Shielding Social Connections: Advanced Privacy-Preserving Friend Discovery via Proxy Re-encryption

A Privacy Preserving Friend Discovery Strategy Using Proxy Re-encryption in Mobile Social Networks

2016-01-01
Entao Luo, Wenbo Wang, Dacheng Meng, Guojun Wang
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces a privacy-preserving friend discovery strategy for Mobile Social Networks (MSN) using Proxy Re-encryption (PRE) and Ciphertext-Policy Attribute-Based Encryption (CP-ABE). It enables secure cross-domain data matching and sharing among different Trusted Authorities while achieving fine-grained access control and hidden access policies.

TL;DR

In the age of Mobile Social Networks (MSN), finding "friends like me" usually involves exposing "who I am." This paper proposes a novel framework that uses Proxy Re-encryption (PRE) and Multi-Authority CP-ABE to allow users to match with others across different domains (like different cloud providers) without ever revealing their underlying access policies or sensitive profile data to untrusted servers.

Problem & Motivation

Most current friend-matching systems suffer from two fatal flaws:

  1. The Single Authority Bottleneck: They assume every user is registered under the same "Trusted Authority." In the real world, users are fragmented across different apps and service domains.
  2. Structural Privacy Leakage: Standard CP-ABE (Ciphertext-Policy Attribute-Based Encryption) attaches an "access tree" to the encrypted data. Even if an attacker can't decrypt the file, they can see the policy (e.g., "Must be a 25-year-old female living in London"), which is a massive privacy leak in a social context.

The authors' insight is to decouple the data owner from the requester via a Data Proxy (DP). By using re-encryption, the specific "logic" of the owner's friend-making criteria is hidden behind a proxy's secondary policy.

Methodology: The Architecture of Trust

The system model comprises five key actors: the Trusted Authority (TA), Friend Server (FS), Data Owner (DO), Data Proxy (DP), and Data Requester (DR).

1. Dual-Layer Encryption

The Data Owner doesn't just encrypt data; they encrypt it using a symmetric key (), and then encrypt that key using CP-ABE. This ensures that only users fitting the "Friend Profile" can ever unlock the symmetry key.

2. The Re-encryption Magic

When a Data Proxy (like a mutual friend or a specialized matching node) wants to facilitate a connection, it generates a Re-encryption Key. The Friend Server uses this key to transform the original ciphertext into a new one that matches the Proxy's access structure.

System Model and General Structure

3. Cross-Domain Compatibility

One of the mathematical highlights is the scheme's ability to handle users from different domains. If User A (Alice) is in Domain 1 and User C (Cindy) is in Domain 2, the Proxy (Bob) can fetch the public key of Cindy’s domain to compute the re-encryption, bridging the gap between isolated "trust islands."

Experiments and Results

The authors performed a rigorous security proof using the Decisional Bilinear Diffie-Hellman (DBDH) assumption.

Security Highlights:

  • Collusion Resistance: Malicious users cannot combine their attribute keys to satisfy a policy that none of them could satisfy individually.
  • CPA Security: The scheme is proven secure against Chosen Plaintext Attacks, meaning the ciphertext leaks no information about the underlying plaintext variables.

Performance:

The computational cost and ciphertext size were found to be linear relative to the number of attributes. Notation and Parameters Table (Note: As seen in the formulas in Section 3, the transformation in Section 3.4 equation (9) demonstrates that the proxy can perform the heavy lifting of re-encryption, significantly reducing the local computational burden on mobile devices.)

Critical Analysis & Conclusion

Takeaway

By introducing a Proxy Re-encryption layer, this paper successfully addresses the "Privacy-Efficiency-Scalability" trilemma in Mobile Social Networks. It moves the needle from "simple set intersection" matching to "fine-grained access control" matching.

Limitations

While the scheme reduces the bottleneck of a single TA, the Friend Server is still considered "honest but curious." If the Friend Server and the Data Proxy were to collude, some levels of anonymity could potentially be compromised. Furthermore, the paper focuses on the cryptographic overhead—future work should evaluate the real-world latency in high-mobility MSN environments.

Future Outlook

As decentralized social networks (like Mastodon or Farcaster) grow, the "cross-domain" aspect of this research becomes more relevant. We expect to see these re-encryption strategies applied to Web3 social protocols to allow peer-to-peer discovery without a central authority having a "God View" of user preferences.

Find Similar Papers

Try Our Examples

  • Search for recent papers that specifically address access policy hiding in Ciphertext-Policy Attribute-Based Encryption (CP-ABE) for mobile edge computing.
  • Which original research proposed the combination of Proxy Re-encryption and ABE, and how does this paper's multi-domain approach differ from that foundation?
  • Investigate how the Decisional Bilinear Diffie-Hellman (DBDH) assumption is utilized in modern privacy-preserving Friend Discovery beyond social networks, such as in Healthcare or IoT.
Contents
Shielding Social Connections: Advanced Privacy-Preserving Friend Discovery via Proxy Re-encryption
1. TL;DR
2. Problem & Motivation
3. Methodology: The Architecture of Trust
3.1. 1. Dual-Layer Encryption
3.2. 2. The Re-encryption Magic
3.3. 3. Cross-Domain Compatibility
4. Experiments and Results
4.1. Security Highlights:
4.2. Performance:
5. Critical Analysis & Conclusion
5.1. Takeaway
5.2. Limitations
5.3. Future Outlook