DidTrust: Privacy-Preserving Trust Management for Decentralized Identity

Jie Yin, Yang Xiao, Jie Feng, Mengmeng Yang, Qingqi Pei, Xun Yi · IEEE Transactions on Dependable and Secure Computing · 2025

Decentralized identity (DID) is rapidly emerging as a promising alternative to centralized identity infrastructure, offering numerous real-world applications. However, existing DID systems are confronted with trust concerns, as any distributed node can act as a credential issuer and be considered trusted, which is impractical. Effective trust management (TM) protocols are critical for system trustworthiness but face two primary challenges: preserving user feedback privacy to meet regulation requirements and building resilience against trust attacks to prevent manipulation. While privacy-preserving TM protocols effectively safeguard sensitive data, they often obscure feedback, hindering anomaly detection and complicating efforts to counter trust attacks. To address these issues, we propose DidTrust, a novel decentralized identity trust management protocol that bridges data privacy and resilience to trust attacks. DidTrust features a feedback data privacy preservation protocol that conceals feedback data while maintaining authorizability and verifiability. It also implements countermeasures against cooperative and individual trust attacks, improving detection accuracy without compromising privacy. To improve efficiency, we introduce a feedback compression module for large-scale sparse matrices. Rigorous analysis proves DidTrust to be universally composable (UC) secure under a malicious model, and experiments demonstrate its improved computational and storage efficiency while achieving higher trust attack detection rates compared to BC-Trust.

Read the paper · More papers on PaperTik