<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.duda-dnsop-dns-did" target="https://datatracker.ietf.org/doc/html/draft-duda-dnsop-dns-did-00">
   <front>
      <title>A DNS-Based Framework for Privacy-Preserving Identity</title>
      <author initials="A." surname="Duda" fullname="Andrzej Duda">
         <organization>Univ. Grenoble Alpes, CNRS, Grenoble INP, LIG</organization>
      </author>
      <author initials="M." surname="Korczynski" fullname="Maciej Korczynski">
         <organization>Univ. Grenoble Alpes, CNRS, Grenoble INP, LIG</organization>
      </author>
      <author initials="O." surname="hureau" fullname="olivier hureau">
         <organization>Univ. Grenoble Alpes, CNRS, Grenoble INP, LIG</organization>
      </author>
      <author initials="Z." surname="jun" fullname="zhang jun">
         <organization>Huawei Technologies France S.A.S.U.</organization>
      </author>
      <author initials="H." surname="Labiod" fullname="Houda Labiod">
         <organization>Huawei Technologies France S.A.S.U.</organization>
      </author>
      <date month="March" day="2" year="2026" />
      <abstract>
	 <t>   This document presents a framework for privacy-preserving identity
   management based on DNS, supporting large-scale management of users,
   IoT devices, and AI agents.  It introduces Self-Certifying
   Identifiers (SIDs), User/Service Trustees as trusted proxies, and
   leverages DNSSEC-secured TXT records to bind public keys to
   identities.  The framework enables privacy-by-design, where real
   identities are hidden behind trusted entities, through privacy-
   preserving intermediarie.  Credentials bound to SIDs support role-
   based access control, while ephemeral tokens ensure short-lived
   authorization.  Although initially DNS-dependent, the model can
   extend to other directories like DIDs or IPFS.  This approach aligns
   with zero-trust architectures and supports automated, AI-driven
   interactions in future networks.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-duda-dnsop-dns-did-00" />
   
</reference>
