SoNeUCON_{ABC}Pro: an access control model for social networks with translucent user provenance

González-Manzano, Lorena; Slaymaker, Mark; de Fuentes, José María and Vayenas, Dimitris (2017). SoNeUCON_{ABC}Pro: an access control model for social networks with translucent user provenance. In: International Workshop on Applications and Techniques in Cyber Security (ATCS), 13th EAI International Conference on Security and Privacy in Communication Networks 2017 (SecureComm)., 22-25 Oct 2017.


Web-Based Social Networks (WBSNs) are used by millions of people worldwide. While WBSNs provide many benefits, privacy preservation is a concern. The management of access control can help to assure data is accessed by authorized users. However, it is critical to provide sufficient flexibility so that a rich set of conditions may be imposed by users. In this paper we coin the term user provenance to refer to tracing users actions to supplement the authorisation decision when users request access. For example restricting access to a particular photograph to those which have “liked” the owners profile. However, such a tracing of actions has the potential to impact the privacy of users requesting access. To mitigate this potential privacy loss the concept of translucency is applied. This paper extends SoNeUCONABC model and presents SoNeUCONABCPro, an access control model which includes translucent user provenance. Entities and access control policies along with their enforcement procedure are formally defined. The evaluation demonstrates that the system satisfies the imposed goals and supports the feasibility of this model in different scenarios.

