Physical Trust at the
Digital-Physical Boundary.
An information-theoretic framework for verification in autonomous action systems.
A persistent, citable
research record.
The full report is preserved on Zenodo with a permanent DOI and versioned metadata. Repository publication supports durable citation and independent access; it does not imply peer review, certification or endorsement.
- Repository
- Zenodo
- Record
- 21471429
- Version
- 1.0
- Publication date
- 21 July 2026
- Resource type
- Research report
- Access
- Open
- Review status
- Non-peer-reviewed
- Length
- 43 pages
Braun, N. (2026). Physical Trust at the Digital-Physical Boundary: An Information-Theoretic Framework for Verification in Autonomous Action Systems. Independent research report, version 1.0. https://doi.org/10.5281/zenodo.21471429
A valid digital representation does not, by itself, establish physical correspondence.
Digital security can prove properties of records, credentials, communications and computing environments. The unresolved question is whether the represented person, object, authority or context has the physical state required before a consequential action occurs.
The report names this residual problem the physical trust gap. Its concern is not whether a digital claim is internally consistent, but whether an institution has decision-relevant evidence about the physical referent behind that claim.
More computation cannot recover information that the observation never contained.
The report formalizes an input-equivalence result: when two relevant physical states produce the same accessible information, no deterministic or randomized decision rule operating only on that information can reliably distinguish them.
This result is computationally agnostic. Increasing model capability, reasoning depth or automation does not remove observational non-identifiability. A useful observation must change the information available to the decision process.
⇒ no rule over X can distinguish θ₀ from θ₁
SAME ACCESSIBLE INPUT
SAME ACCESSIBLE INPUT
Verification is not one event. It is a controlled chain of distinct functions.
The mechanism-neutral architecture separates six roles so that an observation is not mistaken for a decision, and a verification result is not interpreted as unrestricted authority.
This separation enables independent testing, clearer governance and more precise failure analysis. It also allows physical assurance to compose with identity, cryptography, remote attestation, policy and existing enforcement systems without pretending to replace them.
The objective is not simply more data.
It is an observation that changes what the institution can know.
Every claim must be bounded by the conditions under which it is meaningful.
Physical trust is evaluated within a declared assurance envelope: the exact claim, operating domain, adversary model, freshness requirement, lifecycle state and consequence of error.
The report therefore rejects absolute language. A verification result has value only when its semantics, evidence quality and residual risk are commensurate with the action it is asked to govern.
One assurance logic. Different consequential boundaries.
The report applies the framework to four illustrative profiles. These are boundary analyses rather than deployment claims: each asks what physical state matters, what evidence is decision-relevant and where enforcement should occur.
Separate model output from the physical authority required before a sensitive action is enforced.
Require bounded evidence about the expected authority for exceptional transactions or control changes.
Connect digital custody and provenance to the expected physical component at critical lifecycle events.
Bind privileged maintenance access to the expected person, asset and operational context.
A standard should define assurance semantics — not disclose the protected mechanism.
The proposed Physical Trust Assurance Standard is a prospective research and governance pathway, not a published consensus standard or certification program. It would define claims, result semantics, assurance levels, evaluation evidence and conformity processes.
The report argues that mechanisms can remain proprietary while public assurance claims become testable. Standardization should therefore focus on the interface between evidence, appraisal, authorization and enforcement.
The framework is useful only if its boundaries remain visible.
The paper does not disclose a sensing or fabrication mechanism, validate a product, certify a deployment or claim that physical evidence is inherently unforgeable. It identifies an assurance problem and the conditions under which evidence could reduce it.
Human coercion, collusion, privacy risk, bad policy and failures outside the controlled interface remain. Physical trust can improve the evidence available to institutions; it cannot determine whether their objectives are legitimate or correct.
Secure representations are necessary.
Physical correspondence is a separate assurance problem.
The report develops a formal vocabulary, mechanism-neutral architecture and prospective standardization path for that problem — while keeping claims bounded by evidence, operating domain and residual risk.
This visual edition is a condensed interpretation of an independent, non-peer-reviewed research report. It is mechanism-neutral, contains no proprietary implementation details and does not constitute a product validation, certification claim, deployment statement or published consensus standard. The Zenodo record is the authoritative citable version.