DASC: Solving the Delegation Dilemma in Distributed Social Networks

Scope-Aware Delegations in Distributed Social Networks

2015-01-01
Anna Scholtz, Stefan Wild, Martin Gaedke
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces DASC (Delegation Aware of SCope), a semantic framework designed to enable fine-grained, controlled delegation within WebID-based distributed social networks. It allows users to delegate specific access rights to others using RDF-based constraints and dual-subject X.509 certificates.

TL;DR

In distributed social networks, "acting on behalf of others" is a high-risk necessity. The DASC (Delegation Aware of SCope) approach enhances W3C’s WebID specification by allowing users to delegate specific tasks to others with clear boundaries (scope) like time and domain limits, using a combination of semantic RDF triples and specialized security certificates.

Background: The Identity Gap in Decentralized Webs

The rise of network-centric organizations requires workers to share tasks fluidly across platforms. WebID provides a powerful foundation for this by giving users a platform-independent URI and public-key identity. However, WebID originally lacked a "delegate" function. If Alice wants Bob to manage a resource for her, she shouldn't have to give him her private key or unrestricted access.

The core challenge is achieving Scope-Awareness: ensuring the delegatee (Bob) can only act within the specific "whitelist" Alice defines.

Why Previous Approaches Failed

The paper identifies three major gaps in current technology:

  • OAuth: Excellent for third-party service access but doesn't integrate natively with decentralized authentication routines.
  • SAML/XACML: Powerful but "heavy" and lacks the semantic machine-interpretability needed for the Linked Data world.
  • Header-based Delegation: Previous attempts involved injecting X-On-Behalf-Of headers into every HTTP request, which increases complexity and breaks interoperability across standard servers.

Methodology: The DASC Framework

DASC introduces a "least-change" philosophy to the WebID protocol. It relies on two pillars: Semantic Metadata and Dual-Identity Certificates.

1. Semantic Architecture

Alice defines the delegation in her WebID profile using a specific vocabulary. This includes:

  • Delegatee: The WebID URI of the authorized person.
  • Task: A URI describing the specific work.
  • Constraints: Functional whitelists, such as a "Deadline" or a specific "Service Domain."

DASC Process and Integration

2. The Delegation Certificate

To prove his right to act, Bob uses a modified X.509 certificate.

  • Subject Alternative Name (SAN): Contains Bob's WebID URI.
  • Issuer Alternative Name (IAN): Contains Alice's WebID URI.

When Bob hits a service, the service looks at the SAN and IAN, then cross-references Alice's profile. If the service finds Bob's URI in Alice's "whitelist" and the constraints are met, access is granted.

Implementation & Security

The authors integrated DASC into Sociddea, a WebID identity provider. A critical security feature mentioned is the protection against spoofing: even if an attacker generates a fake dual-subject certificate, the service will reject it because the Delegator's public profile (which the attacker cannot control) will not have a corresponding delegation record for that attacker.

BPMN Process Model of DASC

Critical Insight & Conclusion

DASC successfully bridges the gap between Semantic Web expressiveness and PKI security. By moving the "logic" of the permission into the RDF profile and the "proof" into the certificate, it maintains a clean separation of concerns.

Future Directions: While DASC is robust for 1-to-1 delegations, the authors note that future work must address group delegations and more complex, nested constraint logic. As we move toward a more decentralized "Internet of Subjects," DASC provides a vital building block for secure, collaborative knowledge work.

Find Similar Papers

Try Our Examples

  • Search for recent papers that extend WebID or Solid (Social Linked Data) protocols to support hierarchical or transitive delegation mechanisms.
  • What are the primary security vulnerabilities identified in decentralized identity systems that use X.509 Subject Alternative Names (SAN) for multi-subject authentication?
  • Explore how the DASC vocabulary for delegation constraints could be integrated with ODRL (Open Digital Rights Language) for broader policy enforcement.
Contents
DASC: Solving the Delegation Dilemma in Distributed Social Networks
1. TL;DR
2. Background: The Identity Gap in Decentralized Webs
3. Why Previous Approaches Failed
4. Methodology: The DASC Framework
4.1. 1. Semantic Architecture
4.2. 2. The Delegation Certificate
5. Implementation & Security
6. Critical Insight & Conclusion