DID Trust Scoring Using Linked Domain DNS Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity management systems are vulnerable to security risks and lack flexibility in verifying identities, as they rely on centralized authorities, whereas decentralized identifiers (DIDs) offer a secure and independent identity verification method using distributed ledgers, but lack mechanisms for trust assessment.

Innovation Solution

A computing system generates a trust score for DIDs based on metadata from a domain name system (DNS) and associated data, enabling automated acceptance or rejection of transactions or requests based on this score, considering the type of data or service provided.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decentralized identifiers (DIDs) are used for identity verification, then independence from centralized authorities and security are improved, but mechanisms for trust assessment are lacking

Engineering Contradiction:
Improvetrust assessmentVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trust score mechanism that acts as an intermediary between decentralized identifiers and transaction verification. The trust score is calculated based on metadata from DNS and distributed ledger data, providing a mediating trust assessment layer that enables reliable verification without requiring centralized authorities. This resolves the contradiction by adding trust assessment capability while maintaining the decentralized architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automated trust scoring is implemented, then transaction security is improved, but system complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trust scoring system operates autonomously by automatically retrieving metadata from DNS, querying distributed ledgers, and calculating trust scores without human intervention. The system self-manages the entire trust assessment process, from data collection to score generation, which improves transaction security while minimizing the need for complex manual management procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The trust score mechanism serves multiple functions: it assesses entity trustworthiness, validates transaction security, and provides a basis for automated acceptance or rejection decisions. This multi-functionality consolidates several security-related operations into a single unified mechanism, improving transaction security without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If centralized identity management is used, then ease of operation is maintained, but security vulnerabilities and lack of flexibility increase

Engineering Contradiction:
ImprovesecurityVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trust score acts as an intermediary that simplifies operations in decentralized systems by providing automated trust assessment. Instead of requiring users to manually evaluate the trustworthiness of counterparties or understand complex decentralized verification processes, the system automatically calculates and presents trust scores, making decentralized operations as simple as centralized ones while maintaining superior security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4348937B1Bootstrapping trust in decentralized identifiers
Publication Date: 2026.04.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4348937B1 patent drawingFigure 1
  • EP4348937B1 patent drawingFigure 2
  • EP4348937B1 patent drawingFigure 3

AI summary

Bootstrapping trust in decentralized identifiers (DIDs) includes in response to receiving a request from an entity associated with a DID in a decentralized system, obtaining a DID document associated with the DID, and extracting a linked domain that is linked to the DID from the DID document. The DID document contains data associated with the DID that is recorded on the distributed ledger. The request contains the DID and data associated with the DID. Metadata associated with the linked domain is then retrieved from a domain name system (DNS). Based on the metadata associated with the linked domain and the data associated with the DID contained in the request, a trust score, indicating trustworthiness of the DID, is generated.