Global optimization over feasible credential-derivation arborescences

Establish global optimality of the reported designs over all feasible credential-derivation arborescences rather than only within the deterministic bounded-breadth-first derivation family and finite local-search procedure used in the evaluation.

Background

The evaluation uses one deterministic bounded-breadth-first derivation family together with finite local-search budgets. Consequently, the reported architectures are only the best designs found within that restricted search procedure. The paper explicitly notes that global optimality over the full feasible arborescence space has not been verified.

References

Global optimality over all feasible arborescences remains unverified.

Optimizing Credential Blast Radius Through Trust Boundaries and Delegation Under Post-Quantum Authentication Costs  (2609.04566 - Taipale et al., 3 Sep 2026) in Section 6, “Limitations”