On-Sensor Privacy Circuit for Raw Image Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Image sensors face security risks due to the potential for malicious attacks on wired transmission lines and downstream hardware, which can compromise sensitive image data, especially when encryption is not ideal for configuration or operation.

Innovation Solution

An image sensor with an on-sensor controller and a privacy control circuit that includes a multiplexer for selecting between raw data and privacy-preserving data, along with an on-sensor processor for obfuscating sensitive data through encryption and other methods, and a one-time data protection circuitry to prevent access to raw image data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If raw image data is transmitted over wired transmission lines, then data transmission capability is improved, but security against malicious attacks deteriorates

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidsecurity risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the data transmission system into two separate data paths: a first data path for raw image data and a second data path for processed image data. This segmentation allows the system to transmit different types of data through different channels, enabling security protection by destroying access to the raw data path while maintaining the processed data path for safe transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts sensitive raw image data from the transmission system by providing a separate processed data path that contains only necessary information. The one-time programmable fuse destroys access to the raw data path, effectively taking out the security vulnerability while preserving the functional need for data transmission through the processed path.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 3:

The patent implements preliminary security action by incorporating a one-time programmable fuse in the first data path that can be activated to destroy access to raw image data. This preliminary protective measure ensures that even if the transmission line is compromised, the sensitive raw data cannot be accessed or stolen.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If encryption is used to protect data, then security is improved, but ease of operation deteriorates due to configuration complexity

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent uses a one-time programmable fuse that can be activated once to permanently destroy access to the raw data path. This disposable security mechanism provides strong protection without requiring complex ongoing encryption management or configuration, as the security measure is set once and cannot be changed, eliminating configuration complexity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent replaces software-based encryption mechanisms with a hardware-based one-time programmable fuse. This substitution eliminates the need for complex encryption key management, algorithm configuration, and software updates, providing security through a simple hardware mechanism that is easier to operate and configure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If one-time data protection circuitry is activated to disable raw data access, then security is improved, but adaptability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata path flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments the data transmission system into two independent paths: the first data path for raw image data with one-time protection, and the second data path for processed image data. This segmentation allows the system to activate security on the first path without affecting the functionality of the second path, maintaining adaptability while improving security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a dynamic data transmission system where the first data path can be selectively destroyed via the one-time programmable fuse, while the second data path remains continuously available. This dynamic capability allows the system to adapt its security posture based on operational needs, destroying raw data access when security is prioritized while maintaining processed data transmission for ongoing operations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12348697B1On-sensor data guardian
Publication Date: 2025.07.01 META PLATFORMS TECHNOLOGIES LLC
  • US12348697B1 patent drawing
  • US12348697B1 patent drawing
  • US12348697B1 patent drawing

AI summary

The present disclosure provides a privacy control circuit including an array of pixel cells having a first output data path and a second output data path, the first output data path including a one-time data protection circuitry, a sensor communication interface communicatively coupled to the first output data path, an on-sensor processor coupled to the second output data path and communicatively attached to the sensor communication interface, and a data register communicatively attached to the sensor communication interface.