OSNAC: Reclaiming Privacy Through Semantic Relations in Social Networks
OSNAC: An Ontology-based Access Control Model for Social Networking Systems
This paper introduces OSNAC (Ontology-based Social Network Access Control), a formal model leveraging Semantic Web technologies (OWL, SWRL, and SPARQL) to manage fine-grained privacy in Social Networking Systems. It distinguishes itself by protecting semantic relations between entities rather than just the entities themselves, utilizing a Social Networking systems Ontology (SNO).
TL;DR
OSNAC (Ontology-based Social Network Access Control) is a research framework that moves away from the "all-or-nothing" privacy settings of platforms like Facebook. By using Semantic Web standards (OWL, SWRL), it allows users to define rules on the relationships themselves—such as who can see a tag in a photo—and introduces a formal "Joint Authority" model where multiple users must agree before information is disclosed.
Context & Positioning
In the landscape of access control, this work sits at the intersection of Attribute-Based Access Control (ABAC) and Semantic Reasoning. While early 2000s models focused on simple trust scores (e.g., "Friend of a Friend" distance), OSNAC is a SOTA-level attempt to bring formal logic to the messy, interconnected data of modern social media.
The Problem: Relationships are the Blind Spot
Current Social Networking Systems (SNSs) treat data as isolated entities. However, social data is inherently relational. If Alice tags Bob in a photo she owns, who owns the "privacy" of that tag?
- Prior Work Flaw: Existing systems usually prioritize the owner, ignoring the subject's right to control their digital footprint.
- Consistency Issues: Hiding a relationship on your profile is useless if it remains visible on your partner's profile.
- Lack of Multi-Authority: There is no formal way to say "Both Alice AND Bob must permit this access."
Methodology: The Power of Reification
The core innovation of OSNAC is how it handles Relations. In standard Web Ontology Language (OWL), you can't easily set permissions on a "link" between two people. OSNAC solves this via Reification: turning a relationship (like isFriendOf) into an object that can itself be governed by rules.
1. The SNO and ACO Ontologies
The authors propose a Social Networking systems Ontology (SNO) to model People, DigitalObjects, and Events. This is paired with an Access Control Ontology (ACO) which defines actions like ac:canRead and ac:authorizes.
2. The Rule Framework
OSNAC uses SWRL (Semantic Web Rule Language) to define three types of rules:
- Personal Authorization: "I allow my friends to see my tags."
- Delegative Authorization: "I trust Bob to manage who sees my photos."
- System Authority: Rules that settle who has the "Right to Decide" (the Principal Authority).
Figure 1: The OSNAC Policy Framework, showing the integration of User and System-level rules.
Enforcement via Query Augmentation
Rather than checking permissions one by one (which is slow), OSNAC performs Query Augmentation. When a user runs a SPARQL query, the system automatically injects access control primitives. If the user doesn't have permission for a specific "edge" in the social graph, that data simply isn't returned.
Example of an Augmented Query Construction: If Bob asks for "Alice's Friends in Pittsburgh," the engine rewrites it to check:
- Does Bob have
canReadon thefriendOflink? - Does Bob have
canReadon theresidesInlink? - Does Bob have
canReadon thehasFullnamelink?
Experiments & Performance
The implementation was built using Java and the Jena Semantic Web framework.
Table 1: Performance metrics showing the trade-off between initialization and subsequent query speed.
Analysis of Results:
- Inference Overhead: As seen in Table 1, the first inference for a network of 125 users takes over an hour (4584s). This highlights the heavy computational cost of OWL-DL reasoning.
- Caching Efficacy: Once the initial reasoning is done, subsequent checks take mere milliseconds (0.006s). This suggests the model is viable if reasoning can be done offline or incrementally.
Critical Insight & Conclusion
Takeaway: OSNAC successfully moves the needle from "Object-Centric" to "Link-Centric" security. Its support for Conjunctive Multi-Authority (requiring multiple users to approve access) is a significant step toward true digital privacy.
Limitations:
- Scalability: The exponential growth in reasoning time for a 125-user network is a major hurdle for platforms like Facebook with billions of users.
- Usability: While the backend is robust, the authors admit that asking average users to write logic rules is unrealistic.
Future Outlook: The future of this work lies in Incremental Reasoning—where only the changes in the social graph trigger new logic checks—and in developing "NLP-to-Policy" interfaces that translate user intent into the formal SWRL rules seen here.
