New certi cate-oriented access control systems are based on delegation of privileges. In these scenarios, resource guards have an ACL which delegates to some authorization or naming authorities the right to manage the access to the controlled resources. These authorities can issue certi cates delegating these permissions to other subordinates authorities, or to speci c users. In this way, the g...