Social Access Controller: Transforming Smart Things into Social Assets
Sharing using social networks in a composable Web of Things
The paper introduces the Social Access Controller (SAC), a platform designed to enable secure sharing of "Web of Things" (WoT) devices using existing social networks. By leveraging RESTful APIs and social structures from platforms like Facebook and Twitter, it allows device owners to grant granular access to smart things—such as energy meters and actuators—to trusted connections without a centralized data silo.
TL;DR
The paper proposes the Social Access Controller (SAC), a framework that bridges the gap between the Web of Things and Social Networks. It allows you to share access to your physical devices (like smart plugs or heaters) with your Facebook friends or Twitter followers by treating hardware functionalities as RESTful resources. This moves the IoT away from "walled gardens" and into a composable, social ecosystem.
Background & Motivation: The Problem with Isolated Islands
While thousands of devices are becoming "Internet-connected," they remain fragmented. Most require proprietary apps, and sharing access with a friend usually involves the insecure exchange of passwords or using centralized platforms that store your data.
The authors argue that we shouldn't build new user databases for every smart device. Instead, we should leverage the Social Graph we already have. Why create a new "friend list" for your smart home when you already have one on LinkedIn or Facebook?
Methodology: How Social Sharing Works for Hardware
The core of the system is the Social Access Controller (SAC), which operates on three pillars:
- RESTful Everything: Every device function is mapped to a URL (e.g.,
.../lamp/status) and standard HTTP verbs (GET to read, PUT to toggle). - Delegated Authentication: By using OAuth, the system never sees your social network password. It simply asks Facebook, "Is this person actually who they say they are?"
- The Crawler: SAC explores your devices to see what they can do. It checks which methods (PUT, POST, GET) are supported, allowing you to give a friend "Read-Only" access to your energy sensor but "Read-Write" access to your Hi-Fi system.
Figure 1: The SAC acts as a security proxy between the untrusted Web and the private smart device.
Real-World Implementation: FAT (Friends and Things)
The authors built a JavaScript application called FAT (Friends and Things) that serves as a dashboard for this "Social IoT."
- The Workflow: An owner adds a "Smart Gateway" (bridging protocols like Zigbee to the Web), logs in via Facebook, and checks off which friends can use which devices.
- Notification: When you share a device, SAC can automatically "tweet" or post to your friend's newsfeed with a direct URI to the device.
Figure 2: The FAT interface showing how social connections are mapped to device resources.
Critical Insight & Future Outlook
The beauty of this approach is composability. Because SAC exposes a RESTful API itself, other developers can build "Physical Mashups." For instance, a "Going Out" app could check the energy status of your friends' TVs to see if they are home before suggesting a drink nearby.
Limitations & Challenges:
- The Proxy Bottleneck: As SAC sits between the user and the device, it must be highly scalable to avoid becoming a single point of failure.
- Walled Gardens: While the paper advocates for OpenSocial, many platforms (like Facebook) intentionally make it hard to export social data, which threatens the "Open Web" vision.
Conclusion
This work is a seminal step toward a "Composable Web of Things." It shifts the focus from the connectivity of things (the "Internet" part) to the usability and social sharing of things (the "Web" part). By turning physical devices into URL-accessible social assets, the authors provide a blueprint for a more integrated and human-centric smart world.
