Prevalence of credential-delegation regimes in deployments

Determine the deployment prevalence of single-authority, nested-intermediate, and federated trust-domain and credential-delegation layouts represented by the paper’s structural regimes.

Background

The paper relates its structural cases to SPIRE deployments and OAuth 2.0 Token Exchange, which demonstrate that the modeled trust and delegation arrangements are implementable. However, the service-call traces used in the evaluation omit credential semantics, so they cannot establish how common the different regimes are in production. The prevalence of these architectures therefore remains an empirical question.

References

Deployment prevalence remains unknown.

Optimizing Credential Blast Radius Through Trust Boundaries and Delegation Under Post-Quantum Authentication Costs  (2609.04566 - Taipale et al., 3 Sep 2026) in Section 5, paragraph following Table 1