This approach assumes that the smartphone in question is not under the user’s control. That should generally not be the case. When I buy a device, I have the right to install whatever I want on it and to make the camera sensors believe whatever I want. If something cannot be implemented securely under these circumstances, it’s not a good idea, and other solutions are needed. I once tested a video identification syste…
I don’t think there any many people out there with the right equipment to carefully ablate the top of a sensor off, so they can directly inject their own data into the start of signing process. It’s not impossible, but it’s also not the kind of thing most people and organisations are going to be capable of doing.
> The creation of a secure digital negative begins with a secure boot of the camera sensor into a specialized reference capture mode. The mode instructs the sensor to cryptographically sign pixel data immediately after capture, and prevents the sensor firmware from modifying the data.