Quantum physical unclonable functions method, protocol and apparatus
Patent Information
- Application Number
- JP2024529448
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-07-22
- Filing Date
- 2022-07-22
- Publication Date
- 2026-05-13
AI Technical Summary
Existing PUF protocols are vulnerable to digital emulation attacks, machine learning attacks, quantum computer attacks, and CRP database attacks, and require large memory for quantum readout PUFs, relying on trusted equipment.
A quantum physical unclonable function (QPUF) protocol using quantum entanglement and superposition to generate unique signatures between devices, eliminating the need for a secure codebook and enabling public storage of correlation information.
Provides unconditionally secure device authentication resistant to digital and quantum attacks, reducing memory requirements and eliminating the need for trusted equipment.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] STATEMENT REGARDING FEDERALLY SPONSORED RESEARCH OR DEVELOPMENT none
[0002] Cross-Reference to Related Applications This application claims priority to U.S. Provisional Patent Application No. 63 / 224,820, filed July 22, 2021, the disclosure of which is incorporated herein by reference in its entirety.
[0003] The present invention relates to information security, and more particularly to quantum physical unclonable functions (QPUFs) for device authentication, identification, verification, secure communications, and proof of existence. [Background technology]
[0004] Methods of storing secret information in modern communications using digital memories cannot be proven unconditionally secure, because they can be altered, forged, or stolen. Thus, security is not guaranteed when a communication node identifies itself by providing "secret knowledge" instead of "physically presenting its unsubstitutable uniqueness". The latest technique to verify the integrity and authenticity of a device is to embed a physical unclonable function (PUF) in the hardware to act as a "fingerprint". PUFs derive their inherent randomness from delicate manufacturing processes at the micro- or nano-scale, such as threshold voltage mismatches in transistors (i.e., SRAM-PUF), the physical orientation of an accelerometer that responds to different electrostatic impulses (MEMS-PUF), or optical interactions in chaotic silicon microcavities. This scheme means that given different inputs into a PUF device, the different outputs will not only be unique and repeatable, but also non-deterministic. In other words, PUFs provide one-way functions that are cheap and easy to evaluate, but difficult to predict. Moreover, the task of reproducing an identical PUF is considered impractical even by the creators of PUFs due to uncontrollable errors in the manufacturing procedure.
[0005] Traditional methods for PUF protocols use challenge-response pairs (CRPs), where the response of each PUF device is measured when given different input challenges to generate one or many CRPs at the manufacturer. The list of CRPs is securely stored and considered as a "codebook" for each device. In the verification process, the challenge is repeated and if the corresponding response matches one in the "codebook", the device will be successfully authenticated. However, if an adversary gains access to the CRP information, PUF device authentication is no longer secure because the adversary can respond to queries without applying the challenge to the PUF. Therefore, protecting the CRP database from this type of digital emulation attack is a challenge in this scheme. Another type of attack is that if an adversary has physical access to the PUF device, he can still study the device even if he cannot clone it, and can collect some CRP information for further attacks. In addition to this, traditional PUF protocols are vulnerable to machine learning attacks. Even in the case of a powerful PUF device that generates a large number of CRPs, each of which is used only once, access to the device still gives an adversary the opportunity to use machine learning to predict unknown responses from the set of known CRPs that the adversary obtains.
[0006] There is one known method to realize device verification that is separate and independent of database secrecy, called quantum readout PUF. However, this protocol is not protected against quantum emulation attacks. Furthermore, quantum readout PUF requires a large amount of CRP memory, which is inconvenient to accommodate devices with limited memory. Another drawback with this protocol is that it relies on trusted devices. Summary of the Invention [Problem to be solved by the invention]
[0007] The method disclosed herein aims to provide a PUF protocol that is resistant to digital emulation attacks, machine learning attacks, quantum computer attacks, and CRP database attacks. [Means for solving the problem]
[0008] The disclosed embodiments take a different approach and provide an unconditionally secure method based on quantum physics, including quantum entanglement and quantum superposition. The present invention can serve as a next-generation authentication technique for credit card usage, banking systems, telecommunications, etc.
[0009] Traditionally, in the authentication process, the prover must demonstrate the uniqueness of the device, matching information in a CRP codebook known to the verifier. However, this protocol redefines what successful verification / authentication means by using a unique signature assembled from correlations obtained from the outputs of physical one-way functions from all communicating parties.
[0010] For example, at the time of manufacture, PUF-A, PUF-B, and PUF-C are measured to extract correlation information between them based on quantum entanglement, thereby generating measurement results in the form of signatures AB, AC, and BC. These signatures are stored in a public database and are known to all parties, thereby obviating the need for a secure database. By completely eliminating the need for any private codebook, the present invention eliminates a security loophole in conventional PUF protocols.
[0011] The three PUF devices (i.e., PUF-A, PUF-B, and PUF-C) are then distributed to users Alice, Bob, and Charles, respectively. To perform the mutual authentication process, Alice and Bob publicly perform a correlation measurement to build a unique signature between the two of them. If this signature matches the signature AB in the database, authentication will be successful. Similarly, when Alice wants to authenticate herself with Charles, or vice versa, they again perform a correlation measurement to build a unique, publicly known signature between the two of them, and then compare it with AC. Thus, the method allows each party to simultaneously authenticate themselves to each other and to the public as well. FIG. 1 shows an example of a QPUF database, which is essentially a storage of different QPUF patterns corresponding to their designated QPUFs. In one embodiment, the database can be stored and publicly accessible.
[0012] The disclosed invention provides a method for unconditionally secure QPUF, where the device signature is based on correlation measurements of quantum complementary variables (e.g., photon arrival time and carrier frequency) after entangled photons interact with optical chaos. In one embodiment, with energy-time degrees of freedom, the uniqueness of a device pair is defined as the intensity correlation of entangled photons in frequency and / or arrival time. The disclosed inventive protocol does not rely on trusted devices to complete successful authentication.
[0013] One implementation of the invention involves a laser source, an entangled photon source, a single-photon detector, a photonic chaos chip providing a physical one-way function, a photon arrival time measurement device, a photon frequency measurement device, and a public database of correlation measurement results.
[0014] In one embodiment, authentication can be performed through the steps of generating a set of entangled photons, sending each entangled photon to a corresponding one of the devices, each device implementing a corresponding physical unclonable function that jointly has a known quantum correlation signature, recording a response from each device based on its corresponding physical unclonable function, repeating the above steps to build up a verification pattern from the recorded responses, comparing the verification pattern to the known quantum correlation signature, and authenticating if a similarity threshold between the verification pattern and the known quantum correlation signature is achieved. In one embodiment, entanglement of the entangled photons is performed by periodically redirecting the entangled photons away from the device for purposes of verification.
[0015] In one embodiment, the quantum correlation signature is known and can be established, for example, by the manufacturer of the device.
[0016] In one embodiment, the authentication method is performed in a public channel.
[0017] In one embodiment, the quantum correlation signature may be based on the quantum complementary variables after the entangled photons interact with the optical chaos. For example, the optical chaos may be provided by a physical unclonable nanostructure of the respective device. In one embodiment, the physical unclonable nanostructure may comprise a chaotic light-transmitting medium. In one embodiment, the quantum complementary variables may be based on the photon arrival time and / or carrier frequency. In a further embodiment, the quantum correlation signature is defined based on the intensity correlation of the entangled photons in frequency and / or arrival time.
[0018] In one embodiment, the authentication method may utilize a reference signal transmitted continuously to each device.
[0019] In a further embodiment, the known quantum correlation signature is based on one or more of joint spectral intensity, joint temporal intensity, or joint spectro-temporal intensity.
[0020] In yet another embodiment, security can be enhanced by selectively maintaining at least some of the recorded responses in secrecy.
[0021] In one embodiment, the recorded responses are publicly announced to build up a verification pattern. Moreover, by encoding a confidential message as a recorded response by the sender and decoding the confidential message from said recorded response by the receiver, a method of secure communication as well as authentication can be realized. For example, the decoding step can be performed on the recorded responses by maximizing the similarity between the verification pattern when calculating the verification pattern. Meanwhile, the encoding step can be performed according to a publicly agreed protocol. For this purpose, the publicly agreed protocol could have a finite number of swapping actions. This would allow the decoding step to be performed by exhaustively trying all of the finite number of swapping actions.
[0022] For a more complete understanding of the present invention, reference should be had to the following detailed description of one embodiment, provided in connection with the accompanying drawings, in which: [Brief description of the drawings]
[0023] [Figure 1] Figure 1 shows an example of a QPUF database containing two QPUF patterns.
[0024] [Diagram 2] FIG. 2 is an example of a joint spectral intensity verification pattern.
[0025] [Diagram 3] FIG. 3 is another example of a joint spectral intensity verification pattern.
[0026] [Figure 4] FIG. 4 is a further example of a joint spectral intensity verification pattern.
[0027] [Diagram 5] FIG. 5 is yet another example of a joint spectral intensity verification pattern.
[0028] [Figure 6] FIG. 6 is an example of a joint time strength verification pattern.
[0029] [Figure 7] FIG. 7 is another example of a joint time strength verification pattern.
[0030] [Figure 8] FIG. 8 is a further example of a joint time strength verification pattern.
[0031] [Figure 9] FIG. 9 is yet another example of a joint time strength verification pattern.
[0032] [Figure 10] FIG. 10 is a schematic diagram illustrating an example of a two-party QPUF system.
[0033] [Figure 11] FIG. 11 shows one example of how a QPUF system may be implemented.
[0034] [Figure 12] FIG. 12 shows a further example of how a two-party QPUF system may be implemented. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0035] The following disclosure is presented to provide an illustration of the general principles of the present invention, and is not intended to limit in any manner the inventive concepts contained herein. Moreover, certain features described in this section can also be used in combination with other described features in each of the numerous possible permutations and combinations contained herein.
[0036] Every term defined in this specification is to be given its broadest possible interpretation, including not only any meaning implied by reference to the specification, but also any term that a person skilled in the art and / or a dictionary, treatise, or similar source would assign to it.
[0037] It should further be noted that the singular forms "a," "an," "the," and "one" described herein include plural references unless otherwise stated. In addition, while the terms "comprises" and "comprising," when used herein, specify that certain features are present in an embodiment, this phrase should not be interpreted as excluding the presence or addition of further steps, operations, features, components, and / or groups thereof.
[0038] All examples and conditional language described herein are intended for educational purposes to aid the reader in understanding the principles of the invention and the concepts contributed by the inventors to the advancement of the art, and should be construed as without limitation to such specifically described examples and conditions. Moreover, all claims herein that describe principles, aspects, and embodiments of the invention, as well as specific examples thereof, are intended to encompass both structural and functional equivalents thereof. In addition, such equivalents are intended to include both currently known equivalents as well as equivalents developed in the future, i.e., any elements developed that perform the same function, regardless of structure.
[0039] To better illustrate an exemplary QPUF protocol according to an embodiment of the present invention, definitions of joint spectral intensity (JSI), joint temporal intensity (JTI), joint spectral temporal intensity (JSTI), challenge-response pair (CRP), quantum entanglement process, PUF nanostructure, measurement synchronization, and threshold verification are provided below.
[0040] JSI refers to the two-photon correlation function (i.e., the correlation of its carrier frequency) measured at each spectral state. JTI refers to the two-photon correlation function (i.e., the correlation of its arrival time) measured at each time state. JSTI refers to the two-photon correlation function (i.e., the correlation of one carrier frequency with the other arrival time) measured at one spectral state and the other time state. CRP refers to the input state and expected output state paired with the PUF. For the purposes of this disclosure, a quantum entanglement process is any process in which two or more objects are subjected to intrinsic quantum non-local correlations. A PUF device contains a PUF nanostructure with intrinsic imperfections and / or uncontrollable random features that cannot be replicated by any manufacturing means. Measurement synchronization is the process for synchronizing the timestamps of distant communicating parties so that JTI, JST, and / or JSTI can be performed successfully. Threshold verification is a test that will return a positive verification result if the measured quantity is above a certain threshold.
[0041] In Fig. 10, a schematic diagram of the QPUF protocol is given. At the manufacturer, the QPUF-CRP is collected by measuring the JSI, JTI, or mixed JSTi of entangled photons after they are sent through different PUF nanostructures to allow for chaotic responses. Given the consistency of components (e.g., filters, single photon detectors, arrival time converters, etc.) between the combination of PUF devices, the energy and momentum conservation of the entangled photon generation process guarantees an invariant correlation pattern of JSI, JTI, and JSTi. In every authentication attempt, these patterns are constructed by collecting a different set of truly random and uncontrollable sequences of data points according to the local measurements of each communicating party's photons after their interaction with the individual PUFs due to quantum superposition. As a result, the JSI / JTI / JSTI generated after the entangled photons pass through the PUF form a unique joint pattern, yet all the measurement data are one-time padded. This feature allows the CRP database, which may be generated at the time of manufacture, to be stored in a publicly accessible manner without compromising security. Thus, unlike traditional PUFs where a device is instrumented to generate many CRPs at the time of manufacture, the QPUF protocol requires only one pattern.
[0042] The proposed protocol can be used independent of the nanostructure of the PUF or the physical basis of the PUF. The PUF device can have any type of structure that provides a photonic chaotic response that is highly complex and unpredictable, yet reproducible when given the same input. Such nanostructures have been designed and shown to fulfill the required PUF properties. In some embodiments, a chaotic optical transmission medium can function as a PUF for the purpose of secure authentication.
[0043] The REF-ID can be used by the communicating / verifying parties to align coincident measurements. For the purposes of this disclosure, the REF-ID is a reference identification number and / or pulse index that represents the time slot number of the detected photon, regardless of whether it is detected in time or frequency. To enable a common REF-ID, all parties in the communication pool are synchronized to a common reference signal to identify its detected photon time slot. Such a reference signal can be provided through the same optical communication channel (i.e., quantum optical communication channel) that is being used to distribute the entangled photons. Such a channel can leverage the same telecommunication fiber infrastructure that exists today. Also, in the future, such communication channels are predicted to become prevalent due to the anticipated future adoption of quantum information technology. In some embodiments, the reference can have the form of an optical pulse train that is split and distributed over optical fiber or free space communication. The system needs to be set up such that at most one entangled photon pair can be generated in each period of the reference pulse. Thus, if a communicating party receives a photon entangled with another photon, they will have a high likelihood of being detected in the same time slot. The verification pattern is made up of many quantum states that are bounded in frequency or time. To this end, the REF-ID serves as a synchronization mechanism that allows identification of which photon belongs to which entangled state.
[0044] The source of entangled photons may come from a verifier, a third party, a service provider, or the public. Photon entanglement needs to be verified before and during its use for the QPUF. This can be performed bilaterally between user A and user B in a manner similar to entanglement verification during a normal quantum key distribution protocol. It can also be performed through a public verifier. In an exemplary embodiment, entanglement verification is performed by bypassing the PUF and having user A and user B construct a JSI and a JTI, respectively. This verification exploits the fact that only truly entangled photons will result in an inseparable JSI and JTI simultaneously. Such JSI and JTI may be publicly known. The JSI and JTI are independent of transmission losses, but they depend on the characteristics of the source used and the resolution of the measurement device.
[0045] To prevent dishonest parties from cheating during entanglement verification, each party can be controlled to share only about half of its photon counting results with each other, while keeping the other half for verification purposes. For security reasons, in some embodiments, the QPUF only continues when both parties agree on entanglement verification. In an exemplary embodiment, such verification is performed during the QPUF process by using a passive or active switch to bypass the PUF. To this end, users A and B can randomly select some pulses to bypass the PUF and be used only for entanglement verification purposes.
[0046] Assuming successful entanglement verification, users A and B can publicly announce their reference IDs. They will first compare the IDs and select the matches (i.e., IDs that appear on both users A and B's lists). They will then split the matching IDs into two approximately equal subgroups. User A will publicly report its measurements (e.g., time or frequency) for all reference IDs in one subgroup, and user B will report on the other subgroup. This reporting arrangement can be performed on a public channel. Once these results are announced, users can proceed by checking the announced measurements with their individual private results by comparing them to public patterns (i.e., database signatures).
[0047] To complete the final verification, the similarity between the public database signature and the measured (i.e., calculated) signature is calculated, and if the similarity is above an established threshold, the verification succeeds, and if it is below the threshold, it fails. The threshold is determined by the properties of the PUF being used so that an alternative PUF device cannot be used to generate a signature above the threshold. The threshold requires a certain value of photon count statistics to suppress inherent photon counting noise and possible detector dark counts.
[0048] Losses during transmission will impact the length of time of the verification process: entangled photons must be transmitted continuously until such time that photon count statistics are obtained, allowing enough information to be compared with unique identifiers / responses in a public database.
[0049] Example 1: For the sake of clarity, the following description will assume that the authentication process involves only two parties, but it should be noted that the method of the present invention can be applied to perform authentication with more than two parties simultaneously as well. This can be achieved by using a higher level of nonlinearity, for example, generating three entangled photons in the case of three parties, four entangled photons in the case of four parties, etc. Figure 10 shows an example of a QPUF protocol between two parties A and B. Below are the steps of the QPUF protocol, where parties A and B wish to authenticate each other, or where A or B wishes to prove its identity to the public. In other embodiments, party A can prove its identity to party B, and vice versa.
[0050] Step 1: A and B publicly announce that they wish to perform authentication to each other.
[0051] Step 2: Entangled photons are sent to parts A and B.
[0052] In this step, both sides of the entangled photon will be randomly switched to bypass the PUF and enter directly into the JSI, JTI, or JSTI measurement. The event of an entangled photon bypassing the PUF will be publicly announced, and the JSI, JTI, and JSTI results will be constructed to verify the entanglement. As a security feature, the authentication can be immediately terminated if the verification fails.
[0053] Step 3: Parties A and B individually measure the entangled photons in time or frequency. Figure 10 is an example of a two-party QPUF protocol system setup. As mentioned above, photon properties can be measured in time or frequency. The measurement resolution has an impact on the number of pixels that must be agreed upon by all communicating parties in the verification pattern to successfully authenticate.
[0054] Step 4: Both parties A and B announce the REF-ID of their photon, which is followed by the measurement result.
[0055] Step 5: A verification pattern is constructed in the public channel by using the response of each PUF device. In some embodiments, the information from the laser and entanglement source can be written as the following equation:
[0056] φ(ω_s,ω_i)=ψ(ω_s,ω_i)√(p_1(ω_s))√(p_2(ω_i)) (1)
[0057] where ψ(ω_s,ω_i) is an entangled photon state that can be a product of the spectral profile of the pump photons, the phase matching of the nonlinear medium, the filters, etc. This information is publicly announced and stored and maintained in a consistent state in the database signature generation and identity verification process. From the database, p_1(ω_s), p_2(ω_i) are the PFU responses of each communication end. Thus, a joint spectral intensity verification pattern φ(ω_s,ω_i) is derived and used as a unique "fingerprint" between parties A and B. Similarly, other verification patterns can be formed by using the time domain by constructing φ(t_s,t_i) or by using mixed time and frequency domain by constructing φ(ω_s,t_i) or φ(t_s,ω_i). Figure 1 shows examples of verification patterns, where the grayscale coloring represents the intensity (e.g., time intensity, spectral intensity, etc.).
[0058] Step 6: The public channel collects measurements from parties A and B to construct a verification pattern. Due to the superposition property of quantum mechanics, photons are in all states simultaneously until the moment they are measured, and the results are essentially random because they are equally likely to collapse into any possible state. Although every successful authentication returns the same verification pattern, each series of measurements from A and B is random every time. Thus, knowledge of the verification pattern does not provide any useful information for an adversary to attack or deceive or perform any brute force search methods.
[0059] Step 7: The verification pattern is compared with the one stored in the public database to obtain the difference. If this difference is less than the error threshold, the authentication is successful.
[0060] In the following, the system requirements to guarantee an unconditionally secure authentication protocol are described. First, the PUF device must fulfill all PUF requirements: physically unclonable, provide reproducible responses, and provide unique responses. However, it does not have to be unpredictable. For example, machine learning or quantum computer attacks can only predict the response of the PUF device. On the other hand, successful authentication or verification relies on joint measurements, which are truly random due to quantum mechanics. Second, the pump photons must be kept at a low power level to avoid the generation of multiple pairs of entangled photons. Third, the witnessing of entanglement must be verified in the process. Finally, the number of possible photon states in time or frequency must be large enough to generate a sufficient number of possible unique identifiers to avoid different PUF devices returning the same unique joint identifier. Given n possible states for party A, m possible states for party B, and k possible joint intensity levels that can be unambiguously resolved (given sufficient detected photon count statistics), the total possible unique identifiers is P=k^((nxm)). If k=100, as in the usual coincidence-randomness ratio (CAR) case used in quantum key distribution systems, and n=m=5, then P=
[10] ^50, which is roughly equal to the total number of particles on Earth.
[0061] Example 2: In some applications, the same QPUF verification system can be used simultaneously for verification and secure communication. In one embodiment, user A will shuffle / swap / change the index of his measurement results before announcement. User B will try to unshuffle / unswap / unchange the results to maximize the similarity of the measured signature with the database signature. User A's identity is verified if the maximum similarity is above a threshold. Meanwhile, user B will know how user A shuffled / swapped the measurement results, and from this users A and B can communicate certain information securely.
[0062] As a general example, user A's original measurement results are (1,3,4,3,2,4), each of which represents time or frequency according to a certain publicly agreed indexing protocol. User A wants to prove his identity to user B while sending the message "11" or "00". For this purpose, user A will publicly announce that he will swap index 1 with 3 if the message is "11", and 1 with 4 if the message is "00". According to this protocol, user A will announce his measurement results as (3,1,4,1,2,4). After receiving user A's measurements, user B will try two swapping actions and combine them with user B's own measurements to find out whether any action gives a similar pattern and passes a similarity threshold test. If the test is passed, user B will not only verify user A's identity but also get the correct message.
[0063] Many other ways of coding information exist, but such information needs to be well-defined and not so complex that User B can exhaustively try all possible encoding protocols.
[0064] It should be understood that the embodiments described herein are for illustrative purposes only, and that those skilled in the art may make many variations and modifications without departing from the spirit and scope of the invention, and all such variations and modifications are to be understood as falling within the scope of the invention.
Claims
1. A secure authentication method, i) A step in which a quantum entangled photon source generates multiple quantum entangled photons, ii) The step of the entangled photon source transmitting each of the plurality of entangled photons to at least a corresponding device of a pair of devices, each device of the pair of devices implementing a corresponding physical cloning-non-function, the physical cloning-non-function of the pair of devices having a known quantum correlation signature determined based on the quantum complementary variables after the entangled photons have interacted with optical chaos, iii) A first measuring device records a response including measurement results of the plurality of entangled photons measured individually at time or frequency from one of the devices, based on the corresponding physical cloning non-function of one of the devices; iv) A second measuring device records a response including measurement results of the plurality of entangled photons measured individually at time or frequency from the other device, based on the corresponding physical cloning non-function of the other device; v) A step that repeats steps i) to iv), vi) The verification system builds up a verification pattern formed from quantum states assigned in frequency or time from the response recorded in the first measuring device and the response recorded in the second measuring device, vii) The verification system compares the verification pattern with the known quantum correlation signature, viiii) The verification system authenticates if a similarity threshold between the verification pattern and the known quantum correlation signature is achieved based on the comparison step, A method of having.
2. The method according to claim 1, wherein the verification system further comprises the step of verifying the quantum entanglement of the plurality of entangled photons.
3. The method according to claim 2, wherein the verification step is performed by periodically redirecting entangled photons so that they move away from the pair of devices for the purpose of verification.
4. Step v) the method according to claim 1, performed within a public channel.
5. The method according to claim 1, wherein the optical chaos is provided by the physically clonability-free nanostructures of each of the pair of devices.
6. The method according to claim 5, wherein the physically cloning-impossible nanostructure has a chaotic light-transmitting medium.
7. The method according to claim 1, wherein the quantum complementary variable is based on the photon arrival time and / or carrier frequency.
8. The method according to claim 1, wherein the quantum correlation signature is defined based on the intensity correlation of entangled photons at frequency and / or arrival time.
9. The method according to claim 1, further comprising the step of the verification system simultaneously transmitting a reference signal to each device of the pair of devices.
10. The method according to claim 1, further comprising the step of the verification system secretly and selectively retaining for security purposes at least some of the responses recorded in the first measuring device and the responses recorded in the second measuring device from step iii) and / or step iv).
11. The method according to claim 1, wherein the response recorded in the first measuring device and the response recorded in the second measuring device are publicly announced in order to achieve step vi).
12. The method according to claim 11, further comprising the steps of: the verification system encoding a confidential message within the response recorded in the first measuring device and within the response recorded in the second measuring device; and the verification system decoding the confidential message from the response recorded in the first measuring device and within the response recorded in the second measuring device.