Glycos: Bridging the Abstraction Gap in Decentralized Social Networks
Glycos: The Basis for a Peer-to-Peer, Private Online Social Network
This paper introduces Glycos, an abstract protocol and middleware for building Peer-to-Peer (P2P) Private Online Social Networks. It leverages a decentralized graph database built on Kademlia and advanced cryptographic primitives like ring signatures and stealth addresses to provide a developer-friendly ORM (Object-Relational Mapping) layer while ensuring institutional privacy.
TL;DR
Current decentralized social networks are either too hard to build (P2P) or eventually centralize (Federated). Glycos solves this by offering a standardized, privacy-preserving graph database middleware. It uses "Stealth Addresses" and "Ring Signatures" to keep users anonymous even from the hosting peers, while providing an ORM interface that makes developing a P2P social app as easy as writing a standard Web 2.0 site.
The Motivation: Why P2P Social Media Often Fails
Centralized platforms like Facebook provide "social privacy" (you choose your friends) but fail at "institutional privacy" (the platform sees everything). While decentralization is the obvious cure, it faces two massive hurdles:
- Re-centralization: In federated systems like Email, 70% of traffic ends up on Google/Microsoft servers anyway.
- Developer Friction: Unlike Web 2.0, where developers use SQL and Cookies, P2P developers currently have to "reinvent the wheel" for every new feature, dealing with low-level DHTs and complex crypto manually.
Glycos provides the missing "Building Blocks"—the abstractions that decouple the front-end UI from the back-end P2P networking logic.
Methodology: Privacy by Design & Graph Abstractions
The core of Glycos is an Access-Controlled Graph Database. Instead of raw files, it treats social data as triplets: (Subject, Predicate, Object).
1. Anonymity via Stealth Addresses
To prevent the network from linking data points to a specific user, Glycos uses an ephemeral public key derivation (Algorithm 1). This ensures that a vertex ID on the network looks random but is recognizable only by the intended recipient.
2. Ring Signatures for Hidden Access Control
How do you post on a friend's "wall" without the network knowing it was specifically you? Glycos uses Ring Signatures. This allows a user to prove they belong to an "Access Control List" (ACL) without revealing which member of the list they actually are.
Above: The Graph API architecture separating clear text application logic from the cipher text networking domain.
Experiments: Is it Too Slow for Smartphones?
A common critique of P2P systems is the heavy cryptographic overhead. The authors built a proof-of-concept in Rust with Java bindings for Android to test this.
Quantitative Benchmarks
| Operation | Notebook (Intel i5) | Smartphone (ARM A53) |
|---|---|---|
| Verify Vertex Signature | 136.51 μs | 2.84 ms |
| "Seal" (Encrypt/Sign) Vertex | 948.97 μs | 13.46 ms |
| "Open" (Decrypt/Verify) Edge | 129.53 μs | 2.57 ms |

Key Insight: Even on a mid-range smartphone from 2018, the overhead is in the millisecond range. This is negligible compared to network latency, proving that high-grade privacy doesn't have to sacrifice mobile usability.
Critical Analysis & Future Outlook
While Glycos effectively handles confidentiality and authorisation, it identifies a significant "Future Work" area: Deletion and Updates. In a P2P network, preventing "replay attacks" (where an old version of your data is re-broadcast by a malicious peer) requires sophisticated logical clocks or "happened-before" relationships.
Furthermore, the paper notes that P2P privacy definitions are still legally murky under frameworks like GDPR. Who is the "data controller" when the network is the institution?
Takeaway
Glycos shifts the focus of P2P research from "How do we make it secure?" to "How do we make it usable for developers?". By treating a social network as a decentralized graph rather than a collection of files, they provide a roadmap for the next generation of "re-decentralized" applications.
