PeerSoN: Reclaiming Privacy in Social Networks via Broadcast Encryption
P2P Social Networks with Broadcast Encryption Protected Privacy
The paper proposes a decentralized P2P social network architecture that leverages Dynamic Identity-Based Broadcast Encryption (DIBBE) to provide efficient, fine-grained access control. By replacing centralized providers with a combination of broadcast encryption and symmetric cryptography, the system ensures data confidentiality and recipient privacy without relying on trusted third parties.
TL;DR
The paper introduces a provider-independent P2P social network architecture that uses Broadcast Encryption (BE) to replace central servers. By treating the profile owner as their own "Key Generator," it achieves efficient one-to-many data sharing with hidden access lists, ensuring that neither the storage providers nor unauthorized users can see who is interacting with whom.
Background: The Price of "Free" Social Media
In the current OSN landscape (Facebook, X, etc.), privacy is an illusion maintained at the provider's discretion. The fundamental problem is centralization: the provider holds the keys to all user data. While P2P networks (like Diaspora or Safebook) attempted to fix this, they often sacrificed efficiency (using slow Attribute-Based Encryption) or forced users to trust "helper" nodes.
The authors argue that a truly private social network must satisfy three criteria:
- Decentralization: No central authority.
- Cryptographic Enforcement: Access control must be mathematical, not policy-based.
- Metadata Privacy: An attacker shouldn't even know if you have access to a piece of data.
The Core Innovation: Broadcast Encryption (BE)
Most encryption is 1-to-1. If you have 100 friends, you’d traditionally encrypt a photo 100 times. Broadcast Encryption allows a sender to encrypt a message once for a dynamic set of receivers.
The authors specifically utilize Dynamic Identity-Based Broadcast Encryption (DIBBE). In this setup:
- Efficiency: The Ciphertext and Private Keys remain a constant size, regardless of how many friends you have.
- Anonymity: The "Header" of the encrypted file does not reveal the list of recipients. A user must attempt to decrypt it to see if they are a member of the group—a "trial-and-error" approach that protects metadata.
The Architecture of a Privacy-Preserving Profile
The system doesn't just encrypt files; it hides the structure of the user's social life.

Key components include:
- Links Folders: Every contact has a unique, randomly identified folder. This prevents any single user from seeing your entire contact list.
- Dummy Objects: To thwart traffic analysis (where an attacker counts files to guess your activity), the system inserts "fake" encrypted folders and objects.
- Untrusted Replicas: Data is stored on peers. Since data is encrypted via BE, the storage nodes can't read it. They act as "append-only" logs for wall posts and comments.
Operations: How it Works in Practice
- Establishing Connection: Users exchange public keys and set up a symmetric key to decrypt their unique "Links Folder."
- Publishing (Owner): The owner generates a symmetric key , encrypts the content with , and then uses BE to encrypt for a specific set of friends.
- Commenting (Friends): If the owner is offline, friends use a Group Private Key to sign their comments. This allows the untrusted replica to verify the commenter is "a friend" without knowing specifically which friend they are.
Critical Insight: Why This Matters
The shift from CP-ABE (Attribute-Based) to DIBBE (Broadcast) is the paper's masterstroke. While ABE is powerful, its ciphertext grows with the complexity of the access policy—making it too heavy for mobile-first P2P environments. DIBBE provides the "sweet spot" of constant-size overhead while maintaining "hidden access structures."
Limitations & Future Work
- Key Aging: The paper acknowledges that master keys and symmetric keys age over time. Frequent re-encryption of large data volumes remains a computational hurdle.
- Replica Integrity: While the "addition-only" policy helps, a malicious replica could still refuse to serve data (Denial of Service).
- Availability: As with all P2P systems, if the owner and all replicas go offline, the data vanishes.
Conclusion
This architecture presents a robust blueprint for a social network where the user is the sovereign. By combining the efficiency of symmetric crypto for data with the flexibility of Broadcast Encryption for access rights, it proves that "privacy-by-design" doesn't have to mean "slow-by-design."
