Extended Identity: Breaking the Data Silos of Social Networks

Extended Identity for Social Networks

2010-01-01
Antonio Tapiador, Antonio Fumero, Joaquín Salvachúa
Summary
Problem
Method
Results
Takeaways
Abstract

The paper proposes an "Extended Identity" architecture for distributed social networking, leveraging OpenID to transform IDs into dereferenceable URIs. It enables an interoperable ecosystem where user profiles, contacts, and content are synchronized across isolated Social Network (SN) platforms.

TL;DR

This research addresses the "Gated Community" problem of early social media by proposing a distributed architecture. By using dereferenceable IDs (based on OpenID), it allows users to maintain a single, authoritative profile that connects their scattered activities—from Flickr photos to WordPress posts—into a coherent, cross-platform digital identity.

The Problem: Fragmented Self in a Siloed Web

In the mid-2000s (and arguably still today), the social web was a collection of isolated islands. You had your "contact-oriented" networks (LinkedIn, early Facebook) and your "content-oriented" services (YouTube, Flickr).

The authors identify two massive pain points:

  1. Identity Fragmentation: Users have different credentials and profiles for every site.
  2. Information Isolation: There is no "interoperability as an added value." Your blog doesn't know about your latest photo upload, and your professional network doesn't see your latest research slides unless manually updated.

Methodology: The Extended Identity Architecture

The core insight is that a user ID should not just be a string (like a username) but a dereferenceable URI. When a Social Network (SN) receives this URI, it can "look it up" to find a rich set of metadata.

The authors split the ecosystem into three roles:

  • Identity Server (IS): The user's home base. It acts as a proxy, storing the authoritative profile and managing access control lists (ACLs).
  • Resource Server (RS): Third-party services (like a blogging site) that relay authentication to the IS and exchange data with it.
  • Client Agent (CA): The user's local environment (browser/mobile) that facilitates interaction.

Distributed Identity Architecture

Information Flows: Push & Pull

To make identity "extended," the architecture defines two-way communication:

  • Pull (RS -> IS): The social network asks the Identity Server for user attributes (e.g., "Show me this user's latest HCard microformat info").
  • Push (RS -> IS): When a user performs an activity (posts a video), the Resource Server pushes notification of this activity back to the Identity Server to update the global profile.

The Components in Action

Experiments and Validation

The authors validated this approach by developing a Ruby on Rails plugin (Rails Station Engine) that supports multiple authentication schemes. This plugin was integrated into the Virtual Conference Center (VCC), proving that specialized social platforms can leverage distributed identity to enrich user experiences without forcing them to create new accounts from scratch.

Furthermore, they mapped their architecture to Google’s OpenSocial API, demonstrating that their model of contacts, activities, and persistent data perfectly matches the industry trend toward social interoperability.

Critical Insight: The Shift to User-Centricity

The true value of this paper is its early advocacy for User-Centric Identity. Instead of the platform owning the user, the user owns an Identity Server that "delegates" information to platforms.

Limitations & Future Outlook

While the architecture is robust, it relies heavily on the adoption of standards like OpenID and AtomPub, many of which have since been superseded by OIDC (OpenID Connect) and ActivityPub (the engine behind the Fediverse). The "Privacy vs. Interoperability" trade-off mentioned by the authors remains the central tension in social tech today.

Conclusion: This paper serves as a foundational blueprint for what we now see in the decentralized web: an internet where your identity is a portable asset, not a entry in a corporate database.

Find Similar Papers

Try Our Examples

  • Search for recent papers that extend decentralized identity (DID) frameworks specifically for cross-platform social graph portability.
  • How has the transition from OpenID 2.0 to Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) addressed the privacy concerns raised in early distributed social network architectures?
  • Analyze the evolution of the Atom Publishing Protocol and OpenSocial API into the modern ActivityPub and W3C Social Web standards.
Contents
Extended Identity: Breaking the Data Silos of Social Networks
1. TL;DR
2. The Problem: Fragmented Self in a Siloed Web
3. Methodology: The Extended Identity Architecture
3.1. Information Flows: Push & Pull
4. Experiments and Validation
5. Critical Insight: The Shift to User-Centricity
5.1. Limitations & Future Outlook