• DocumentCode
    3100720
  • Title

    Enabling Secure Secret Sharing in Distributed Online Social Networks

  • Author

    Vu, Le-Hung ; Aberer, Karl ; Buchegger, Sonja ; Datta, Anwitaman

  • Author_Institution
    Sch. of Comput. & Commun. Sci., Ecole Polytech. Federate de Lausanne (EPFL), Lausanne, Switzerland
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    419
  • Lastpage
    428
  • Abstract
    We study a new application of threshold-based secret sharing in a distributed online social network (DOSN), where users need a means to back up and recover their private keys in a network of untrusted servers. Using a simple threshold-based secret sharing in such an environment is insufficiently secured since delegates keeping the secret shares may collude to steal the user´s private keys. To mitigate this problem, we propose using different techniques to improve the system security: by selecting only the most reliable delegates for keeping these shares and further by encrypting the shares with passwords. We develop a mechanism to select the most reliable delegates based on an effective trust measure. Specifically, relationships among the secret owner, delegate candidates and their related friends are used to estimate the trustworthiness of a delegate. This trust measure minimizes the likelihood of the secret being stolen by an adversary and is shown to be effective against various collusive attacks. Extensive simulations show that the proposed trust-based delegate selection performs very well in highly vulnerable environments where the adversary controls many nodes with different distributions and even with spreading of infections in the network. In fact, the number of keys lost is very low under extremely pessimistic assumptions of the adversary model.
  • Keywords
    distributed processing; private key cryptography; security of data; social networking (online); collusive attacks; distributed online social networks; system security; threshold-based secret sharing; trust measure; trust-based delegate selection; untrusted servers; user private keys; Application software; Computer crashes; Computer networks; Computer security; Cryptographic protocols; Cryptography; Distributed computing; Laboratories; Network servers; Social network services; distributed online social networks; online social networks; secret sharing; trust;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2009. ACSAC '09. Annual
  • Conference_Location
    Honolulu, HI
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3919-5
  • Type

    conf

  • DOI
    10.1109/ACSAC.2009.46
  • Filename
    5380695