Research story · Digital Scarcity, economics & security
The price of
digital possession.
A digital transfer becomes economically meaningful when the recipient gains effective control and the sender can no longer exercise a competing claim. The research asks what it costs to make that promise credible.
A record says that a digital good has changed hands. The new holder receives the means to use it. But suppose the previous holder has kept a usable key. A successful update to the record has left a harder question unanswered: who can still exercise effective control?
My paper, The Enforcement Price of Digital Possession: Threshold Attestation, Extinguishment, and the Economics of a New Property Object, studies the institution needed to close that gap. It brings property economics, cryptographic accountability and mechanism design together around a practical problem: making a transfer divest the sender, and pricing the residual risk when that divestment is imperfectly observable.
Possession needs an enforcement mechanism
The paper distinguishes the uniqueness of a record from the exclusivity of control. A ledger can identify one recognised holder. The system supporting the good must also determine whether an old credential remains effective, whether a competing use will be accepted and what happens if it reappears.
The model uses a quorum of attestors: a specified threshold must sign before a transfer takes effect. Their role includes attesting that the transfer is admissible, that control is reassigned and that the sender’s prior control has been extinguished. The last task creates the central information problem.
Remote erasure can be difficult to observe. A later use of an old key may reveal a failure, while the absence of such use does not establish that no copy exists. The research therefore works with economic extinguishment: prior control made invalid, unrecognised or commercially unusable within the institution being analysed. It does not require proof that every external copy of information has vanished.
Detection and containment buy different protection
Two weaknesses can make retained control profitable. First, misconduct may be detected and punished only slowly or unreliably. Second, the duplicate may be exploited repeatedly before its use is contained. These processes affect different sides of the attacker’s calculation.
Detection determines how much of a threatened penalty the attacker expects to bear, allowing for delay and the quality of the evidence. Containment determines how much can be extracted from the retained control before further exploitation stops. Finding a fault and limiting its consequences are related operational tasks, but their effectiveness should be measured separately.
The paper derives a sharp benchmark under explicit assumptions: homogeneous, risk-neutral attestors, accountable signatures, positive detection and no additional legal penalties or future-business rents. The combined stake exposed by the threshold of signing attestors must be at least the good’s value divided by the product of detection quality and containment. Weaker protection on either dimension raises the collateral requirement.
Put a price on the promise
An illustrative calculation makes the result tangible. For a good worth 10,000 dollars, detection quality of 0.4 and containment of 0.6 imply approximately 41,700 dollars of required stake at risk in that benchmark. This is capital exposed to forfeiture, rather than a transaction fee or an observed commercial price.
Improving containment to one reduces the requirement to 25,000 dollars. Improving detection as well reduces it further. The example shows why security design can be an economic substitute for simply locking up more capital. Faster investigation, stronger evidence and effective limits on repeated exploitation change the cost of supporting possession.
The same relationship places a ceiling on the value a fixed stake can secure under the model. A system cannot assume that a mechanism adequate for a modest asset remains adequate as the exposure grows. The relevant comparison is between the gain available from misconduct and the consequences the responsible parties would actually face.
Accountability has to reach the actor
A large bond helps only if a supported claim can connect misconduct to someone whose bond is at risk. The model therefore treats accountable signatures and positive detectability as prerequisites for its stake-based deterrence result. The amount of collateral alone cannot repair an enforcement process that has no attributable sanction.
In the more general formulation, attestors differ. Stake, expected legal or reputational consequences and the loss of future business all contribute to the cost of recruiting a corrupt coalition. The relevant security margin is the least costly coalition capable of authorising the transfer, rather than the average resources of the whole group.
This connects technical design to institutional selection. Who can attest, what can be evidenced, which consequences are enforceable and how operators remain accountable become part of the same security calculation.
Monitoring is work, and evidence has limits
Checking a transfer costs effort. When the benefits of checking are shared across a quorum, each participant may prefer another to do the work. The paper analyses that team-incentive problem and a mechanism that assigns inspection responsibilities with consequences for attributable failures.
Its analysis separates accidental failures, deliberate attacks involving captured inspectors and collusion reaching the signing threshold. Extra inspectors attenuate capture risk; deterring the model’s deliberate sub-threshold attack by a complicit holder requires a separately enforceable transferor bond. Better monitoring can reduce risk and improve effort incentives while imperfect evidence leaves a residual. Increasing the required number of signatures also affects availability, so the design must balance deterrence with the ability to complete legitimate transfers.
A further limit concerns attribution after a key resurfaces. The same public evidence may result from a sender deliberately retaining control or from a copy stolen before an otherwise honest erasure. A penalty aimed only at signers cannot reliably distinguish every such history. The liability arrangement must address the relevant custody and environment risks.
Design the institution around the exposure
The research develops a conditional case for combining instruments. Stake places capital at risk. Reputation exposes future business. Insurance allocates losses and can support monitoring. Legal and contractual responsibility address risks that the available technical evidence cannot resolve on its own. Their appropriate combination depends on value, evidence quality, containment and cost.
These are analytical results about a specified enforcement setting. Their practical value is a structured assessment of a proposed digital-possession system: identify the control being transferred, the evidence available, the gain from retaining it, the response to misuse and the party bearing each residual risk.
Digital scarcity then becomes a question that can be investigated economically. What makes rival control non-viable, and what does providing that protection require? Answering it connects the architecture of a transfer to the institution standing behind it, giving a stronger foundation for meaningful exchange than a change of name in a record alone.