Bridging Social Context and Privacy: Expanding Access Control with Public Information

A new access control scheme for Facebook-style social networks

2015-05-07
Jun Pang, Yang Zhang
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces a novel relationship-based access control (ReBAC) scheme for Online Social Networks (OSNs) like Facebook. It integrates "Public Information" (e.g., locations, organizations, interests) as a first-class entity alongside users, utilizing a hybrid logic framework to define fine-grained policies.

TL;DR

Existing social network privacy settings are often too blunt, relying purely on who you know. This paper introduces a dual-graph model that integrates Public Information (locations, companies, hobbies) into the access control logic. By using an extended Hybrid Logic, users can now write precise policies like "Only friends who work for my company's rival can see this," effectively turning the social graph into a sophisticated semantic network.

The Motivation: Why "Friend of Friend" Isn't Enough

Online Social Networks (OSNs) have evolved into "Geo-Social" and "Professional" hubs. Yet, our privacy tools are stuck in 2010. Consider these gaps:

  • Location Awareness: You want to share a post about a car break-in only with people in your neighborhood, regardless of friendship status.
  • Professional Boundaries: You want to hide a party photo from colleagues, but show it to friends who work for competitors.
  • Semantic Clumping: You want to share content with "Sports fans," but current systems don't understand that a "Lakers fan" is a sub-category of "Basketball," which is a sub-category of "Sports."

Prior SOTA methods treated these attributes as simple strings. This paper argues that public information should be its own graph, connected to the user graph, allowing for logical jumps between "Who I know" and "What I am associated with."

Methodology: The Dual-Graph Hybrid Logic

The core innovation lies in the architectural split of the OSN into two distinct but interconnected layers:

  1. User Graph (UG): Classic social nodes and relationships (Friend, Colleague, Parent).
  2. Public Information Graph (PG): Entities like "Paris," "UNICEF," or "Tennis," including hierarchical relationships like is-in or is-a.

Architecture of the Model

The authors represent the system as , where maps users to public info, and maps public info back to users.

Overall Architecture

To navigate these graphs, the authors extend Hybrid Logic. The key "magic" happens with two new operators:

  • : From a user node, jump to the Public Information Graph to check if the user is linked to an entity satisfying .
  • : From a public info node, jump back to the User Graph to check if the linked users satisfy .

Handling the "Category" Problem

To solve the "Sports fan" vs "Tennis fan" issue, the authors introduce the Category Nominal . This allows the logic to automatically include all descendants in a hierarchy, preventing users from having to manually list every possible sub-category in their privacy settings.

Experiments and Comparisons: Beyond Interpersonal Links

The paper demonstrates expressiveness through complex scenarios. For example, a "3-common charities" policy (Scenario 2) ensures that a requester is not just a stranger but someone deeply embedded in the same social causes as the owner.

SOTA Comparison Table

The authors compare their scheme against foundational works like Fong et al. and Carminati et al.

Performance Comparison Table

Unlike previous models, this is the only framework that handles Public Information, Trust Levels, and Topology-based policies (like cliques) simultaneously. It also addresses Information Reliability by allowing "endorsements"—requiring that a user's claim to work at a certain company be verified by other users in that same company.

Critical Analysis & Conclusion

The "Takeaway"

The industry value of this work is the shift from Identity-Based to Context-plus-Relationship Based access control. As Facebook’s "Graph Search" demonstrated years ago, the data already exists; this logic providing the formal backbone to make that data searchable and securable.

Limitations & Future Work

  • Complexity for End-Users: While the logic is powerful, writing hybrid logic formulas is impossible for the average user. A UI/UX layer that translates "natural language" to these formulas is missing.
  • Performance: Local model checking on two massive graphs can be computationally expensive as the depth of relationship paths increases.
  • Privacy of the Policy: The paper assumes policies are public or handled by a trusted server, but the policy itself might reveal private intentions of the owner.

In conclusion, by treating external knowledge (the Public Information Graph) as equal to social ties, Pang and Zhang have provided a robust roadmap for the next generation of social privacy frameworks.

Find Similar Papers

Try Our Examples

  • Search for recent papers that extend relationship-based access control (ReBAC) using knowledge graphs or semantic web technologies in the context of Decentralized Social Networks (Deso).
  • Which paper first introduced the use of hybrid logic for social network access control, and how does the current work's syntax for graph traversal differ from that origin?
  • Examine research that applies hybrid logic or modal logic frameworks to privacy-preserving access control in Geo-Social Networks (GSNs) or Internet of Things (IoT) ecosystems.
Contents
Bridging Social Context and Privacy: Expanding Access Control with Public Information
1. TL;DR
2. The Motivation: Why "Friend of Friend" Isn't Enough
3. Methodology: The Dual-Graph Hybrid Logic
3.1. Architecture of the Model
3.2. Handling the "Category" Problem
4. Experiments and Comparisons: Beyond Interpersonal Links
4.1. SOTA Comparison Table
5. Critical Analysis & Conclusion
5.1. The "Takeaway"
5.2. Limitations & Future Work