Secure Friend Discovery: Turning Physical Encounters into Cryptographic Bonds
Secure friend discovery based on encounter history in mobile social networks
This paper introduces a secure friend discovery mechanism for Mobile Social Networks (MSNs) that identifies potential friends based on shared encounter history. The system utilizes a peer-to-peer radio-telepathy protocol for key establishment and B+ trees for efficient encrypted event matching, achieving decentralized, privacy-preserving social discovery.
TL;DR
In the era of heavy reliance on centralized social giants, this paper proposes a decentralized alternative for Mobile Social Networks (MSNs). By using "encounter history" as a proxy for shared interests, the authors developed a system where your smartphone automatically negotiates secret keys with people nearby via wireless signal quirks. Later, you can find "missed connections" or like-minded strangers by matching these encrypted histories—all without a central server ever knowing where you were or who you met.
Problem & Motivation: The Privacy Trap of Social Discovery
Current mobile social services (like Loopt or Google Latitude) face a fundamental paradox: to help you find friends, they must track your every move. This creates a massive honey-pot of location data on centralized servers, which are susceptible to data breaches, government surveillance, or corporate misuse.
The authors argue that shared encounters (e.g., being at the same conference, café, or gym) are the strongest indicators of common interests. However, sharing this history is risky. How can we prove we were at the same place at the same time to a stranger without revealing our entire travel log to everyone else?
Methodology: From Wireless Physics to Social Matches
1. The Multi-path Fingerprint
The core "magic" lies in Encounter Key Establishment. Instead of exchanging passwords, two devices use the Radio-Telepathy protocol. They measure the unique multipath fading of the wireless channel between them. Because this signal behavior is unique to their specific spatial relationship and decorrelates rapidly (just a few centimeters away), an eavesdropper (Eve) perceives a completely different signal.
Figure 1: The three-way handshake: Encrypted event broadcasting, peer matching, and verification.
2. Efficient Matching with B+ Trees
Recording every encounter creates a data management problem. To solve this, the authors utilize a dual B+ tree structure:
- Event B+ Tree: Indexes hashed location and time
Hash(L, T). - Key B+ Tree: For every event, it stores the shared symmetric keys.
When you want to find friends, you broadcast a request containing Hash(L, T) and the event details encrypted with the encounter key. Only a person who was actually there and has the same key can decrypt the message.
Experiments & Performance
The system was tested on legacy Android hardware (Galaxy S2/S3), proving its efficiency even on resource-constrained devices.
- Storage: Even with hundreds of recorded events and dozens of keys per event, the memory footprint remains in the kilobyte range, easily manageable for modern devices.
- Energy: The primary drain is message transmission. The study found that while energy scales with distance and message size (25KB vs 100KB), the discovery process typically completes in under 10 seconds.
Figure 2: Memory storage overhead relative to the number of events and encounter keys.
Critical Analysis & Conclusion
This work is a significant step toward Sovereign Social Networking. By moving the "trust" from a server to the physical laws of radio wave propagation (Reciprocity), it creates a system where privacy is a guarantee of the architecture rather than a policy promise.
Limitations: The approach assumes a certain level of "social density." If your encounters are too sparse, the threshold for friend discovery might never be met. Furthermore, radio-telepathy requires both users to be actively probing the channel simultaneously, which might impact battery if not managed by low-power wake-up triggers.
Future Outlook: As privacy regulations like GDPR and CCPA tighten, decentralized discovery mechanisms like this offer a viable path for "Missed Connection" services and professional networking apps that value user anonymity above all else.
