Hi all,
I’m seeking an arXiv endorsement for cs.CR to post the camera-ready of a paper that has been accepted at DSN 2026: A Secure, Manifest-Based Framework for Delegated Privilege Promotion. A Secure, Manifest-Based Framework for Delegated Privilege Promotion
Paper summary. A privileged-promotion infrastructure for enterprise systems that run as unprivileged service accounts but still depend on a small set of root-owned helpers. A minimal privileged mediator (“enabler”) validates a vendor-signed manifest and promotes only authorized files. Validation and promotion are bound to file descriptors rather than pathnames, eliminating TOCTOU races under an attacker-controlled unprivileged namespace. Also supports offline key rotation, KRL-based revocation, and atomic self-update. Deployed in production in a large-scale enterprise database.
To endorse please visit
Endorsement Code: WVWH38