M. Nagy, Emiliano De Cristofaro, A. Dmitrienko, N. Asokan, A. Sadeghi
{"title":"Do I know you?: efficient and privacy-preserving common friend-finder protocols and applications","authors":"M. Nagy, Emiliano De Cristofaro, A. Dmitrienko, N. Asokan, A. Sadeghi","doi":"10.1145/2523649.2523668","DOIUrl":null,"url":null,"abstract":"The increasing penetration of Online Social Networks (OSNs) prompts the need for effectively accessing and utilizing social networking information. In numerous applications, users need to make trust and/or access control decisions involving other (possibly stranger) users, and one important factor is often the existence of common social relationships. This motivates the need for secure and privacy-preserving techniques allowing users to assess whether or not they have mutual friends. This paper introduces the Common Friends service, a framework for finding common friends which protects privacy of non-mutual friends and guarantees authenticity of friendships. First, we present a generic construction that reduces to secure computation of set intersection, while ensuring authenticity of announced friends via bearer capabilities. Then, we propose an efficient instantiation, based on Bloom filters, that only incurs a constant number of public-key operations and appreciably low communication overhead. Our software is designed so that developers can easily integrate Common Friends into their applications, e.g., to enforce access control based on users' social proximity in a privacy-preserving manner. Finally, we showcase our techniques in the context of an existing application for sharing (tethered) Internet access, whereby users decide to share access depending on the existence of common friends. A comprehensive experimental evaluation attests to the practicality of proposed techniques.","PeriodicalId":127404,"journal":{"name":"Proceedings of the 29th Annual Computer Security Applications Conference","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"41","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 29th Annual Computer Security Applications Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2523649.2523668","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 41
Abstract
The increasing penetration of Online Social Networks (OSNs) prompts the need for effectively accessing and utilizing social networking information. In numerous applications, users need to make trust and/or access control decisions involving other (possibly stranger) users, and one important factor is often the existence of common social relationships. This motivates the need for secure and privacy-preserving techniques allowing users to assess whether or not they have mutual friends. This paper introduces the Common Friends service, a framework for finding common friends which protects privacy of non-mutual friends and guarantees authenticity of friendships. First, we present a generic construction that reduces to secure computation of set intersection, while ensuring authenticity of announced friends via bearer capabilities. Then, we propose an efficient instantiation, based on Bloom filters, that only incurs a constant number of public-key operations and appreciably low communication overhead. Our software is designed so that developers can easily integrate Common Friends into their applications, e.g., to enforce access control based on users' social proximity in a privacy-preserving manner. Finally, we showcase our techniques in the context of an existing application for sharing (tethered) Internet access, whereby users decide to share access depending on the existence of common friends. A comprehensive experimental evaluation attests to the practicality of proposed techniques.
在线社交网络(Online Social Networks, OSNs)的日益普及促使人们需要有效地访问和利用社交网络信息。在许多应用程序中,用户需要做出涉及其他(可能是陌生人)用户的信任和/或访问控制决策,其中一个重要因素通常是存在共同的社会关系。这激发了对安全和隐私保护技术的需求,允许用户评估他们是否有共同的朋友。本文介绍了共同朋友服务,这是一个寻找共同朋友的框架,它保护了非共同朋友的隐私,保证了友谊的真实性。首先,我们提出了一种通用结构,该结构减少了集合交集的安全计算,同时通过承载能力确保了宣布朋友的真实性。然后,我们提出了一种基于Bloom过滤器的高效实例化,它只会导致固定数量的公钥操作和相当低的通信开销。我们的软件设计使开发人员可以轻松地将Common Friends集成到他们的应用程序中,例如,以保护隐私的方式根据用户的社交距离强制执行访问控制。最后,我们在一个现有的共享(系留)Internet访问的应用程序的上下文中展示了我们的技术,在这个应用程序中,用户决定根据共同朋友的存在来共享访问。综合实验评价证明了所提技术的实用性。