SoNet: Balancing Absolute Privacy with High Availability in Federated Social Networks

SoNet -- Privacy and Replication in Federated Online Social Networks

2013-07-01
Lorenz Schwittmann, Christopher Boelmann, Matthäus Wander, Torben Weis
Summary
Problem
Method
Results
Takeaways
Abstract

SoNet is a federated online social network (OSN) architecture designed to safeguard user privacy and data availability. It employs end-to-end encryption for content and a novel Single Direction Alias (SDA) approach to obfuscate the social graph from providers while maintaining a replication scheme to handle server downtimes.

TL;DR

SoNet is a federated social network architecture that proves you don't have to choose between privacy and usability. By combining end-to-end encryption, a unique Single Direction Alias (SDA) system to hide who you know, and a privacy-preserving replication scheme, SoNet achieves a high level of availability and security—even on low-power mobile devices.

Problem & Motivation: The Centralization Trap

Traditional Online Social Networks (OSNs) like Facebook or X act as "data silos." Even when they promise privacy via Terms of Service, users have no technical way to verify that their personal data or social graphs aren't being exploited.

While federated models (like Mastodon or Diaspora) exist, they face two massive hurdles:

  1. The Social Graph Leak: Even if content is encrypted, the provider still knows who you talk to, which is often as sensitive as what you say.
  2. The Availability Gap: Studies show up to 50% of independent servers in federated networks experience significant downtime, leading to lost posts and "broken" feeds.

The authors' insight was to decouple the identity from the communication channel using aliases, ensuring that a server only knows "User A is talking to someone," but never exactly who.

Methodology: The Core Mechanics

SoNet rests on three pillars: Federation, Cryptography, and Obfuscation.

1. Architectural Layers

The system separates the Federation Protocol (server-to-server) from the OSN Protocol (client-to-client). Servers act as blind storage providers for opaque binary blobs.

System Architecture Figure 1: The federated structure where clients connect exclusively to their chosen home server.

2. Social Graph Obfuscation (The SDA Approach)

This is SoNet's "Secret Sauce." Instead of using a global identifier (like @alice:server.com) for all interactions, Alice uses a different Single Direction Alias (SDA) for every single friend.

  • Server X knows Alice.
  • Server Y knows "Alias_123."
  • Neither server knows that Alice and Alias_123 are the same person or that they are friends.

Alias Information Flow Figure 2: The limited knowledge held by servers during communication.

3. Friendship via Zero-Knowledge

To establish trust without a middleman, SoNet uses a modified Socialist Millionaires' Protocol (SMP). This allows two users to verify they know a shared secret (like an answer to a personal question) and exchange public keys without the server ever seeing the identity or the secret.

Experiments & Results: Mobile-First Performance

A common critique of heavy encryption is that it kills mobile battery and speed. SoNet's benchmarks on a legacy HTC Desire S suggest otherwise:

OperationPerformance (ms)
Generate RSA-2048 Pair3155.19 ms
Create Post (Sign + Encrypt)28.47 ms
Read Post (Decryption)10.44 ms

The "Worst Case" reading scenario—where a client has to trial-decrypt with 100 potential keys because of identity obfuscation—still clocks in at nearly instantaneous speeds for the human eye.


Critical Analysis & Conclusion

Takeaway

SoNet successfully demonstrates that Social Graph Obfuscation and Data Replication are not mutually exclusive. By allowing friends to act as encrypted caches for each other, the network remains robust even when individual nodes go offline.

Limitations

  • Metadata Evolution: While the social graph is hidden, sophisticated traffic analysis (timing and packet size) can still hint at relationships, which the authors acknowledge as a trade-off for mobile efficiency.
  • Password Reliance: Recovery of keys depends on a user-defined password. If the password is weak, the server provider could theoretically brute-force the key container.

Future Outlook

SoNet provides a blueprint for "Privacy by Design" in the Fediverse. As privacy regulations tighten globally, the SDA (Single Direction Alias) model offers a compelling way for developers to build social platforms where the "provider" truly has zero knowledge of the user's social life.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize Single Direction Aliases (SDA) or similar pseudonymity techniques in federated systems to prevent social graph mining.
  • Which original research proposed the Socialist Millionaires' Protocol (SMP) for zero-knowledge authentication, and how have subsequent federated OSNs modified it?
  • Find studies evaluating the energy consumption and battery impact of end-to-end encryption and metadata obfuscation on modern mobile social media clients.
Contents
SoNet: Balancing Absolute Privacy with High Availability in Federated Social Networks
1. TL;DR
2. Problem & Motivation: The Centralization Trap
3. Methodology: The Core Mechanics
3.1. 1. Architectural Layers
3.2. 2. Social Graph Obfuscation (The SDA Approach)
3.3. 3. Friendship via Zero-Knowledge
4. Experiments & Results: Mobile-First Performance
5. Critical Analysis & Conclusion
5.1. Takeaway
5.2. Limitations
5.3. Future Outlook