Beyond the Walled Garden: Building Secure Decentralized Social Networks with Likir
Secure and flexible framework for decentralized social network services
The paper introduces a secure and flexible framework for Decentralized Social Network Services (DSNS) built upon Likir, an identity-aware DHT based on Kademlia. The framework provides a modular architecture that supports user authentication at the routing level, discretionary access control, and distributed reputation management to ensure privacy and security without a central provider.
TL;DR
This paper presents a robust architectural framework for Decentralized Social Network Services (DSNS). By replacing the centralized provider with a secure DHT called Likir, it addresses privacy concerns, prevents data exploitation, and solves the "walled garden" problem. The core innovation lies in embedding user identity management directly into the routing layer, enabling authenticated interactions and fine-grained access control.
Background: The Price of Convenience
Modern Online Social Networks (OSNs) like Facebook or Flickr are functional "silos." Users trade their privacy for services, granting providers total control over their data. This centralization leads to two major issues:
- Data Exploitation: Providers can mine and sell user information.
- The Walled Garden: Data is locked within one platform, preventing interoperability between different social tools.
While P2P systems offer a solution, they are historically plagued by security vulnerabilities and the difficulty of managing access rights without a central server.
The Core Mechanism: Identity-Aware DHT (Likir)
The foundation of this framework is Likir, a secure version of the Kademlia DHT. Unlike traditional DHTs where node IDs are arbitrary, Likir binds every node to a verified user identity (e.g., OpenID) via a signed certificate.
Why this matters:
- Attack Resistance: It effectively neutralizes Sybil and Eclipse attacks because an attacker cannot easily create multiple fake identities.
- Authenticated Routing: Every interaction—whether storing a resource (PUT) or retrieving one (GET)—is authenticated at the protocol level.

Methodology: Privacy and Flexibility
The authors propose a modular client architecture composed of several key components:
1. Discretionary Access Control (DACM)
Instead of relying solely on heavy encryption (which is hard to manage when groups change), the framework delegates access control to index nodes.
- Grant Certificates: When User A friends User B, A issues a "Grant Certificate" signed with their private key.
- Enforcement: When User B requests a private resource from the DHT, the index node checks the certificate. If the signature and permissions (defined by regular expressions) match, the data is released.
2. Reputation & Blacklisting
Dealing with malicious actors in a P2P environment is notoriously difficult. The framework provides a BLACKLIST(userId) primitive. If an application-level Reputation System determines a user is malicious, they are blacklisted at the overlay level, effectively cutting them off from the entire network, not just one app.
3. Tag-Based Search
To bridge the functional gap with centralized sites, a distributed tag-based engine creates a "folksonomy." This allows users to find content via labels across different applications, fueling a decentralized "information mash-up."

Critical Insight: Solving the Walled Garden
The authors argue that by publishing clear APIs for resource keys and types, different social applications can "cohabit" on Likir. A user could use an Instant Messaging widget from one developer and a Photo Sharing widget from another, with both tools interacting seamlessly over the same identity-based substrate. This modularity is a direct strike against the information silos of Big Tech.
Conclusion and Future Outlook
The paper successfully demonstrates that embedding identity into the DHT layer provides the necessary Inductive Bias for secure social networking. While the Certification Service (CS) still represents a centralized touchpoint for initial registration, the subsequent operation is fully distributed.
Takeaway: The future of social media may not lie in bigger servers, but in smarter overlays that treat identity as a first-class citizen of the network protocol itself.
Limitations to Consider:
- Storage Availability: While the DHT handles replication, "churn" (users going offline) remains a challenge for data persistence compared to 24/7 data centers.
- Index Node Trust: Though the paper mentions encryption, index nodes still hold significant power in the access control loop.
