Vocabulary
A measurement on the object is verified against reference data.
- Note: the reference data itself allows an attacker to artificially construct measurement data that will pass the identification test, even if the object itself it not available for the test.
The reference data gives insufficient information to construct a possible valid measurement data, unless a certain a known, large computational effort is invested.
The object data is measured by a trusted third party, the measurements are processed and stored for later use, that is, to allow verification.
If the secret has been compromised: take a new one