Secure Content Sharing in MSNs: A Proxy Re-Encryption Approach

A novel authorization delegation scheme for multimedia social networks by using proxy re-encryption

2015-09-07
Weining Feng, Zhiyong Zhang, Jian Wang, Linqian Han
Summary
Problem
Method
Results
Takeaways
Abstract

This paper presents a novel authorization delegation scheme for Multimedia Social Networks (MSNs) using Proxy Re-Encryption (PRE). It enables secure, fine-grained sharing of copyrighted or private multimedia content by transforming ciphertexts between users without revealing private keys or plaintext content.

TL;DR

Sharing private or copyrighted videos in social networks usually involves a trade-off between security and convenience. This paper introduces a Proxy Re-Encryption (PRE) based authorization scheme that allows users to delegate access rights to others without sharing passwords or private keys. By combining PRE with the Usage Control (UCON) model, the authors provide a system that handles rights revocation and fine-grained access while avoiding the "ACL bloat" common in large-scale social platforms.

The Motivation: Why ACLs Fail in Modern MSNs

In massive multimedia social networks (MSNs), the traditional Access Control List (ACL) approach—where a server keeps a list of "who can see what"—breaks down. As millions of users upload content, these lists become astronomically large, slowing down search efficiency and database performance.

Moreover, when Alice wants to share a purchased movie with Bob, she faces a dilemma:

  1. The Privacy Gap: Traditional DRM focuses on the content owner but ignores the privacy of the delegator (Alice) and the delegatee (Bob).
  2. The Security Risk: Sharing account passwords or symmetric keys is a "security nightmare."
  3. Static Control: Most systems grant access once, but cannot easily revoke it based on usage time or frequency.

The Core Solution: Proxy Re-Encryption (PRE)

The authors pivot from "list-based access" to "cryptographic delegation." The architectural backbone is a unidirectional, single-hop PRE scheme.

How it Works (The Intuition)

  1. Enc1 (Symmetric): The actual video content is encrypted with a high-speed Content Encryption Key (CEK).
  2. Enc2 (Asymmetric): The CEK is encrypted using Alice's public key (becoming ).
  3. ReKeyGen: Alice creates a special "Re-Encryption Key" using her private key and Bob's public key.
  4. Re-Encryption: A proxy server uses this key to transform into .
    • Crucially: The proxy cannot see the CEK or the video. It only "shifts" the lock from Alice's key to Bob's.
  5. Decryption: Bob uses his own private key to unlock the CEK and watch the video.

Overall Architecture Fig 1. The structural flow of authorization delegation across the delegator, proxy, and MSNS.

Fine-Grained Usage Control

Unlike traditional "all-or-nothing" access, this scheme integrates the UCON model. This adds "Decision Continuity." The Multimedia Social Network Server (MSNS) monitors attributes (like play counts or time elapsed). If Alice grants Bob the right to watch a video 5 times, a "temporary attribute" tracks this. Once the threshold is met, the privilege is revoked by stopping the proxy's re-encryption capability.

Experimental Validation: The CyVOD MSN Prototype

The authors implemented this in CyVOD MSN, a prototype platform for secure media sharing.

Comparative Advantage

FeatureTraditional ACLABE (Attribute-Based)Proposed PRE Scheme
ScalabilityLow (Heavy ACLs)MediumHigh
EfficiencyMediumLow (Computationally heavy)High
Key PrivacyN/ALow (Proxy needs keys)High (Key-Private)
Collusion ResistanceHighUsually NoYes

CyVOD MSN Platform Fig 2. The CyVOD MSN Prototype Architecture showing the integration of the authorization module.

Critical Analysis & Takeaways

The real genius of this work lies in achieving Key-Private delegation. In many earlier PRE schemes, the proxy was "semi-trusted" but still required sensitive information to function. Here, the delegator is the only one who generates the re-encryption key, and the proxy is strictly a "blind transformer."

Future Outlook

While the scheme is mathematically robust (CCA-secure under DBDH assumptions), the authors acknowledge two main areas for growth:

  1. Cross-Domain Delegation: How do we delegate rights between different social platforms (e.g., from YouTube to Facebook)?
  2. Policy Conflicts: Managing cases where multiple delegated policies might contradict each other remains a challenge for the UCON engine.

Ultimately, this paper serves as a blueprint for moving away from centralized access control toward a more secure, decentralized, and cryptographically-enforced social web.

Find Similar Papers

Try Our Examples

  • Search for recent papers that integrate Proxy Re-Encryption with Blockchain for decentralized Multimedia Social Network authorization.
  • Who first proposed the Usage Control (UCON) model, and how does this paper adapt its "Decision Continuity" feature for cryptographic delegation?
  • Find research exploring the application of multi-hop or bidirectional Proxy Re-Encryption in high-performance cloud media streaming services.
Contents
Secure Content Sharing in MSNs: A Proxy Re-Encryption Approach
1. TL;DR
2. The Motivation: Why ACLs Fail in Modern MSNs
3. The Core Solution: Proxy Re-Encryption (PRE)
3.1. How it Works (The Intuition)
4. Fine-Grained Usage Control
5. Experimental Validation: The CyVOD MSN Prototype
5.1. Comparative Advantage
6. Critical Analysis & Takeaways
6.1. Future Outlook