Andrew Potter

Andrew Potter

Authenticity Is Not a Deliverable

US Patent 7,792,791 B2 and the limits of building trust into a system

Andrew Potter's avatar
Andrew Potter
Jul 22, 2026
∙ Paid

On September 7, 2010, the United States Patent and Trademark Office granted patent number 7,792,791 B2. Its title is a sentence no patent office should ever have to process: Systems and Methods for Establishing Authenticity of Electronic Records in an Archives System.

The field-of-invention paragraph is worth reading slowly, because it makes three promises in a single breath:

...techniques that are scalable essentially without limitation for establishing and maintaining comprehensive authenticity of electronic records over an indefinite period of time in a substantially obsolescence-proof manner.

Unlimited scale. Indefinite duration. Obsolescence-proof. This is a patent-attorney register, and the document underneath it is far more careful than its own opening sentence — but the gap between what the claim language promises and what the specification actually knows is the whole subject of this essay.

Because this is not a thought experiment. The patent describes the design intent behind the Electronic Records Archives, the system built to hold the permanent digital records of the United States federal government. It was a procurement. It had a prime contractor. Somebody had to deliver it.

And here is what makes the document remarkable rather than merely ambitious. The patent understands, better than almost any technical document of its era, that authenticity is a socio-technical judgment rather than a cryptographic property. It says so explicitly and repeatedly, in language carefully drawn from InterPARES and the Society of American Archivists — including a sentence reserving the final determination to an individual. And then it spends thirty pages translating the evidentiary basis for that judgment into controls a system can be tested against.

The result is a document containing two competing models of authenticity that run side by side, never quite reconciled. Watching that tension play out is more instructive than watching most projects succeed. So: what the patent gets right, what its central diagram actually draws, where the tension breaks the surface, and what it tells us about the road the field did not take.

Quotations are cited by PDF page, with the patent’s own printed column page in brackets. Patent 7,792,791 is one member of a larger family of patents arising from the ERA development effort, covering preservation, storage, identification, catalog integrity, and access. What follows concerns what this patent itself claims and describes; it is not a complete inventory of the architecture represented across the related filings. The patent is likewise a contractor-team design artifact, not a statement of NARA policy or a description of the system as eventually built.


I. What it gets right

It refuses the checksum answer

The single most important sentence in the patent is this one:

Authenticity applies to records and aggregates of records, not to bit streams; it is a determination about conceptual objects, not logical or physical objects. Preserving accurate bit streams is necessary but not sufficient for preserving authentic records. — PDF p. 23 [col. 21], §2.2.1

For readers coming from engineering rather than archives, that distinction is the entire ballgame, so let me put it plainly. Comparison against a securely retained cryptographic digest can show that a bitstream matches the one hashed earlier. That is what it establishes. It cannot by itself establish the record’s identity, completeness, provenance, meaning, or freedom from manipulation elsewhere in the process. Everything interesting about a record — as opposed to a file — lives in the region a digest cannot reach.

The patent recognizes this and builds it into its taxonomy. Fixity is a subset of integrity; integrity is a subset of authenticity:

Integrity includes fixity and provides the assurance that the digital item has not been modified. Fixity of records ensures the stability of the files in the archives by checking that a file is what it purports to be, and that it has not been corrupted over time... The concept of integrity then may have to extend beyond the bit-level integrity of the data files put into the archives. — PDF pp. 24–25 [col. 26]

This nesting is more disciplined than most contemporary digital-preservation writing manages, and considerably more disciplined than the marketing copy attached to any product currently selling immutability. Note in passing that the patent’s own phrasing — fixity as checking that a file “is what it purports to be” — slides fixity toward identity in a way the rest of its taxonomy does not support. Even careful documents leak at the seams.


Four words people use interchangeably, and shouldn’t

The patent separates them in §1.3, and that separation is the most portable part of the document.

Reliability — whether a record can be trusted to stand for the facts it contains. A property of creation. “Reliability generally is more the concern of the record’s creator than its preserver.”

Authenticity — whether a record is what it purports to be and has maintained its identity and integrity across time and custody. InterPARES: “a record that is what it purports to be and is free from tampering or corruption.”

Authentication — a declaration, by someone, at a particular time. “Authentication thus may be thought of as being external to the record itself and is temporary.”

Trustworthiness — the umbrella term, borrowed from the Minnesota Historical Society’s work on trustworthy information systems.

The corollary the patent draws out of the third definition is the one to keep: “An ‘authenticated record’ only can be as reliable as when the record was first issued by its creator.” A stamp does not improve a record. It only dates an opinion about it.


It knows authenticity is a continuum

There is a growing consensus that authenticity of records is a judgment — a continuum — rather than a binary, yes-or-no choice. — PDF p. 22 [col. 20], §2.1.3

The patent cites InterPARES by name and draws heavily on its framework, including the part that most implementers quietly drop: authenticity requirements support a presumption of authenticity and enable the production of authentic copies. They do not certify that the contents of the record are true. An authentic record of a lie is still an authentic record. The archive’s job is not truth; it is identity and integrity across time.

It knows the archive cannot repair what it did not create

This is where the patent is at its most defensible, and where it quietly indicts a large fraction of what gets pitched as digital-provenance technology today:

Reliability generally is more the concern of the record’s creator than its preserver. In some ways, reliability is a “given” (e.g., must be assumed) before records ever reach the electronic archives. Although unreliable records generally cannot be made reliable, the issue of reliability cannot be ignored. — PDF p. 15 [col. 6], §1.3.1

And the operational consequence, stated without flinching:

As such, reliability ultimately may be outside the scope of the archives system. — PDF p. 23 [col. 22], §2.2.2.1

Ingest does not launder provenance. A repository that receives a defective record and preserves it faithfully has done its job — it has not repaired the record. Compare this to the implicit promise of nearly every blockchain-for-records proposal over the last decade, which mostly amounts to notarizing the moment of arrival and calling the result “history”. The patent, in 2006, was clearer about this than most 2026 pitch decks.

It carries authenticity across the whole lifecycle

Figure 8 walks authenticity through records scheduling, transfer, ingest, preservation planning, description, assessment of adaptation and presentation methods, preservation processing, and dissemination. Authenticity is not deferred until archival storage. Contextual capture begins at scheduling — before the records are anywhere near the repository, while they are still being appraised.

This aligns with the lifecycle metadata principle already in circulation as the patent was being drafted: record metadata applies not only to the record but also to every process that affects it, every system in which it resides, and every organization responsible for it. That principle appeared in ISO/TS 23081-1:2004 and in the first International Standard edition, ISO 23081-1:2006, published in January 2006 — four months before this patent’s priority date — and survives into the 2017 revision. The patent is working in a current, not a prophetic, idiom.

So far, so good. A document that gets all of this right in 2006 deserves to be read seriously.


II. Read Figure 6 literally

On sheet 6 of 10, printed sideways — which is its own small comedy — the patent draws its model of authenticity. Nearly everyone who summarizes this patent describes Figure 6 as a stack of layers. It is worth looking at what is actually on the page.

The specification confirms the reading:

Components Related to Records and Archival Judgment are represented as grouped pillars and include components of: Records that include: content, structure, and context; and Archival judgment of the records that includes: provenance, essential characteristics, and integrity. — PDF p. 25 [col. 26], §3.2

Here is the detail that matters, and it is easy to miss. “Archival Judgment” is not a layer sitting above the evidence. It is a bracket grouping three of the six columns. Provenance, essential characteristics, and integrity are labeled as the objects of archival judgment. Content, structure, and context are labeled simply “Records.” Judgment appears in the diagram as a property of certain columns — not as an act performed by a person on the whole structure.

Which means: there is no archivist in Figure 6.

There is no designated community. No court. No researcher. No future reader with a question. Authenticity is a shape that appears at the top when enough columns are in place underneath. Hold that observation loosely for a moment — the specification says something different, and the gap between them turns out to be the most revealing thing in the document.

The direction of the arrows

Look at the callouts. They point upward into System Credibility, from system accreditation, information assurance, configuration management, and quality management. The visual grammar is unambiguous. Institutional controls flow into system credibility. System credibility supports the pillars. The pillars support authenticity.

It is a load path. It is drawn exactly like a building.

And there is the substitution: authenticity is not a load. It is a verdict.

Structures transmit force upward through their members whether or not anyone is watching. That is what makes them structures. Verdicts require a party with standing to render them, at a particular moment, for a particular purpose, on the basis of evidence, and they remain open to challenge. Figure 6 draws the second thing using the visual language of the first. The substitution is so natural, and so useful for a systems engineer trying to decompose a requirement, that it takes real effort to notice it has happened.

The patent’s own prose half-catches the problem, and then walks straight into it:

If the support structure model is analyzed, to attest to the authenticity of records, the entire archives system has to be credible. This means that risk should not be assessed just at individual processes or for archival users or records administrators. Instead, the entire system may be held accountable for proving the authenticity of a particular record. — PDF pp. 25–26 [col. 27], §3.3

The entire system may be held accountable for proving the authenticity of a particular record.

Read that twice. The system is the party doing the proving.

And yet — this is where the document becomes genuinely interesting rather than merely wrong — the archivist has not disappeared from the specification. Two sections earlier, the patent states the traditional position in as many words:

Although ultimately an archivist must judge authenticity, the archives system’s large volume of records will require computer-implemented methods to check specific features of the record that give an indication of authenticity. — PDF p. 23 [col. 21], §2.2.2

That is unambiguous, and it recurs throughout in substance: archivists assess adaptation and presentation methods, inspect evidence of custody and lifecycle, and may authenticate or certify copies. The patent does not abolish professional judgment. It affirms it — and then, in its implementation sections, keeps converting the evidentiary basis for that judgment into things a system can be tested against. Including this:

Human assessment may be applied to archives system processes that impact authenticity using sampled records as part of a user acceptance testing process that can serve as quality control. — PDF p. 26 [col. 28], §3.5.3.1

Note carefully what human assessment is applied there. Not the records. The archives system processes that impact the records.

So the patent carries two models at once. In the first, authenticity is a judgment a person renders on evidence, and the system’s job is to preserve and expose that evidence well. In the second, authenticity is an outcome that a sufficiently credible system produces, with human review serving as quality control on the production line. Section 2.2.2 states the first. Figure 6 draws the second. Neither is repudiated, and the document never reconciles them.

The pressure that produced the second model is real and worth respecting. At NARA’s volumes, sampling and computer-implemented checking are unavoidable, and the patent is right about that. But sampling a process is a different act from judging a record, and the specification slides between them without ever marking the transition.

If you value deeply researched archival analysis that connects records theory, standards, systems design, and institutional history, please consider becoming a paid subscriber. Your support makes it possible for me to spend the time required to examine documents like this patent closely, test their claims against the historical record, and publish work that goes beyond the usual summaries.

User's avatar

Continue reading this post for free, courtesy of Andrew Potter.

Or purchase a paid subscription.
© 2026 Andrew Potter · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture