Social Network Privacy via Evolving Access Control

  • Authors:
  • Giovanni Crescenzo;Richard J. Lipton

  • Affiliations:
  • Telcordia Technologies, Piscataway, USA;Georgia Tech, Atlanta, USA

  • Venue:
  • WASA '09 Proceedings of the 4th International Conference on Wireless Algorithms, Systems, and Applications
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

We study the problem of limiting privacy loss due to data shared in a social network, where the basic underlying assumptions are that users are interested in sharing data and cannot be assumed to constantly follow appropriate privacy policies. Note that if these two assumptions do not hold, social network privacy is theoretically very easy to achieve; for instance, via some form of access control and confidentiality transformation on the data. In this paper we observe that users-regulated access control has shown to be unsuccessful for practical social network, and propose that social networks deploy an additional layer of server-assisted access control which, even under no action from a user, automatically evolves over time, by restricting access to the user's data. The evolving access control mechanism provides non-trivial quantifiable guarantees for formally specified requirements of utility (i.e., users share as much data as possible to all other users) and privacy (i.e., users expose combinations of sensitive data only with low probability and over a long time). To the best of our knowledge, this is the first research solution attempting to simultaneously maximizes utility and safeguards privacy of users sharing data in social networking websites.