Mobile and Ubiquitous Systems: Computing, Networking, and Services. 10th International Conference, MOBIQUITOUS 2013, Tokyo, Japan, December 2-4, 2013, Revised Selected Papers

Research Article

A Layered Secret Sharing Scheme for Automated Profile Sharing in OSN Groups

Download
396 downloads
  • @INPROCEEDINGS{10.1007/978-3-319-11569-6_38,
        author={Guillaume Smith and Roksana Boreli and Mohamed Kaafar},
        title={A Layered Secret Sharing Scheme for Automated Profile Sharing in OSN Groups},
        proceedings={Mobile and Ubiquitous Systems: Computing, Networking, and Services. 10th International Conference, MOBIQUITOUS 2013, Tokyo, Japan, December 2-4, 2013,  Revised Selected Papers},
        proceedings_a={MOBIQUITOUS},
        year={2014},
        month={12},
        keywords={},
        doi={10.1007/978-3-319-11569-6_38}
    }
    
  • Guillaume Smith
    Roksana Boreli
    Mohamed Kaafar
    Year: 2014
    A Layered Secret Sharing Scheme for Automated Profile Sharing in OSN Groups
    MOBIQUITOUS
    Springer
    DOI: 10.1007/978-3-319-11569-6_38
Guillaume Smith,*, Roksana Boreli, Mohamed Kaafar
    *Contact email: guillaume.smith@nicta.com.au

    Abstract

    We propose a novel Layered secret sharing scheme and its application to Online Social Networks (OSNs). In current, commercially offered OSNs, access to users’ profile information is managed by the service provider e.g. Facebook or Google+, based on the user defined privacy settings. A limited set of rules such as those governing the creation of groups of friends as defined by the user (e.g. circles, friend groups or lists) allow the users to define different levels of privacy, however they are arguably complex and rely on a trusted third party (the service provider) to ensure compliance. The proposed scheme enables automated profile sharing in OSN groups with fine grained privacy control, via a multi-secret sharing scheme comprising layered shares, created from user’s profile attributes (multiple secrets), that are distributed to group members; with no reliance on a trusted third party. The scheme can be implemented via e.g. a browser plugin, enabling automation of all operations for OSN users. We study the security of the scheme against attacks aiming to acquire knowledge about user’s profile. We also provide a theoretical analysis of the resulting level of protection for specific (privacy sensitive) attributes of the profile.