EAP-SocTLS: Automating WiFi Access through Physical Proximity and Social Trust
WiFi Authentication through Social Networks – a Decentralized and Context-Aware Approach –
The paper introduces EAP-SocTLS, a decentralized authentication and authorization framework for WiFi Access Points (APs) that leverages distributed social networks (WebID). It eliminates the need for manual password sharing by establishing trust relations between device owners and AP owners, achieving a localized authorization speedup for indirect friends.
TL;DR
Forget sharing your WiFi password with guests. EAP-SocTLS is a decentralized protocol that turns your WiFi Access Point (AP) into a "socially aware" device. By linking hardware owners to distributed social profiles (WebID), it authenticates guests automatically if a trust link exists. Crucially, it uses WiFi probe requests—those silent signals your phone sends to find networks—to identify which friends are nearby, slashing the time it takes to find a trust connection from minutes to seconds.
The Problem: The Security-Convenience Paradox
Most home WiFi security is fundamentally broken. We either use weak, shared passwords or leave our networks open to friends, creating a security liability. While centralized solutions (like Facebook login via Captive Portals) exist, they are privacy nightmares and fail if the internet goes down.
The academic challenge for a decentralized social WiFi system is the "Indirect Friend" problem. If Alice visits Bob, but they are only connected through a mutual friend, Charlie, the AP must crawl through social profiles over HTTPS to find that link. This search space grows quadratically, leading to a frustrating "waiting for authentication" screen that can last over a minute.
Methodology: The "Local Bridge" Insight
The authors propose EAP-SocTLS (Extensible Authentication Protocol - Social TLS). It replaces the standard Certificate Authority (CA) check with a WebID lookup.
1. Architectural Integration
The system modifies hostapd (the standard Linux daemon for APs) to include a Python-based authorization library. Instead of checking if a certificate is signed by "VeriSign," the AP:
- Fetches the client's public profile (FOAF).
- Verifies the client owns the private key.
- Searches the social graph for a
foaf:knowslink between the AP owner and the client owner.
2. Context-Aware Optimization
To beat the quadratic search complexity, the authors hit on a physical intuition: If you are visiting a house and you are an "indirect friend," the "bridge" (the mutual friend) is likely standing in the same room.

By sniffing 802.11 probe requests, the AP maintains a list of MAC addresses and arrival times of nearby devices. When an unknown client tries to connect, the AP doesn't search the entire global social graph; it only looks at the social circles of people currently in the vicinity.
Experiments And Results: Speeding Up the Handshake
The authors tested EAP-SocTLS using a Samsung Galaxy S2 and a Dell Ultrabook.
The Search Scalability
Without optimization, as the "neighbor degree" (number of friends) increases, the time required to establish a trust link via an indirect friend explodes.

Key Findings:
- Naive Indirect Search: For a social degree of 4, it took ~60s.
- Context-Aware Search: With proximity filtering, this dropped to 11s—a 5x improvement.
- Projections: For a degree of 100, a naive search would take nearly 1.5 hours, whereas the optimized search remains manageable.
Critical Analysis & Conclusion
The "Ownership" Gap
The authors identify a fascinating semantic limitation: the FOAF vocabulary lacks a foaf:owns property. Currently, a device "knows" its owner, which is semantically awkward. Future iterations of decentralized IoT need better ontologies to distinguish between social relationships (friends) and legal relationships (ownership).
Limitations
- Privacy: Currently, the AP fetches raw profile data. If friend lists aren't public, the system fails.
- Probe MAC Randomization: Modern mobile OSs (iOS/Android) now randomize MAC addresses in probe requests, which might break the proximity heuristic described in this 2013-era research.
Final Takeaway
EAP-SocTLS demonstrates that decentralized authentication is feasible only when it is context-aware. By grounding digital trust in physical presence, we can create secure, zero-touch network experiences that feel like magic but are rooted in rigorous cryptographic and social graph analysis.
