Qualification: Trust-Based Blockchain Authorization for IoT

Record: kaal:position:2026-08-26-020 · 2026-08-26

Putra and his coauthors provide a concrete qualification to the proposed separation between reputation and authorization. Their peer-reviewed design does not permit a reputation score to execute access by itself because a resource owner first signs an attribute-based access policy. A policy contract then evaluates the requested action, mandatory attributes, payment balance, and minimum trust and reputation scores, and only that contract issues the access token. The distinction is material, but the result is not merely advisory reputation. The minimum trust and reputation scores form part of the access policy. Algorithm 1 requires both thresholds to be satisfied before authorization can succeed. A higher score may therefore change the token outcome and enlarge effective access within the authority already committed by the resource owner. The enforcement boundary remains separate. It consists of the signed policy, the policy contract, token issuance, and token validation by the data store. The article reports a proof-of-concept implementation on a public Rinkeby test network connected to a lab scale Internet of Things testbed, and its evaluation addresses score evolution, authorization latency, access latency, and gas consumption. It does not study sovereign local agent runtimes. It does not provide a formal security proof, field evidence across adversarial deployments, or a legal account of delegated authority. The authors choose to couple reputation to permission, but their evidence does not establish that this coupling is generally safe. The categorical rule should therefore distinguish a reputation signal from the authority that makes the signal operative. Reputation must not authenticate itself, define its own threshold, issue its own token, or bypass revocation. If a system uses reputation inside authorization, the resource owner must bind its permitted role in advance and an independent enforcement mechanism must remain authoritative. For sovereign runtimes, an advisory-only rule may still be the safer institutional design. The external evidence shows, however, that reputation can influence a permission decision without replacing the enforcement boundary. The relevant prohibition is self-authorizing reputation, not every policy-bound use of a reputation input.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

Trust-Based Blockchain Authorization for IoT

Scholarly basis

kaal:claim:7314479-020
Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479
Source PDF sha256: debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6

Evidence and mapping

Evidence: peer-reviewed journal systems paper with complete public author manuscript and lab scale proof-of-concept evaluation
Review tier: independent substantive scholarly-growth qualification
Mapping confidence: 0.98
Mapping ambiguous: false

Topics

institutional-designgovernance-designreputationauthorizationaccess-controlenforcement-boundarytrust-managementblockchaininternet-of-things

Provenance

Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-020-reviewed-v1 on 2026-08-26. Review record.

Verify

Canonical markdown sha256: a04536c9c9f74fa28280c7794a36e08884da07c9580b8bf4fef4b6a4ddb722c5
curl -s https://wulfkaal.github.io/positions/2026-08-26-020.md | sha256sum