Selective Disclosure: Achieving GDPR Data Minimization via Social Networks

9425_A Lightweight Scheme Exploiting Social Networks for Data Minimization According to the GDPR.

Summary
Problem
Method
Results
Takeaways
Abstract

This paper proposes a lightweight data minimization scheme for online service access, leveraging Social Networks (SN) as a transparent repository for hidden credentials. By combining eIDAS-compliant authentication with XOR-based secret sharing, it enables selective attribute disclosure without relying on heavyweight blockchain technology.

TL;DR

Researchers have developed a lightweight privacy framework that uses everyday social networks (Facebook, Instagram) to handle secure credentials. By utilizing XOR operations and hash functions, users can prove specific attributes (like "being over 18") to service providers without revealing their full identity, ensuring full compliance with GDPR's Data Minimization principle at a fraction of the cost of blockchain solutions.

The Privacy Paradox in Digital Identity

Under the General Data Protection Regulation (GDPR), the principle of data minimization dictates that personal data must be "adequate, relevant, and limited to what is necessary." However, the reality of the web is quite different. When you prove your age via a driver's license scan to a video platform, you often hand over your full name, home address, and exact birthdate.

Standard solutions have recently pivoted toward Self-Sovereign Identity (SSI), usually backed by blockchain. While robust, blockchains are often expensive (fees), slow (consensus latency), and legally "sticky"—once data is on a chain, it is nearly impossible to exercise the "Right to be Forgotten."

The Core Insight: Social Networks as Secure Middlemen

The authors of this paper propose a "middle way." Instead of a permanent ledger, they use the temporary and familiar environment of Social Networks (SN). The logic is simple:

  1. Trust without Visibility: Use social networks to store "halves" of a credential.
  2. Lightweight Crypto: Avoid heavy asymmetric encryption in favor of XOR and Hashes.
  3. User Agency: The user controls the "key" and can revoke access by simply deleting a post.

Methodology: How the Split-Credential Works

The protocol involves three main actors: the User (U), the Attribute Provider (AP) (e.g., a University or Gov body), and the Service Provider (SP).

Overall Architecture

  • Generation: The AP creates a credential and encrypts it using two random seeds: one from the user () and one from themselves ().
  • The Post: The AP posts their encrypted half () on their public profile, indexed by a hashtag.
  • The Activation: When the user wants to use the service, they post their "half" () on their own profile.
  • Reconstruction: The Service Provider (SP) pulls both posts, applies the user’s secret, and performs XOR operations to recover the plain-text attribute.

Mathematical Intuition: By using , the credential is effectively locked by two keys. The XOR function is computationally "cheap" but cryptographically strong when used with high-entropy pseudorandom numbers.

Experimental Results: Performance & Scalability

The researchers implemented this on Facebook, using SHA-256 for hashing.

Performance Comparison Table

Key findings include:

  • Latency: Service access takes ~3 seconds. Most of this time is waiting for Facebook's API, not the computation.
  • Cost Efficiency: Unlike Ethereum-based SSI (e.g., uPort), there are no gas fees. The infrastructure is effectively "rented" for free from the social network provider.
  • Scalability: Because the SP only performs a few hashes and XORs, the system can scale to millions of users, limited only by the social network's own availability.

Critical Analysis & Conclusion

The brilliance of this scheme lies in its pragmatism. While academic circles often chase the "perfect" decentralization of blockchain, this method recognizes that billions of people already use Facebook and Instagram daily.

Advantages:

  • Easy Revocation: If a user wants to "hide" their attribute, they delete their post. The SP can no longer reconstruct the credential.
  • GDPR Compliance: It naturally supports the "Right to Erasure" and "Data Minimization."

Limitations:

  • Platform Dependency: The system relies on the Social Network’s Post, Send, and Search functions. If a platform like Twitter limits API access or changes hashtag indexing, the system breaks.
  • Trust in eIDAS: The initial identity verification still relies on traditional Identity Providers (IP), meaning it is a hybrid model rather than a "pure" SSI.

In summary, this lightweight scheme provides a highly deployable alternative for organizations that need to satisfy regulatory requirements without the overhead of emerging tech stacks. It turns our "public" social profiles into "private" cryptographic vaults.

Find Similar Papers

Try Our Examples

  • Search for recent studies that implement GDPR data minimization principles using non-blockchain decentralized identity systems.
  • Which paper first defined the "ten principles of self-sovereign identity," and how does this social network-based scheme align with the 'Control' and 'Minimization' principles?
  • Explore research applying XOR-based secret sharing or lightweight cryptographic hashes to privacy-preserving authentication in Internet of Things (IoT) or E-health environments.
Contents
Selective Disclosure: Achieving GDPR Data Minimization via Social Networks
1. TL;DR
2. The Privacy Paradox in Digital Identity
3. The Core Insight: Social Networks as Secure Middlemen
3.1. Methodology: How the Split-Credential Works
4. Experimental Results: Performance & Scalability
5. Critical Analysis & Conclusion