be enabled, for example, by one or more antennas and / or one or more transceivers (e.g., wireless transceiver(s)).

[0109] At block 560, the computing device (or component thereof) can receive, on a port of the device (e.g., port-1 330 and / or port-2 335 of SOC 320 of FIG. 3 and / or FIG. 4) from a first camera (e.g., one of the camera 315 and / or the camera 310 of FIG. 3 and / or FIG. 4), information associated with the first camera. In some cases, the computing device (or component thereof) can send, to the first camera, a request for the information associated with the first camera. In such cases, the first camera can send the information to the port of the device in reply to the request. In some aspects, the computing device (or component thereof) can determine, based on the information, an identity of the first camera connected to the port of the device.PATENTQualcomm Ref. No. 2403790WO33

[0110] In some aspects, the information associated with the device includes sensor-specific information associated with the first camera or a certificate including the sensor-specific information associated with the first camera. In some cases, the sensor-specific information includes at least one of capabilities associated with the first camera, a manufacturer of the first camera, a make of the first camera, a model of the first camera, a serial number of the first camera, a unique identifier (UID) of the first camera, any combination thereof, and / or other sensor-specific information. In some aspects, the capabilities include a resolution of the first camera or a maximum frame rate of the first camera. In some examples, the information includes a random number. In some aspects, fuses of the device and the first camera are blown based on the random number. In some cases, the computing device (or component thereof) can receive a license authorizing replacement of the first camera on the port of the device with another camera.

[0111] At block 570, the computing device (or component thereof) can determine the information does not match attributes of a second camera (e.g., the other of the camera 315 and / or the camera 310 of FIG. 3 and / or FIG. 4).

[0112] At block 580, the computing device (or component thereof) can determine, based on the information not matching the attributes of the second camera, the first camera is connected to the port of the device that previously had the second camera connected.

[0113] At block 590, the computing device (or component thereof) can reject the first camera for operation using the port. In some aspects, the computing device (or component thereof) can output an alert or alarm indicating rejection of the first camera for operation using the port.

[0114] In some cases, the computing device configured to perform the process 500 and / or process 550 may include various components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or other component s) that are configured to carry out the steps of processes described herein. In some examples, the computing device may include a display, one or more network interfaces configured toPATENTQualcomm Ref. No. 2403790WO34 communicate and / or receive the data, any combination thereof, and / or other component(s). The one or more network interfaces may be configured to communicate and / or receive wired and / or wireless data, including data according to the 3G, 4G, 5G, and / or other cellular standard, data according to the Wi-Fi (802.1 lx) standards, data according to the Bluetooth™ standard, data according to the Internet Protocol (IP) standard, and / or other types of data.

[0115] The components of the computing device configured to perform the process 500 and / or process 550 can be implemented in circuitry. For example, the components can include and / or can be implemented using electronic circuits or other electronic hardware, which can include one or more programmable electronic circuits (e.g., microprocessors, graphics processing units (GPUs), digital signal processors (DSPs), central processing units (CPUs), and / or other suitable electronic circuits), and / or can include and / or be implemented using computer software, firmware, or any combination thereof, to perform the various operations described herein. The computing device may further include a display (as an example of the output device or in addition to the output device), a network interface configured to communicate and / or receive the data, any combination thereof, and / or other component(s). The network interface may be configured to communicate and / or receive Internet Protocol (IP) based data or other type of data.

[0116] The process 500 and the process 550 illustrated as a logical flow diagram, the operations of which represent a sequence of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored on one or more computer- readable storage media that, when executed by one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations can be combined in any order and / or in parallel to implement the processes.PATENTQualcomm Ref. No. 2403790WO35

[0117] Additionally, the process 500 and the process 550 may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware, or combinations thereof. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.

[0118] FIG. 6 is a block diagram illustrating an example of a computing system 600, which may be employed for camera sensor security. In particular, FIG. 6 illustrates an example of computing system 600, which can be for example any computing device making up internal computing system, a remote computing system, a camera, or any component thereof in which the components of the system are in communication with each other using connection 605. Connection 605 can be a physical connection using a bus, or a direct connection into processor 610, such as in a chipset architecture. Connection 605 can also be a virtual connection, networked connection, or logical connection.

[0119] In some aspects, computing system 600 is a distributed system in which the functions described in this disclosure can be distributed within a datacenter, multiple data centers, a peer network, etc. In some aspects, one or more of the described system components represents many such components each performing some or all of the function for which the component is described. In some aspects, the components can be physical or virtual devices.

[0120] Example system 600 includes at least one processing unit (CPU or processor) 610 and connection 605 that communicatively couples various system components including system memory 615, such as read-only memory (ROM) 620 and random access memory (RAM) 625 to processor 610. Computing system 600 can include a cache 612 of high-speed memory connected directly with, in close proximity to, or integrated as part of processor 610.

[0121] Processor 610 can include any general purpose processor and a hardware service or software service, such as services 632, 634, and 636 stored in storage device 630, configuredPATENTQualcomm Ref. No. 2403790WO36 to control processor 610 as well as a special-purpose processor where software instructions are incorporated into the actual processor design. Processor 610 may essentially be a completely self-contained computing system, containing multiple cores or processors, a bus, memory controller, cache, etc. A multi-core processor may be symmetric or asymmetric.

[0122] To enable user interaction, computing system 600 includes an input device 645, which can represent any number of input mechanisms, such as a microphone for speech, a touch-sensitive screen for gesture or graphical input, keyboard, mouse, motion input, speech, etc. Computing system 600 can also include output device 635, which can be one or more of a number of output mechanisms. In some instances, multimodal systems can enable a user to provide multiple types of input / output to communicate with computing system 600.

[0123] Computing system 600 can include communications interface 640, which can generally govern and manage the user input and system output. The communication interface may perform or facilitate receipt and / or transmission wired or wireless communications using wired and / or wireless transceivers, including those making use of an audio jack / plug, a microphone jack / plug, a universal serial bus (USB) port / plug, an Apple™ Lightning™ port / plug, an Ethernet port / plug, a fiber optic port / plug, a proprietary wired port / plug, 3G, 4G, 5G and / or other cellular data network wireless signal transfer, a Bluetooth™ wireless signal transfer, a Bluetooth™ low energy (BLE) wireless signal transfer, an IBEACON™ wireless signal transfer, a radio-frequency identification (RFID) wireless signal transfer, near-field communications (NFC) wireless signal transfer, dedicated short range communication (DSRC) wireless signal transfer, 802.11 Wi-Fi wireless signal transfer, wireless local area network (WLAN) signal transfer, Visible Light Communication (VLC), Worldwide Interoperability for Microwave Access (WiMAX), Infrared (IR) communication wireless signal transfer, Public Switched Telephone Network (PSTN) signal transfer, Integrated Services Digital Network (ISDN) signal transfer, ad-hoc network signal transfer, radio wave signal transfer, microwave signal transfer, infrared signal transfer, visible light signal transfer, ultraviolet light signal transfer, wireless signal transfer along the electromagnetic spectrum, or some combination thereof.PATENTQualcomm Ref. No. 2403790WO37

[0124] The communications interface 640 may also include one or more range sensors (e.g., LiDAR sensors, laser range finders, RF radars, ultrasonic sensors, and infrared (IR) sensors) configured to collect data and provide measurements to processor 610, whereby processor 610 can be configured to perform determinations and calculations needed to obtain various measurements for the one or more range sensors. In some examples, the measurements can include time of flight, wavelengths, azimuth angle, elevation angle, range, linear velocity and / or angular velocity, or any combination thereof. The communications interface 640 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers that are used to determine a location of the computing system 600 based on receipt of one or more signals from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the US-based GPS, the Russia-based Global Navigation Satellite System (GLONASS), the China-based BeiDou Navigation Satellite System (BDS), and the Europe-based Galileo GNSS. There is no restriction on operating on any particular hardware arrangement, and therefore the basic features here may easily be substituted for improved hardware or firmware arrangements as they are developed.

[0125] Storage device 630 can be a non-volatile and / or non-transitory and / or computer- readable memory device and can be a hard disk or other types of computer readable media which can store data that are accessible by a computer, such as magnetic cassettes, flash memory cards, solid state memory devices, digital versatile disks, cartridges, a floppy disk, a flexible disk, a hard disk, magnetic tape, a magnetic strip / stripe, any other magnetic storage medium, flash memory, memristor memory, any other solid-state memory, a compact disc read only memory (CD-ROM) optical disc, a rewritable compact disc (CD) optical disc, digital video disk (DVD) optical disc, a blu-ray disc (BDD) optical disc, a holographic optical disk, another optical medium, a secure digital (SD) card, a micro secure digital (microSD) card, a Memory Stick® card, a smartcard chip, a EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, another integrated circuit (IC) chip / card, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash EPROMPATENTQualcomm Ref. No. 2403790WO38(FLASHEPROM), cache memory (e.g., Level 1 (LI) cache, Level 2 (L2) cache, Level 3 (L3) cache, Level 4 (L4) cache, Level 5 (L5) cache, or other (L#) cache), resistive random-access memory (RRAM / ReRAM), phase change memory (PCM), spin transfer torque RAM (STT- RAM), another memory chip or cartridge, and / or a combination thereof.

[0126] The storage device 630 can include software services, servers, services, etc., that when the code that defines such software is executed by the processor 610, it causes the system to perform a function. In some aspects, a hardware service that performs a particular function can include the software component stored in a computer-readable medium in connection with the necessary hardware components, such as processor 610, connection 605, output device 635, etc., to carry out the function. The term “computer-readable medium” includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other mediums capable of storing, containing, or carrying instruction(s) and / or data. A computer- readable medium may include a non-transitory medium in which data can be stored and that does not include carrier waves and / or transitory electronic signals propagating wirelessly or over wired connections. Examples of a non-transitory medium may include, but are not limited to, a magnetic disk or tape, optical storage media such as compact disk (CD) or digital versatile disk (DVD), flash memory, memory or memory devices. A computer-readable medium may have stored thereon code and / or machine-executable instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted via any suitable means including memory sharing, message passing, token passing, network transmission, or the like.

[0127] Specific details are provided in the description above to provide a thorough understanding of the aspects and examples provided herein, but those skilled in the art will recognize that the application is not limited thereto. Thus, while illustrative aspects of the application have been described in detail herein, it is to be understood that the inventivePATENTQualcomm Ref. No. 2403790WO39 concepts may be otherwise variously embodied and employed, and that the appended claims are intended to be construed to include such variations, except as limited by the prior art. Various features and aspects of the above-described application may be used individually or jointly. Further, aspects can be utilized in any number of environments and applications beyond those described herein without departing from the broader scope of the specification. The specification and drawings are, accordingly, to be regarded as illustrative rather than restrictive. For the purposes of illustration, methods were described in a particular order. It should be appreciated that in alternate aspects, the methods may be performed in a different order than that described.

[0128] For clarity of explanation, in some instances the present technology may be presented as including individual functional blocks comprising devices, device components, steps or routines in a method embodied in software, or combinations of hardware and software. Additional components may be used other than those shown in the figures and / or described herein. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the aspects in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the aspects.

[0129] Further, those of skill in the art will appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein may be implemented as electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.PATENTQualcomm Ref. No. 2403790WO40

[0130] Individual aspects may be described above as a process or method which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed, but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0131] Processes and methods according to the above-described examples can be implemented using computer-executable instructions that are stored or otherwise available from computer-readable media. Such instructions can include, for example, instructions and data which cause or otherwise configure a general purpose computer, special purpose computer, or a processing device to perform a certain function or group of functions. Portions of computer resources used can be accessible over a network. The computer executable instructions may be, for example, binaries, intermediate format instructions such as assembly language, firmware, source code. Examples of computer-readable media that may be used to store instructions, information used, and / or information created during methods according to described examples include magnetic or optical disks, flash memory, USB devices provided with non-volatile memory, networked storage devices, and so on.

[0132] In some aspects the computer-readable storage devices, mediums, and memories can include a cable or wireless signal containing a bitstream and the like. However, when mentioned, non-transitory computer-readable storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and signals per se.

[0133] Those of skill in the art will appreciate that information and signals may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the above description may be represented by voltages, currents, electromagneticPATENTQualcomm Ref. No. 2403790WO41 waves, magnetic fields or particles, optical fields or particles, or any combination thereof, in some cases depending in part on the particular application, in part on the desired design, in part on the corresponding technology, etc.

[0134] The various illustrative logical blocks, modules, and circuits described in connection with the aspects disclosed herein may be implemented or performed using hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof, and can take any of a variety of form factors. When implemented in software, firmware, middleware, or microcode, the program code or code segments to perform the necessary tasks (e.g., a computer-program product) may be stored in a computer-readable or machine-readable medium. A processor(s) may perform the necessary tasks. Examples of form factors include laptops, smart phones, mobile phones, tablet devices or other small form factor personal computers, personal digital assistants, rackmount devices, standalone devices, and so on. Functionality described herein also can be embodied in peripherals or add-in cards. Such functionality can also be implemented on a circuit board among different chips or different processes executing in a single device, by way of further example.

[0135] The instructions, media for conveying such instructions, computing resources for executing them, and other structures for supporting such computing resources are example means for providing the functions described in the disclosure.

[0136] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices such as general purposes computers, wireless communication device handsets, or integrated circuit devices having multiple uses including application in wireless communication device handsets and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be realized at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed, performs one or more of the methods, algorithms, and / or operations described above. The computer-readable dataPATENTQualcomm Ref. No. 2403790WO42 storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium may comprise memory or data storage media, such as random access memory (RAM) such as synchronous dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), FLASH memory, magnetic or optical data storage media, and the like. The techniques additionally, or alternatively, may be realized at least in part by a computer-readable communication medium that carries or communicates program code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer, such as propagated signals or waves.

[0137] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general purpose microprocessors, an application specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Accordingly, the term “processor,” as used herein may refer to any of the foregoing structure, any combination of the foregoing structure, or any other structure or apparatus suitable for implementation of the techniques described herein.

[0138] One of ordinary skill will appreciate that the less than (“<”) and greater than (“>”) symbols or terminology used herein can be replaced with less than or equal to (“<”) and greater than or equal to (“ >”) symbols, respectively, without departing from the scope of this description.

[0139] Where components are described as being “configured to” perform certain operations, such configuration can be accomplished, for example, by designing electronicPATENTQualcomm Ref. No. 2403790WO43 circuits or other hardware to perform the operation, by programming programmable electronic circuits (e.g., microprocessors, or other suitable electronic circuits) to perform the operation, or any combination thereof.

[0140] The phrase “coupled to” or “communicatively coupled to” refers to any component that is physically connected to another component either directly or indirectly, and / or any component that is in communication with another component (e.g., connected to the other component over a wired or wireless connection, and / or other suitable communication interface) either directly or indirectly.

[0141] Claim language or other language reciting “at least one of’ a set and / or “one or more” of a set indicates that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language reciting “at least one of A and B” or “at least one of A or B” means A, B, or A and B. In another example, claim language reciting “at least one of A, B, and C” or “at least one of A, B, or C” means A, B, C, or A and B, or A and C, or B and C, A and B and C, or any duplicate information or data (e.g., A and A, B and B, C and C, A and A and B, and so on), or any other ordering, duplication, or combination of A, B, and C. The language “at least one of’ a set and / or “one or more” of a set does not limit the set to the items listed in the set. For example, claim language reciting “at least one of A and B” or “at least one of A or B” may mean A, B, or A and B, and may additionally include items not listed in the set of A and B. The phrases “at least one” and “one or more” are used interchangeably herein.

[0142] Claim language or other language reciting “at least one processor configured to,” “at least one processor being configured to,” “one or more processors configured to,” “one or more processors being configured to,” or the like indicates that one processor or multiple processors (in any combination) can perform the associated operation(s). For example, claim language reciting “at least one processor configured to: X, Y, and Z” means a single processor can be used to perform operations X, Y, and Z; or that multiple processors are each tasked with a certain subset of operations X, Y, and Z such that together the multiple processors perform X, Y, and Z; or that a group of multiple processors work together to perform operations X, Y,PATENTQualcomm Ref. No. 2403790WO44 and Z. In another example, claim language reciting “at least one processor configured to: X, Y, and Z” can mean that any single processor may only perform at least a subset of operations X, Y, and Z.

[0143] Where reference is made to one or more elements performing functions (e.g., steps of a method), one element may perform all functions, or more than one element may collectively perform the functions. When more than one element collectively performs the functions, each function need not be performed by each of those elements (e.g., different functions may be performed by different elements) and / or each function need not be performed in whole by only one element (e.g., different elements may perform different sub-functions of a function). Similarly, where reference is made to one or more elements configured to cause another element (e.g., an apparatus) to perform functions, one element may be configured to cause the other element to perform all functions, or more than one element may collectively be configured to cause the other element to perform the functions.

[0144] Where reference is made to an entity (e.g., any entity or device described herein) performing functions or being configured to perform functions (e.g., steps of a method), the entity may be configured to cause one or more elements (individually or collectively) to perform the functions. The one or more components of the entity may include at least one memory, at least one processor, at least one communication interface, another component configured to perform one or more (or all) of the functions, and / or any combination thereof. Where reference to the entity performing functions, the entity may be configured to cause one component to perform all functions, or to cause more than one component to collectively perform the functions. When the entity is configured to cause more than one component to collectively perform the functions, each function need not be performed by each of those components (e.g., different functions may be performed by different components) and / or each function need not be performed in whole by only one component (e.g., different components may perform different sub-functions of a function).

[0145] The various illustrative logical blocks, modules, engines, circuits, and algorithm steps described in connection with the embodiments disclosed herein may be implemented asPATENTQualcomm Ref. No. 2403790WO45 electronic hardware, computer software, firmware, or combinations thereof. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, engines, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present application.

[0146] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices such as general purposes computers, wireless communication device handsets, or integrated circuit devices having multiple uses including application in wireless communication device handsets and other devices. Any features described as engines, modules, or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be realized at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed, performs one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer- readable medium may comprise memory or data storage media, such as random access memory (RAM) such as synchronous dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), FLASH memory, magnetic or optical data storage media, and the like. The techniques additionally, or alternatively, may be realized at least in part by a computer-readable communication medium that carries or communicates program code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer, such as propagated signals or waves.

[0147] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general purposePATENTQualcomm Ref. No. 2403790WO46 microprocessors, an application specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Such a processor may be configured to perform any of the techniques described in this disclosure. A general purpose processor may be a microprocessor; but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Accordingly, the term “processor,” as used herein may refer to any of the foregoing structure, any combination of the foregoing structure, or any other structure or apparatus suitable for implementation of the techniques described herein. In addition, in some aspects, the functionality described herein may be provided within dedicated software modules or hardware modules configured for encoding and decoding, or incorporated in a combined video encoder-decoder (CODEC).

[0148] Illustrative aspects of the disclosure include:

[0149] Aspect 1. An apparatus for determining a camera swap at the apparatus, the apparatus comprising: a memory; and a processor coupled to the memory and configured to: receive, on a port of the apparatus from a first camera, encrypted information; determine that the apparatus is unable to decrypt the encrypted information using a key stored at the apparatus; determine, based on determining that the apparatus is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the apparatus that previously had a second camera connected; and reject the first camera for operation using the port.

[0150] Aspect 2. The apparatus of Aspect 1, wherein the key is associated with the second camera.

[0151] Aspect 3. The apparatus of any of Aspects 1 or 2, wherein the key is one of: a traffic key (TK); a random number; generated by the apparatus using a key derivation function (KDF) based on the random number; or generated by the apparatus using the KDF based on the random number and the TK.PATENTQualcomm Ref. No. 2403790WO47

[0152] Aspect 4. The apparatus of Aspect 3, wherein the TK is pre-programmed into the apparatus during manufacturing of the apparatus.

[0153] Aspect 5. The apparatus of any of Aspects 3 or 4, wherein the processor is configured to generate the random number during runtime operation of the apparatus.

[0154] Aspect 6. The apparatus of any of Aspects 1 to 5, wherein the processor is configured to determine that the apparatus is able to decrypt the encrypted information using a key of one or more additional keys stored at the apparatus to produce decrypted information.

[0155] Aspect 7. The apparatus of Aspect 6, wherein the processor is configured to determine, based on determining that the apparatus is able to decrypt the encrypted information using the key of the one or more additional keys to produce the decrypted information, an identity of the first camera connected to the port of the apparatus.

[0156] Aspect 8. The apparatus of any of Aspects 6 or 7, wherein the decrypted information comprises data obtained by the first camera and a message authentication code (MAC) associated with the first camera.

[0157] Aspect 9. The apparatus of any of Aspects 1 to 8, wherein the apparatus is a system on a chip (SOC).

[0158] Aspect 10. An apparatus for determining a camera swap at the apparatus, the apparatus comprising: a memory; and a processor coupled to the memory and configured to: receive, on a port of the apparatus from a first camera, information associated with the first camera; determine the information does not match attributes of a second camera; determine, based on the information not matching the attributes of the second camera, the first camera is connected to the port of the apparatus that previously had the second camera connected; and reject the first camera for operation using the port.

[0159] Aspect 11. The apparatus of Aspect 10, wherein the information associated with the first camera comprises sensor-specific information associated with the first camera or a certificate comprising the sensor-specific information associated with the first camera.PATENTQualcomm Ref. No. 2403790WO48

[0160] Aspect 12. The apparatus of Aspect 11, wherein the sensor-specific information comprises at least one of capabilities associated with the first camera, a manufacturer of the first camera, a make of the first camera, a model of the first camera, a serial number of the first camera, or a unique identifier (UID) of the first camera.

[0161] Aspect 13. The apparatus of Aspect 12, wherein the capabilities comprise at least one of a resolution of the apparatus or a maximum frame rate of the apparatus.

[0162] Aspect 14. The apparatus of any of Aspects 10 to 13, wherein the information comprises a random number.

[0163] Aspect 15. The apparatus of Aspect 14, wherein fuses of the apparatus and the first camera are blown based on the random number.

[0164] Aspect 16. The apparatus of any of Aspects 14 or 15, wherein the processor is configured to receive a license authorizing replacement of the first camera on the port of the apparatus with another camera.

[0165] Aspect 17. The apparatus of any of Aspects 10 to 16, wherein the processor is configured to determine, based on the information, an identity of the first camera connected to the port of the apparatus.

[0166] Aspect 18. The apparatus of any of Aspects 10 to 17, wherein the processor is configured to send, to the first camera, a request for the information associated with the first camera.

[0167] Aspect 19. The apparatus of any of Aspects 10 to 18, wherein the apparatus is a system on a chip (SOC).

[0168] Aspect 20. A method for determining a camera swap at a device, the method comprising: receiving, on a port of the device from a first camera, encrypted information; determining that the device is unable to decrypt the encrypted information using a key stored at the device; determining, based on determining that the device is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the devicePATENTQualcomm Ref. No. 2403790WO49 that previously had a second camera connected; and rejecting the first camera for operation using the port.

[0169] Aspect 21. The method of Aspect 20, wherein the key is associated with the second camera.[00170J Aspect 22. The method of any of Aspects 20 or 21, wherein the key is one of: a traffic key (TK); a random number; generated by the device using a key derivation function (KDF) based on the random number; or generated by the device using the KDF based on the random number and the TK.

[0171] Aspect 23. The method of Aspect 22, wherein the TK is pre-programmed into the device during manufacturing of the device.

[0172] Aspect 24. The method of any of Aspects 22 or 23, wherein the random number is generated during runtime operation of the device.

[0173] Aspect 25. The method of any of Aspects 20 to 24, further comprising determining that the device is able to decrypt the encrypted information using a key of one or more additional keys stored at the device to produce decrypted information.

[0174] Aspect 26. The method of Aspect 25, further comprising determining, based on determining that the device is able to decrypt the encrypted information using the key of the one or more additional keys to produce the decrypted information, an identity of the first camera connected to the port of the device.

[0175] Aspect 27. The method of any of Aspects 25 or 26, wherein the decrypted information comprises data obtained by the first camera and a message authentication code (MAC) associated with the first camera.

[0176] Aspect 28. The method of any of Aspects 20 to 27, wherein the device is a system on a chip (SOC).PATENTQualcomm Ref. No. 2403790WO50

[0177] Aspect 29. A method for determining a camera swap at a device, the method comprising: receiving, on a port of the device from a first camera, information associated with the first camera; determining the information does not match attributes of a second camera; determining, based on the information not matching the attributes of the second camera, the first camera is connected to the port of the device that previously had the second camera connected; and rejecting the first camera for operation using the port.

[0178] Aspect 30. The method of Aspect 29, wherein the information associated with the first camera comprises sensor-specific information associated with the first camera or a certificate comprising the sensor-specific information associated with the first camera.

[0179] Aspect 31. The method of Aspect 30, wherein the sensor-specific information comprises at least one of capabilities associated with the first camera, a manufacturer of the first camera, a make of the first camera, a model of the first camera, a serial number of the first camera, or a unique identifier (UID) of the first camera.

[0180] Aspect 32. The method of Aspect 31, wherein the capabilities comprise at least one of a resolution of the device or a maximum frame rate of the device.

[0181] Aspect 33. The method of any of Aspects 29 to 32, wherein the information comprises a random number.

[0182] Aspect 34. The method of Aspect 33, wherein fuses of the device and the first camera are blown based on the random number.

[0183] Aspect 35. The method of any of Aspects 33 or 34, further comprising receiving a license authorizing replacement of the first camera on the port of the device with another camera.

[0184] Aspect 36. The method of any of Aspects 29 to 35, further comprising determining, based on the information, an identity of the first camera connected to the port of the device.

[0185] Aspect 37. The method of any of Aspects 29 to 36, further comprising sending, to the first camera, a request for the information associated with the first camera.PATENTQualcomm Ref. No. 2403790WO51

[0186] Aspect 38. The method of any of Aspects 29 to 37, wherein the device is a system on a chip (SOC).

[0187] Aspect 39. A non-transitory computer-readable medium having stored thereon instructions that, when executed by at least one processor, cause the at least one processor to perform operations according to any of Aspects 10 to 19.

[0188] Aspect 40. An apparatus for determining a camera swap at the apparatus, the apparatus including one or more means for performing operations according to any of Aspects 10 to 19.

[0189] Aspect 41. A non-transitory computer-readable medium having stored thereon instructions that, when executed by at least one processor, cause the at least one processor to perform operations according to any of Aspects 29 to 38.

[0190] Aspect 42. An apparatus for determining a camera swap at the apparatus, the apparatus including one or more means for performing operations according to any of Aspects 29 to 38.

[0191] The previous description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other aspects. Thus, the claims are not intended to be limited to the aspects shown herein, but is to be accorded the full scope consistent with the language claims, wherein reference to an element in the singular is not intended to mean “one and only one” unless specifically so stated, but rather “one or more.”

Claims

PATENTQualcomm Ref. No. 2403790WO52CLAIMSWhat is claimed is:

1. An apparatus for determining a camera swap at the apparatus, the apparatus comprising: a memory; and a processor coupled to the memory and configured to: receive, on a port of the apparatus from a first camera, encrypted information; determine that the apparatus is unable to decrypt the encrypted information using a key stored at the apparatus; determine, based on determining that the apparatus is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the apparatus that previously had a second camera connected; and reject the first camera for operation using the port.

2. The apparatus of claim 1, wherein the key is associated with the second camera.

3. The apparatus of claim 1, wherein the key is one of: a traffic key (TK); a random number; generated by the apparatus using a key derivation function (KDF) based on the random number; or generated by the apparatus using the KDF based on the random number and the TK.

4. The apparatus of claim 3, wherein the TK is pre-programmed into the apparatus during manufacturing of the apparatus.

5. The apparatus of claim 3, wherein the processor is configured to generate the random number during runtime operation of the apparatus.PATENTQualcomm Ref. No. 2403790WO536. The apparatus of claim 1, wherein the processor is configured to determine that the apparatus is able to decrypt the encrypted information using a key of one or more additional keys stored at the apparatus to produce decrypted information.

7. The apparatus of claim 6, wherein the processor is configured to determine, based on determining that the apparatus is able to decrypt the encrypted information using the key of the one or more additional keys to produce the decrypted information, an identity of the first camera connected to the port of the apparatus.

8. The apparatus of claim 6, wherein the decrypted information comprises data obtained by the first camera and a message authentication code (MAC) associated with the first camera.

9. The apparatus of claim 1, wherein the apparatus is a system on a chip (SOC).

10. An apparatus for determining a camera swap at the apparatus, the apparatus comprising: a memory; and a processor coupled to the memory and configured to: receive, on a port of the apparatus from a first camera, information associated with the first camera; determine the information does not match attributes of a second camera; determine, based on the information not matching the attributes of the second camera, the first camera is connected to the port of the apparatus that previously had the second camera connected; and reject the first camera for operation using the port.

11. The apparatus of claim 10, wherein the information associated with the first camera comprises sensor-specific information associated with the first camera or a certificate comprising the sensor-specific information associated with the first camera.PATENTQualcomm Ref. No. 2403790WO5412. The apparatus of claim 11, wherein the sensor-specific information comprises at least one of capabilities associated with the first camera, a manufacturer of the first camera, a make of the first camera, a model of the first camera, a serial number of the first camera, or a unique identifier (UID) of the first camera.

13. The apparatus of claim 12, wherein the capabilities comprise at least one of a resolution of the apparatus or a maximum frame rate of the apparatus.

14. The apparatus of claim 10, wherein the information comprises a random number.

15. The apparatus of claim 14, wherein fuses of the apparatus and the first camera are blown based on the random number.

16. The apparatus of claim 14, wherein the processor is configured to receive a license authorizing replacement of the first camera on the port of the apparatus with another camera.

17. The apparatus of claim 10, wherein the processor is configured to determine, based on the information, an identity of the first camera connected to the port of the apparatus.

18. The apparatus of claim 10, wherein the processor is configured to send, to the first camera, a request for the information associated with the first camera.

19. The apparatus of claim 10, wherein the apparatus is a system on a chip (SOC).

20. A method for determining a camera swap at a device, the method comprising: receiving, on a port of the device from a first camera, encrypted information; determining that the device is unable to decrypt the encrypted information using a key stored at the device;PATENTQualcomm Ref. No. 2403790WO55 determining, based on determining that the device is unable to decrypt the encrypted information using the key, that the first camera is connected to the port of the device that previously had a second camera connected; and rejecting the first camera for operation using the port.

Citation Information

Patent Citations

  • Signal processing device, signal processing method, and program

    US20220237305A1