Skip to main navigation Skip to search Skip to main content

Forgery-Resistant Range Queries via Multi-Client Order-Revealing Encryption

Research output: Contribution to journalArticlepeer-review

Abstract

Secure multi-client range-query systems enable multiple parties to search a shared, outsourced database without revealing either the queries or the data. The leading primitives are multi-client order-revealing encryption (m-ORE) and its security-enhanced variant om-ORE, which targets fully malicious clients and server. We show that both schemes remain vulnerable: a colluding malicious client and server can launch a practical ciphertext-forgery attack, silently injecting counterfeit records into the encrypted dataset. To close this gap we propose MORES, the first multi-client ORE scheme that preserves range-query functionality while provably resisting arbitrarily malicious participants. In addition to its stronger integrity guarantees, MORES trims query size and comparison cost by roughly one-third relative to both m-ORE and om-ORE, as confirmed by experiments in various bit lengths of plaintext. These gains make MORES an immediate drop-in replacement for encrypted-database systems that demand both efficiency and robustness in adversarial environments.

Original languageEnglish
JournalIEEE Transactions on Information Forensics and Security
DOIs
StateAccepted/In press - 2026

Keywords

  • Adversarial client
  • Encrypted database
  • Multi-client
  • Order-revealing encryption
  • Range query

Fingerprint

Dive into the research topics of 'Forgery-Resistant Range Queries via Multi-Client Order-Revealing Encryption'. Together they form a unique fingerprint.

Cite this