Research
Joint Trust-Boundary and Credential-Derivation Design Beat Sequential Design in 195 of 230 Comparisons
arXiv 2609.04566 formulates the joint selection of trust domains and credential-derivation structures under policy and latency constraints, measuring credential blast radius as weighted service impact after compromise, and linking service-interaction and credential-derivation graphs through domain assignment. The general problem is NP-hard, but scalarized two-domain direct issuance reduces to a weighted minimum cut. Joint optimization beat choosing boundaries first in 195 of 230 exhaustive synthetic comparisons, especially under chained delegation, and a trace-derived replay using measured post-quantum costs cut expected impact by up to 36%.
↳ Follow the thread