Beyond Simple Connections: Enhancing OSN Security with Attribute-Aware ReBAC
Attribute-Aware Relationship-Based Access Control for Online Social Networks
The paper proposes an attribute-aware Relationship-Based Access Control (ReBAC) model for Online Social Networks (OSNs), extending the prior UURAC framework. It integrates Attribute-Based Access Control (ABAC) into ReBAC to allow fine-grained policies based on user/relationship attributes and topological constraints like common friend counts.
TL;DR
While "Friend" or "Friend of Friend" is the standard for social media privacy, it isn't granular enough for modern security needs. This paper introduces an Attribute-Aware ReBAC model that combines relationship logic with user/edge attributes. By extending the UURAC model, the authors allow users to define rules like "Allow access if we share 5 student friends" or "Trust if the connection strength is > 0.5."
The "Relationship-Only" Limitation
Standard Relationship-Based Access Control (ReBAC) is excellent for scalability in Online Social Networks (OSNs). However, it has two major blind spots:
- Topological Ignorance: It cannot easily count paths (e.g., "at least five common friends").
- Context Blindness: It ignores specific attributes of the people on the path (e.g., "must be a friend who lives in Texas").
To solve this, the authors argue for a hybrid approach: ReBAC + ABAC.
Methodology: The Attribute-Aware Framework
The core innovation lies in the integration of Node, Edge, and Count attributes into a path-checking logic based on regular expressions.
1. The Three Layers of Attributes
- Node Attributes: Metadata about users (age, location, occupation).
- Edge Attributes: Metadata about the relationship itself (trust level, duration).
- Count Attributes: A predicate that checks how many qualifying paths exist between the requester () and the target ().
2. Policy Specification and DFA
The model uses an extended grammar where policies are represented as:
⟨action, (starting_node, path_rule : attribute_policy)⟩

The system converts the "path" part of the rule into a Deterministic Finite Automaton (DFA). As the algorithm traverses the social graph, it uses the DFA to ensure the relationship types match the allowed sequence while simultaneously checking attribute conditions at each hop.
Enhanced Path-Checking Algorithm
A simple DFS (Depth-First Search) isn't enough when you need to verify attributes on the fly. The authors proposed a modified DFS Path-Checker that:
- Tracks
stateHistoryof the DFA. - Maintains an
attrListto store attributes of nodes and edges currently in the recurrence stack. - Evaluates boolean functions before deciding to continue a path.
This "on-the-fly" checking is significantly more efficient than finding all paths first and filtering them later.
Experiments & Real-World Utility
The paper highlights three key scenarios that this model enables:
- Common Friends: Alice allows access only to those who share at least common friends.
- Transitive Trust: Access is granted only if the product of trust values along a multi-hop path exceeds a threshold.
- Demographic Filtering: Restricting access based on the attributes of the intermediaries (e.g., "only through paths involving adult users").

From a performance standpoint, the complexity remains exponential relative to hop count (), which is the inherent cost of path searching in large graphs. However, the attribute check adds only a constant overhead ( per edge/node), making it practical for real OSN implementions.
Critical Insight & Conclusion
The primary value of this work is the unification of topology and context. By treating "Count" as an attribute, the model effectively bridges the gap between local relationship checks and global graph properties.
Takeaway: Future access control systems should not treat "who you know" and "who you are" as separate silos. The marriage of ReBAC and ABAC is the roadmap for fine-grained privacy in interconnected digital ecosystems.
Limitations: The model assumes attributes are static or updated synchronously. In a real-world OSN, attribute-tracking at scale while performing path-checking in real-time remains a significant engineering challenge for high-latency environments.
