Research notesVRF-003 / Measurement framework

Evaluating device revocation as an operational control

A framework for testing effectiveness, speed, scope and cross-device consistency of revocation.

9 minutesBIBTEXRIS

Technical measurement framework, not evidence of any specific product's effectiveness. Product claims require separate current release evidence.

01

Control objective

After an authorised revocation decision, the affected device must no longer perform protected actions. Other authorised devices should continue without unnecessary global interruption.

02

Start and end point

The clock starts at confirmed administrative action and ends only when API, realtime, refresh, file access and reauthentication consistently reject the old state. A disappearing interface is insufficient.

03

Attack surface

Test the existing access token, rotating refresh token, open WebSocket, cached file URL, push subscription and parallel device history. Each path needs an expected revocation effect.

04

Metrics

Core measures are maximum rather than only mean revocation latency, blocked old requests, error rate on unaffected devices, residual offline data and audit evidence quality.

05

Negative tests

Tests repeat the old session after network isolation, clock skew, process restart and concurrent token rotation. Robust revocation remains effective even when the device did not initially receive the server decision.

06

Acceptance

Each organisation sets its targets. At minimum, no tested path remains authorised after the documented endpoint, and actor, target, time and outcome are traceable.