Reclaiming Privacy: Efficient Data Access and Revocation in P2P Social Networks
Secure Data Management in P2P Social Networks Using Access Tokens
This paper introduces a secure data management model for Peer-to-Peer Online Social Networks (P2P OSNs) using signed access tokens and Alternative IDs (AID). By decoupling data encryption from access rights, the model achieves significantly lower computational and network costs for member revocation compared to traditional re-encryption or periodic expiration methods.
TL;DR
In the landscape of decentralized social networks, managing who sees what—and revoking that access—has traditionally been a resource nightmare. This paper proposes a model using Signed Access Tokens and Alternative IDs (AID) to allow near-instant user revocation and metadata privacy without the massive overhead of re-encrypting entire media libraries.
The "Revocation Dilemma" in P2P Networks
In a centralized world (Facebook, X), revoking a friend's access is a simple database update. In a Peer-to-Peer (P2P) world, data is scattered across untrusted storage nodes. To protect privacy, we encrypt data. But what happens when you "unfriend" someone?
- The Re-Encryption Trap: Earlier models like Persona or PeerSoN required the owner to re-encrypt all their posts with a new key and re-upload them. For high-res video, this is impossible.
- The Expiration Lag: Models like LotusNet used tokens that expire. The problem? The "exiled" friend still has access until the clock runs out.
The Proposed Architecture: Tokens over Tunnels
The authors suggest that we shouldn't just encrypt data; we should verify the requestor at the point of storage.
1. Alternative IDs (AID): Hiding in Plain Sight
Metadata is often a "silent killer" of privacy. Even if a post is encrypted, knowing who is talking to whom reveals social graphs. This model uses GAID (Group AID) and MAID (Member AID). These are pseudonyms known only to group members, preventing external storage nodes or eavesdroppers from mapping activity back to real identities.
2. The Access Token Mechanism
Instead of hard-coding access into the ciphertext, the model uses a signed token:

- tkpub: A public key generated by the user.
- sig: A signature by the group admin's private key.
When a user wants to read a post, the storage node verifies this signature. To revoke access, the admin simply changes the group's signing key and updates the headers of the stored objects—a task significantly lighter than re-encrypting the payload.

Performance Benchmarks
The linear growth of the header is the only significant "tax" on this system. In experiments, the authors found:
- Header Overhead: Approx 1.9KB per recipient group. While non-zero, it is manageable for modern devices.
- Revocation Efficiency: The cost of expelling a member scales beautifully—it depends on the number of members and replicas (), staying nearly flat regardless of whether the actual data files are 10KB texts or 1GB videos.
Figure: The linear relationship between the number of recipients and encryption time confirms the O(n) complexity.
Critical Insight: Why This Matters
The genius of this approach lies in the decoupling of the payload from the permission. By treating the storage node as a "semi-smart" gatekeeper that verifies signatures rather than just a "dumb" bucket of bits, we gain the agility of a centralized system without the privacy violations.
Comparison with SOTA
| Feature | PeerSoN | LotusNet | Proposed Model |
|---|---|---|---|
| Revocation Cost | High (Re-encrypt) | Periodic (Lag) | Low (Key Rotation) |
| Metadata Privacy | Low | Medium | High (via AID) |
| FoF Support | No | Limited | Full Support |
Conclusion & Future Outlook
The proposed model successfully bridges the gap between privacy and performance. While the header size currently uses RSA-2048, moving to Elliptic Curve Cryptography (ECC) could further shrink the 1.9KB overhead, making it even more viable for mobile-first P2P social applications. As the industry moves toward decentralized protocols like ATProto, the logic of "revocable signed tokens" documented here reflects a clear path forward for scalable, private social interaction.
