Balancing Anonymity and Accountability: A New Reputation Scheme for Pervasive Social Networks

Reputation Schemes for Pervasive Social Networks with Anonymity (Short Paper)

2017-08-01
Lydia Garms, Keith M. Martin, Siaw-Lynn Ng
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces a privacy-preserving reputation-based messaging scheme for Pervasive Social Networks (PSNs). It leverages BBS* group signatures and a modified Direct Anonymous Attestation (CDL*) to enable anonymous communication while allowing a Trusted Server to manage user reputations and revoke malicious actors without compromising unlinkability between peers.

TL;DR

Communication among strangers in Pervasive Social Networks (PSNs) like Firechat or Kik requires absolute privacy, yet anonymity often invites abuse. This paper proposes a hybrid scheme that uses BBS Group Signatures* and a modified Direct Anonymous Attestation (CDL)* to create a system where users remain anonymous to each other, but the system can still track reputation and revoke bad actors.

Problem & Motivation: The Anonymity Paradox

In a "Pervasive Social Network of Strangers," users connect directly via smartphones or wearables without prior relationships.

  • The Privacy Need: Users demand untraceability (hiding long-term identity) and unlinkability (preventing different actions from being traced to the same user).
  • The Trust Gap: Without identities or profiles, how do you filter out spam, fraud, or malicious content?

Existing solutions usually fall into two traps:

  1. Distributed Schemes: Rely on local experience, which requires long-term linkable identifiers, destroying privacy.
  2. Centralized Schemes: Require a server to act as a proxy for every message, creating a bottleneck and a single point of failure for privacy.

The authors argue that a Hybrid Approach is the only way forward: using a Trusted Server (TS) only for periodic reputation updates and feedback collation, while allowing direct peer-to-peer communication.

Methodology: Cryptographic Foundations

The core of the proposal lies in two modified signature schemes that "bind" reputation to the cryptographic process.

1. BBS* for Public Messaging

Based on the Boneh-Boyen-Shacham (BBS) short group signature, BBS* allows a user to prove they are a valid member of the network without revealing who they are. Crucially, the authors modified it so that a Reputation Value (r) is baked into the signature.

  • The "Opening" Function: The TS holds a secret key that can "open" a signature to link it to a specific user—but only the TS can do this. This allows feedback to be attributed to the correct (anonymous) author.

2. CDL* for Anonymous Feedback

For feedback, the authors modified a Direct Anonymous Attestation (DAA) scheme. Unlike group signatures, DAA has no "opening" function, meaning feedback is anonymous even to the TS.

  • Linkability Control: It uses a "basename" (the subject message). If a user tries to give feedback on the same message twice, the CDLLink* function will output true, allowing the TS to reject the unfair duplicate.

CDL* and BBS* Algorithm Details

Performance and Feasibility

A common criticism of Pairing-Based Cryptography (PBC) is computational overhead. The authors address this by providing a detailed cost analysis:

  • Computational Efficiency: The most expensive operation is the "Pairing." On a mid-range mobile device (Samsung I9100), a signature verification takes roughly 54ms. While not instantaneous, it is well within the threshold for social messaging apps.
  • Communication Overhead: A message with a BBS* signature is roughly 218 bytes. Given modern 4G/5G speeds, the download time is negligible (approx. 0.12ms).
  • Revocation: Instead of heavy "Revocation Lists," the system simply stops providing updated secret keys to malicious users during their periodic "Reputation Retrieval" phase. No key, no access.

Table of Computational Costs

Critical Analysis & Conclusion

Takeaway

The paper successfully bridges the gap between the need for a central authority (to manage reputation) and the desire for decentralized, anonymous communication. By using different cryptographic primitives for messaging (where the server needs to link authors for reputation) and feedback (where the server should not know who said what), they achieve a sophisticated balance of privacy.

Limitations

  • Trust in TS: While the TS cannot "deanonymize" feedback, it still holds the "Opening Key" for public messages. A compromised TS could potentially unmask the authors of all public broadcasts.
  • Latency in Punishment: Bad behavior isn't punished until the next reputation retrieval cycle. This "time-window" could be exploited by an attacker to send many malicious messages before being revoked.

Future Work

The next logical step for this research would be moving toward Threshold Cryptography, where the "Opening Key" is split among multiple servers to ensure that no single entity can deanonymize the entire network.

Find Similar Papers

Try Our Examples

  • Examine recent advances in Privacy-Preserving Reputation Systems (PPRS) for decentralized networks published after 2017 that improve upon BBS* or CDL* efficiency.
  • How does the "basename" concept in Direct Anonymous Attestation (DAA) fundamentally differ from linkable ring signatures in preventing Sybil attacks within anonymous voting or feedback systems?
  • Investigate the current state of Pairing-Based Cryptography (PBC) performance on modern ARMv9 architectures compared to the Samsung I9100 benchmarks provided in this paper.
Contents
Balancing Anonymity and Accountability: A New Reputation Scheme for Pervasive Social Networks
1. TL;DR
2. Problem & Motivation: The Anonymity Paradox
3. Methodology: Cryptographic Foundations
3.1. 1. BBS* for Public Messaging
3.2. 2. CDL* for Anonymous Feedback
4. Performance and Feasibility
5. Critical Analysis & Conclusion
5.1. Takeaway
5.2. Limitations
5.3. Future Work