Breaking the Walled Garden: eU+F Protocol for Interoperable and Private Social Networks
Extended U+F Social Network Protocol: Interoperability, reusability, data protection and indirect relationships in Web Based Social Networks
The paper introduces eU+F (Extended UMA + FOAF), an interoperable social network protocol that combines User-Managed Access (UMA) and Friend-Of-A-Friend (FOAF) with cryptographic techniques. It achieves decentralized data management across disparate Web-Based Social Networks (WBSNs), enabling secure direct and indirect relationship discovery while maintaining SOTA data protection against service providers.
TL;DR
Current social networks like Facebook and LinkedIn are digital silos that own your data. This paper presents eU+F, a protocol that uses the UMA (User-Managed Access) and FOAF (Friend-Of-A-Friend) standards to decouple your data from the platform. It allows you to share photos and profiles across different social networks securely, managing even "friends of friends" connections without ever letting the social network provider see your private information.
The Motivation: Why Your Privacy is Currently an Illusion
Most Web-Based Social Networks (WBSNs) operate on a centralized model. When you join, you grant the provider total control. The authors identify four critical gaps in current systems:
- Lack of Interoperability: You can't easily interact with a user on a different platform.
- No Reusability: You have to re-upload profiles and data for every new network.
- Provider Overreach: Providers can (and do) mine your data for profit.
- Indirect Relationship Complexity: Managing access for "friends of friends" across platform boundaries is mathematically and logistically difficult.
Methodology: The Architecture of eU+F
The core "magic" of eU+F lies in its decentralized architecture. Instead of one server holding everything, the duty is split among four specialized entities:
- Identity Provider (IdP): Stores your social graph (FOAF files).
- Host: A repository for your encrypted resources (photos, videos).
- Authorization Manager (AM): Evaluates access policies on your behalf.
- WBSN (The Viewer): Simply acts as the interface or "browser" for the data.
1. Data Exposure Minimization
To prevent the WBSN from snooping, eU+F uses local decryption. Data is stored encrypted on the Host. The decryption keys are shared only between the Requesting Party and the Authorizing User through a secure cryptographic handshake. The social network only sees the "ciphertext."
2. Managing Indirect Relationships
This is the paper’s major contribution. If User A wants to see User C's photo via their mutual friend User B, the protocol builds a recursive Chain of Trust.
Figure 1: The decentralized architecture separating Identity, Resources, and Policies.
The protocol verifies each "jump" in the social path. For a 3-hop relationship, it requests a signature from each intermediate friend's IdP to prove the connection exists without exposing the entire social graph to the requester.
Experimental Results: Is it Usable?
The authors developed a prototype involving two simulated networks: FriendBook+ and MyLeisure.
- Latency: Accessing a direct contact's profile takes approximately 3.4 seconds. While slower than Facebook's internal cache, it is remarkably close to LinkedIn's profile loading times.
- Local Decryption: The overhead for RSA-2048 and AES-128 decryption is negligible (~86ms), proving that privacy doesn't have to kill performance.
- Scalability: By reusing "claims" (security tokens), the protocol reduces network traffic by nearly 60%.
Figure 2: Prototype performance vs. Facebook and LinkedIn. eU+F shows competitive speeds for profile access.
Critical Insights & Takeaways
The eU+F protocol demonstrates that the "Walled Garden" is an intentional business choice, not a technical necessity. By leveraging established standards like UMA and FOAF:
- Ownership is Restored: Users can "unplug" their data from one WBSN and plug it into another without losing their social graph.
- Security by Design: Even if a Host or WBSN is compromised, the data remains encrypted.
Limitations: The primary bottleneck is the "indirect relationship" discovery in very large graphs, which could lead to an exponential number of requests if the path is deep. However, for the "six degrees of separation" standard, eU+F remains functionally viable.
Conclusion
This work is a significant step toward a truly democratic social web. It provides a robust theoretical and practical framework for users to reclaim their digital identities from centralized giants while still enjoying the rich, interconnected social experiences that modern WBSNs provide.
