Protocol and system for tee-based authenticating and editing of mobile-device captured visual and audio media
In general, one aspect disclosed features a media asset capture and processing method, implemented via a computer-based state machine executing on a computer processor, the method comprising: implementing a first phase including media asset capture and frame processing limited to Rich Execution Environment (REE) read-only (RO) frame access; implementing a second phase including processing with REE read-write (RW) frame access; and implementing a third phase including processing with REE read-only (RO) frame access.
1 . A media asset capture and processing method, implemented by an electronic device, the method comprising:
capturing a media asset in an electronic device;
storing frame buffer objects of the captured media asset in a Trusted Execution Environment (TEE) of the electronic device;
subsequent to storing the frame buffer objects, processing the media asset in a Rich Execution Environment (REE) of the electronic device in a first state with read-only (RO) access to the stored frame buffer objects and a second state with read-write (RW) access to the stored frame buffer objects;
controlling, in the TEE, the RO and RW access by the REE to the stored frame buffer objects during processing of the media asset; and
subsequent to processing the media asset, authenticating the processed media asset in the TEE.
2 . The method of claim 1 , wherein controlling the RO and RW access by the REE to the stored frame buffer objects comprises:
receiving a first call sent by the REE to grant the RW access to the frame buffer objects to the REE; and
responsive to the first call, granting the RW access to the stored frame buffer objects to the REE.
3 . The method of claim 2 , wherein granting the RW access to the stored frame buffer objects to the REE comprises:
updating a hardware page table attribute.
4 . The method of claim 2 , wherein controlling the RO and RW access by the REE to the stored frame buffer objects further comprises:
receiving a second call sent by the REE to withdraw the RW access to the frame buffer objects from the REE; and
responsive to the second call, withdrawing the RW access to the stored frame buffer objects from the REE.
5 . The method of claim 4 , wherein withdrawing the RW access to the stored frame buffer objects from the REE comprises:
updating a hardware page table attribute.
6 . The method of claim 1 , wherein processing the media asset in the REE of the electronic device in a first state comprises:
generating earliest viable image (EVI) objects of the media asset.
7 . The method of claim 6 , wherein authenticating the processed media asset in the TEE comprises:
generating thumbnail images of the EVI objects;
attaching individual ones of the thumbnail images to corresponding EVI objects; and
attaching metadata to the EVI objects, wherein the metadata comprises at least one of data, time, or depth information.
8 . A system, comprising:
one or more hardware processors; and
one or more non-transitory machine-readable storage media encoded with instructions that, when executed by the one or more hardware processors, cause the system to perform operations for media asset capture and processing, the operations comprising:
capturing a media asset in an electronic device;
storing frame buffer objects of the captured media asset in a Trusted Execution Environment (TEE) of the electronic device;
subsequent to storing the frame buffer objects, processing the media asset in a Rich Execution Environment (REE) of the electronic device in a first state with read-only (RO) access to the stored frame buffer objects and a second state with read-write (RW) access to the stored frame buffer objects;
controlling, in the TEE, the RO and RW access by the REE to the stored frame buffer objects during processing of the media asset; and
subsequent to processing the media asset, authenticating the processed media asset in the TEE.
9 . The system of claim 8 , wherein controlling the RO and RW access by the REE to the stored frame buffer objects comprises:
receiving a first call sent by the REE to grant the RW access to the frame buffer objects to the REE; and
responsive to the first call, granting the RW access to the stored frame buffer objects to the REE.
10 . The system of claim 9 , wherein granting the RW access to the stored frame buffer objects to the REE comprises:
updating a hardware page table attribute.
11 . The system of claim 9 , wherein controlling the RO and RW access by the REE to the stored frame buffer objects further comprises:
receiving a second call sent by the REE to withdraw the RW access to the frame buffer objects from the REE; and
responsive to the second call, withdrawing the RW access to the stored frame buffer objects from the REE.
12 . The system of claim 11 , wherein withdrawing the RW access to the stored frame buffer objects from the REE comprises:
updating a hardware page table attribute.
13 . The system of claim 8 , wherein processing the media asset in the REE of the electronic device in a first state comprises:
generating earliest viable image (EVI) objects of the media asset.
14 . The system of claim 13 , wherein authenticating the processed media asset in the TEE comprises:
generating thumbnail images of the EVI objects;
attaching individual ones of the thumbnail images to corresponding EVI objects; and
attaching metadata to the EVI objects, wherein the metadata comprises at least one of data, time, or depth information.
15 . One or more non-transitory machine-readable storage media encoded with instructions that, when executed by one or more hardware processors, cause a system to perform operations for media asset capture and processing, the operations comprising:
capturing a media asset in an electronic device;
storing frame buffer objects of the captured media asset in a Trusted Execution Environment (TEE) of the electronic device;
subsequent to storing the frame buffer objects, processing the media asset in a Rich Execution Environment (REE) of the electronic device in a first state with read-only (RO) access to the stored frame buffer objects and a second state with read-write (RW) access to the stored frame buffer objects;
controlling, in the TEE, the RO and RW access by the REE to the stored frame buffer objects during processing of the media asset; and
subsequent to processing the media asset, authenticating the processed media asset in the TEE.
16 . The media of claim 15 , wherein controlling the RO and RW access by the REE to the stored frame buffer objects comprises:
receiving a first call sent by the REE to grant the RW access to the frame buffer objects to the REE; and
responsive to the first call, granting the RW access to the stored frame buffer objects to the REE.
17 . The media of claim 16 , wherein granting the RW access to the stored frame buffer objects to the REE comprises:
updating a hardware page table attribute.
18 . The media of claim 16 , wherein controlling the RO and RW access by the REE to the stored frame buffer objects further comprises:
receiving a second call sent by the REE to withdraw the RW access to the frame buffer objects from the REE; and
responsive to the second call, withdrawing the RW access to the stored frame buffer objects from the REE.
19 . The media of claim 15 , wherein processing the media asset in the REE of the electronic device in a first state comprises:
generating earliest viable image (EVI) objects of the media asset.
20 . The media of claim 19 , wherein authenticating the processed media asset in the TEE comprises:
generating thumbnail images of the EVI objects;
attaching individual ones of the thumbnail images to corresponding EVI objects; and
attaching metadata to the EVI objects, wherein the metadata comprises at least one of data, time, or depth information.