Persona: An Online Social Network with User-Defined Privacy

被引:137
作者
Baden, Randy [1 ]
Bender, Adam [1 ]
Spring, Neil [1 ]
Bhattacharjee, Bobby [1 ]
Starin, Daniel
机构
[1] Univ Maryland, College Pk, MD 20742 USA
关键词
Design; Security; Performance; Persona; OSN; Social Networks; ABE; Privacy; Facebook;
D O I
10.1145/1594977.1592585
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Online social networks (OSNs) are immensely popular, with some claiming over 200 million users [10]. Users share private content, such as personal information or photographs, using OSN applications. Users must trust the OSN service to protect personal information even as the OSN provider benefits from examining and sharing that information. We present Persona, an OSN where users dictate who may access their information. Persona hides user data with attribute-based encryption (ABE), allowing users to apply fine-grained policies over who may view their data. Persona provides an effective means of creating applications in which users, not the OSN, define policy over access to private data. We demonstrate new cryptographic mechanisms that enhance the general applicability of ABE. We show how Persona provides the functionality of existing online social networks with additional privacy benefits. We describe an implementation of Persona that replicates Facebook applications and show that Persona provides acceptable performance when browsing privacy-enhanced web pages, even on mobile devices.
引用
收藏
页码:135 / 146
页数:12
相关论文
共 38 条
[1]  
Ahern Shane., 2007, Human Factors in Computing Systems
[2]  
[Anonymous], 2008, WOSN
[3]  
[Anonymous], Advanced crypto software collection
[4]  
[Anonymous], FAC STAT
[5]  
[Anonymous], PET
[6]  
*APPL, APPL IPHONE SDK
[7]  
Bethencourt J., 2007, SECURITY PRIVACY
[8]  
BONATTI PA, 2002, J COMPUTER SECURITY
[9]  
CHASE M, 2007, TCC
[10]  
Clark DavidD., 1988, SIGCOMM