Beyond "Friends Only": A Formal Logic for Social Network Privacy
A Privacy Preservation Model for Facebook-Style Social Network Systems.
The paper introduces a formal access control model for Facebook-style Social Network Systems (SNSs). It defines a framework that generalizes SNS privacy mechanisms, where authorization is a function of "search listing reachability" and "social graph topology," effectively situating Facebook as one of many possible instantiations.
TL;DR
Social networks like Facebook don't follow traditional security rules. This paper presents the first formal model to explain how SNS privacy actually works—treating your "search listing" like a secure key (capability) and your "friend list" as a map for authorization. It moves beyond simple binary "friend" checks to complex graph-based policies like "k-cliques" and "degrees of separation."
The "Facebook Paradox": Why Traditional Security Fails
In a standard corporate system, an administrator decides who is a "manager" or "employee" (RBAC). In a Social Network System (SNS), there is no central admin. You, the user, co-construct the security state every time you accept a friend request.
The authors identify three distinctives (D1-D3) that make SNS security unique:
- Capability Mediation: You can't see someone's data unless you first "find" their profile—their search listing acts as a capability handle.
- Relation-Based Policies: Access isn't granted to "User 123," but to "anyone who is a friend of a friend."
- Graph Abstraction: The system looks at the global "Social Graph" to make local decisions.
Methodology: The Anatomy of a Social System
The authors define a Social Network System as a formal quintuple. The engine of the model rests on two pillars:
1. The Communication Automaton (CA)
How does a stranger become a friend? The CA defines the "protocol" of friendship. It tracks states like stranger -> invited -> friend.
Figure 1: Example of a State Transition for friendship articulation.
2. The Two-Stage Authorization
- Stage I: Reachability: Can User A even see User B's profile? This is governed by Search and Traversal policies. You might find B through a global search or by "traversing" a mutual friend's list.
- Stage II: Accessibility: Once you find the profile, which "Profile Items" are you allowed to see? This is the Access Policy.
Figure 2: Formal logic for social graph traversal (F-TRV).
Advanced Social Policies: The Power of Topology
The true beauty of this model is its ability to describe policies that Facebook didn't have yet, but are socially intuitive:
- Known Quantity: "I'll let you see my photos only if we share at least 5 mutual friends."
- Cliques: "I'll share my location only with people who are part of a tightly-knit 4-person group where everyone knows everyone."
- Anti-Monotonic (Stranger) Policies: "Only show this 'Public help' post to people who are not my friends (distance > 3)."
Case Study: From Recreation to E-Learning
The paper applies this to an E-Learning environment. Imagine a peer-tutoring system where:
- Peer Help: A student restricts their "Help Needed" status to a social circle of radius 2 (Distance-2).
- Blind Review: To ensure fairness, a paper is only visible to "strangers" (Anti-monotonic distance policy) to prevent bias among close friends.
Critical Insight & Conclusion
By formalizing the "Social Graph" as the primary source of truth for authorization, Fong et al. laid the groundwork for what is now known as ReBAC (Relationship-Based Access Control).
Takeaway: Privacy in the social era isn't about who you are, but where you sit in the web of connections. While the model is mathematically elegant, its real-world challenge lies in Safety Analysis: how can a user be sure that befriending a "friend-of-a-friend" won't accidentally leak their private data to a "stranger" via a shortcut in the graph? This paper provides the first formal language to even begin asking that question.
