Calibrating Integrity Claims for Centrally Operated Records: An Optional-Scrutiny Design Model
A hash chain, a ledger database, or a transparency log makes a single-writer record checkable; what the operating institution may claim depends on who retained evidence, when, and how independently. This paper develops an optional-scrutiny assurance model for centrally operated institutional records. The model distinguishes three evidence states (self-attested, independently observed, and diversified) and counts verifiers as independent only when their schedules and failure domains are independent. For a rewrite after an exposure window W, observation groups with periods S_g, and an optional external anchor with period T, it gives the schedule coverage 1 - (1 - q_A) * prod_g (1 - q_g) with q = min(1, W/S). A Python reference instantiation with 27 automated tests, laboratory measurements up to 100,000 records, and a discrete-day simulation over a 100-cell parameter grid exercise the model. Three correlated monthly copies cover a seven-day rewrite exactly as often as one (0.233), against 0.549 for three independent schedules; a weekly anchor covers it alone. Rewriting half of a 100,000-record chain takes 0.57 s, and verifying a 10% suffix from a checkpoint is about ten times faster than full verification. The result is an assurance vocabulary, a small decision model, and five design principles that let institutions pair mature ledger components with integrity claims their actual observation arrangements support. The reference implementation, tests, and evaluation outputs are included in this record (osl-reference-code.zip).
Authors
- Emre Akadal (ORCID: https://orcid.org/0000-0001-6817-0127)
Institutions
- Istanbul University (TR)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-25
- DOI
- https://doi.org/10.5281/zenodo.22955120
- Primary Topic
- Data Quality and Management
- Type
- preprint