Relational Bootstrapping: Minimal Sufficient External Information for Initial System Establishment
Problem. In the conventional engineering sense, a bootstrap is the initial induction step that makes it possible for a system to construct or configure the rest. Existing mechanisms describe many ways to inject, authenticate, or transfer initial information, but they do not provide a general criterion for a prior question: what information must cross a chosen bootstrap boundary at all, when is it sufficient for autonomous continuation, and which distinctions are unnecessary? Solution. We model bootstrap relative to an explicit lifecycle boundary, an endogenous construction mechanism, and a pre-specified operational goal. The external bootstrap basis consists of grounded distinctions whose validity is supplied across that boundary rather than justified by the mechanism being initialized. Let Hbe admissible histories, G: H→Y the operational goal, and TB : H→Z the terminal representation produced after the endogenous mechanism consumes basis B. The basis is sufficient exactly when G= f ◦TB for some f: histories that remain indistinguishable after bootstrap must never require different operational outcomes. Minimal bases are minimal elements under an informativeness preorder; they need not be unique. Findings. The model yields six results. First, bootstrap is boundary-relative: the same arti- fact may be the output of an upstream lifecycle stage and the bootstrap input of a downstream stage. Second, authenticating objects does not in general authenticate the bindings among them; identity, ownership, membership, location, role, and authority are distinct operational facts. Third, insufficiency has an exact test: if two bootstrap-indistinguishable histories require different outcomes, some required distinction is missing. Fourth, so-called zero-touch bootstrap does not eliminate external grounding; it relocates, aggregates, or delegates it. Fifth, bootstrap minimality and disclosure minimality are different: the internal process may use rich traces, while each observer should receive only a view sufficient for that observer’s authorized goal. Sixth, for descriptive binding problems in which a pre-existing assignment must be recovered exactly, the evidence must carry at least the entropy of that assignment; for n unconstrained device-to-position permutations this is log2(n!) bits. This information bound does not apply unchanged to constitutive choices such as leader election. The framework is stress-tested against consumer cloud devices, datacenter sensors, DHCP, Zeroconf, BRSKI, Secure Zero Touch Provisioning, FIDO Device Onboard, TLS-POK, remote attestation, trusted IoT network onboarding, TPM bootstrapping, and device-pairing misbinding. The contribution is not a new onboarding protocol or a new logic of knowledge, but a criterion for determining the external basis from which the rest of a system can be built correctly.
Authors
- Alexey POLOVINKIN (ORCID: https://orcid.org/0009-0009-4307-6498)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-26
- DOI
- https://doi.org/10.5281/zenodo.22982842
- Primary Topic
- Formal Methods in Verification
- Type
- preprint