Reclaiming Privacy: Efficient Data Access and Revocation in P2P Social Networks

Secure Data Management in P2P Social Networks Using Access Tokens

2018-06-01
Mohammed Hamed Al-Amin, Mohamed Shaheen Elgamel, Ayman Abdel-Hamid
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces a secure data management model for Peer-to-Peer Online Social Networks (P2P OSNs) using signed access tokens and Alternative IDs (AID). By decoupling data encryption from access rights, the model achieves significantly lower computational and network costs for member revocation compared to traditional re-encryption or periodic expiration methods.

TL;DR

In the landscape of decentralized social networks, managing who sees what—and revoking that access—has traditionally been a resource nightmare. This paper proposes a model using Signed Access Tokens and Alternative IDs (AID) to allow near-instant user revocation and metadata privacy without the massive overhead of re-encrypting entire media libraries.

The "Revocation Dilemma" in P2P Networks

In a centralized world (Facebook, X), revoking a friend's access is a simple database update. In a Peer-to-Peer (P2P) world, data is scattered across untrusted storage nodes. To protect privacy, we encrypt data. But what happens when you "unfriend" someone?

  • The Re-Encryption Trap: Earlier models like Persona or PeerSoN required the owner to re-encrypt all their posts with a new key and re-upload them. For high-res video, this is impossible.
  • The Expiration Lag: Models like LotusNet used tokens that expire. The problem? The "exiled" friend still has access until the clock runs out.

The Proposed Architecture: Tokens over Tunnels

The authors suggest that we shouldn't just encrypt data; we should verify the requestor at the point of storage.

1. Alternative IDs (AID): Hiding in Plain Sight

Metadata is often a "silent killer" of privacy. Even if a post is encrypted, knowing who is talking to whom reveals social graphs. This model uses GAID (Group AID) and MAID (Member AID). These are pseudonyms known only to group members, preventing external storage nodes or eavesdroppers from mapping activity back to real identities.

2. The Access Token Mechanism

Instead of hard-coding access into the ciphertext, the model uses a signed token: Access Token Structure

  • tkpub: A public key generated by the user.
  • sig: A signature by the group admin's private key.

When a user wants to read a post, the storage node verifies this signature. To revoke access, the admin simply changes the group's signing key and updates the headers of the stored objects—a task significantly lighter than re-encrypting the payload.

System Relations and Interactions

Performance Benchmarks

The linear growth of the header is the only significant "tax" on this system. In experiments, the authors found:

  • Header Overhead: Approx 1.9KB per recipient group. While non-zero, it is manageable for modern devices.
  • Revocation Efficiency: The cost of expelling a member scales beautifully—it depends on the number of members and replicas (), staying nearly flat regardless of whether the actual data files are 10KB texts or 1GB videos.

Encryption Time vs Recipients Figure: The linear relationship between the number of recipients and encryption time confirms the O(n) complexity.

Critical Insight: Why This Matters

The genius of this approach lies in the decoupling of the payload from the permission. By treating the storage node as a "semi-smart" gatekeeper that verifies signatures rather than just a "dumb" bucket of bits, we gain the agility of a centralized system without the privacy violations.

Comparison with SOTA

FeaturePeerSoNLotusNetProposed Model
Revocation CostHigh (Re-encrypt)Periodic (Lag)Low (Key Rotation)
Metadata PrivacyLowMediumHigh (via AID)
FoF SupportNoLimitedFull Support

Conclusion & Future Outlook

The proposed model successfully bridges the gap between privacy and performance. While the header size currently uses RSA-2048, moving to Elliptic Curve Cryptography (ECC) could further shrink the 1.9KB overhead, making it even more viable for mobile-first P2P social applications. As the industry moves toward decentralized protocols like ATProto, the logic of "revocable signed tokens" documented here reflects a clear path forward for scalable, private social interaction.

Find Similar Papers

Try Our Examples

  • Search for recent papers on P2P Online Social Networks that utilize Zero-Knowledge Proofs (ZKP) for access control without revealing metadata.
  • Which paper first proposed the "LotusNet" architecture, and how does its "Grant" mechanism differ fundamentally from the signed access tokens used in this study?
  • Explore the application of Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) in modern decentralised social media platforms like Mastodon or Bluesky compared to the Alternative ID system.
Contents
Reclaiming Privacy: Efficient Data Access and Revocation in P2P Social Networks
1. TL;DR
2. The "Revocation Dilemma" in P2P Networks
3. The Proposed Architecture: Tokens over Tunnels
3.1. 1. Alternative IDs (AID): Hiding in Plain Sight
3.2. 2. The Access Token Mechanism
4. Performance Benchmarks
5. Critical Insight: Why This Matters
5.1. Comparison with SOTA
6. Conclusion & Future Outlook