Friday, October 9, 2026
Science
No Result
View All Result
  • Login
  • HOME
  • SCIENCE NEWS
  • CONTACT US
  • HOME
  • SCIENCE NEWS
  • CONTACT US
No Result
View All Result
Scienmag
No Result
View All Result
Home Science News Technology and Engineering

New Security Framework Guards Shared Encrypted Databases Against Their Own Owners

October 9, 2026
in Technology and Engineering
Denise Maddox
By Denise Maddox Scienmag Editorial Profile - Mechanical Engineering
Reading Time: 5 mins read
0
New Security Framework Guards Shared Encrypted Databases Against Their Own Owners

New Security Framework Guards Shared Encrypted Databases Against Their Own Owners

65
SHARES
587
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT

When rival banks pool their data for fraud detection, they face an uncomfortable paradox: the analytics only work if everyone contributes honestly, yet every participant has an incentive to cheat. A new study published in the journal Cybersecurity tackles this paradox head-on, presenting a security-enhanced query framework that protects collaborative, privacy-preserving databases not only from prying outsiders and untrusted servers, but from the data owners themselves. The work, led by Lili Gu, Jinguo Li, and Jiaqi Shi of Shanghai University of Electric Power, extends an existing privacy-preserving computation system into territory that cryptography alone could not reach.

The starting point is PRISM, a framework for privacy-preserving set computation over outsourced secret-shared databases. In PRISM, multiple data owners split their records into cryptographic shares and distribute them across servers that never see plaintext data. The servers can execute private set intersection and aggregation queries directly over the shares, and the system offers verifiability guarantees against dishonest servers. But PRISM, like most systems in this family, rests on a quiet assumption: that the data owners themselves behave honestly and follow the protocol. In real consortiums of competing organizations, that assumption is often unrealistic.

The researchers catalog the ways a malicious owner can sabotage a query without ever breaking encryption. An owner might distribute inconsistent secret shares so that different servers hold contradictory versions of the same record. It might outsource values that violate declared attribute-level constraints, such as a numeric field exceeding its permitted range, quietly poisoning every aggregate computed downstream. It might issue unauthorized queries that breach the consortium’s access policies. Or it might interfere at the final stage, selectively approving or refusing to confirm aggregation results, or sending conflicting confirmations to different participants. Each of these attacks preserves data confidentiality while corrupting the correctness of the answers everyone relies on.

To close these gaps, the team built a framework that combines verifiable data outsourcing with query-level governance. The first pillar uses verifiable secret sharing, based on Pedersen commitments, to guarantee that every accepted share is consistent with a single committed plaintext value. When a data owner distributes shares of a value, it also publishes commitments derived from the sharing polynomial’s coefficients. Each server can then check locally, through a simple algebraic relation, whether the share it received matches the committed value. A malicious owner cannot hand out mutually inconsistent shares that still pass this check, and the verification requires no interaction between servers.

Consistency alone, however, is not enough. A malicious owner could share a perfectly consistent value that is simply wrong, such as an out-of-range cost figure or a Boolean indicator that is neither zero nor one. The framework therefore layers zero-knowledge proofs on top of the commitments. For Boolean attributes, the owner proves that the committed value satisfies the equation v times (v minus 1) equals zero, which holds only for zero or one, without revealing which. For numeric attributes, the owner supplies a range proof demonstrating that the committed value lies between zero and a public bound. The same commitment anchors both the share-consistency check and the validity proof, so the two guarantees are cryptographically bound to one another. In experiments, these mechanisms detected every injected malicious input, including tampered shares, invalid Boolean values, and out-of-range numbers, with a false-positive rate of zero.

The second pillar, called Adaptive Query Consensus or AQC, governs the query lifecycle itself. Rather than deploying heavyweight Byzantine fault-tolerant protocols that replicate an entire system state, AQC operates strictly per query under an honest-majority assumption, tolerating fewer than one third malicious owners. Before any query reaches the servers, data owners collectively vote on its admissibility against a consortium-wide policy. Only when at least a two-thirds quorum signs the same query descriptor does the coordinator assemble an authorization certificate, and servers refuse to execute anything without one. For aggregation queries, a second certificate confirms the final result: at least Q owners must sign the same result digest before the answer is accepted.

The safety argument is elegant. Because any two valid quorums must overlap in at least one honest owner, and honest owners sign at most one authorization and one result digest per query instance, two conflicting queries or two conflicting results can never both obtain valid certificates. The coordinator, notably, is not trusted at all; it merely collects votes and cannot determine outcomes without sufficient honest signatures. To handle unstable or malicious coordinators, AQC selects them adaptively based on observed behavior, such as vote-collection latency and certificate-assembly success. Certified timeouts or provable equivocation exclude a coordinator for the remainder of that query phase, and the protocol retries with growing timeout windows, guaranteeing eventual progress when the network stabilizes and enough honest owners participate.

The experimental evaluation is striking for its scale and restraint. Using a Python prototype with datasets drawn from the TPC-H benchmark, the team tested workloads of up to 50 data owners and datasets of up to 5 million records. The cryptographic machinery added only moderate cost: query-computation overhead over the PRISM baseline ranged from roughly 5.3 to 7.9 percent and stayed below 8 percent in every tested configuration. Signature processing contributed just 18 milliseconds to the critical path of a two-phase query, and coordinator selection cost less than a millisecond of local computation. Under congested networks and a 30 percent malicious-owner ratio, full two-phase queries completed in under two seconds. Because verification happens during data outsourcing, its cost amortizes across many subsequent queries.

The adaptive coordinator selection proved its worth in adversarial settings. At a 30 percent malicious ratio, adaptive selection cut completion times by roughly 18.6 to 30.5 percent compared with round-robin and random strategies, required about 0.15 to 0.26 retries per query instead of roughly 0.8, and maintained completion rates between 99 and 99.9 percent. A static-leader strategy, by contrast, collapsed to a 70 percent completion rate when its fixed leader turned malicious. The authors are careful about limits: the framework verifies protocol-level integrity, not the real-world truthfulness of syntactically valid data, and its guarantees hold only under the honest-majority assumption, with the 40 percent malicious setting reported purely as a stress test.

The broader significance lies in reframing where trust must be established in collaborative analytics. Cryptographic privacy has long been treated as sufficient protection for multi-party computation, yet the integrity of shared answers depends on participants who may be strategically misaligned, compromised, or simply unreliable. By binding verifiable secret sharing, zero-knowledge validity proofs, and lightweight query-scoped consensus into a single lifecycle-aware workflow, the researchers show that outsourced multi-owner databases can survive their own owners’ misbehavior without the crushing overhead of full Byzantine replication. The team plans to extend the work toward stronger robustness beyond honest majorities, real cloud deployments with heterogeneous latency, and richer query types and policy constraints, pointing toward consortium analytics that are resilient from data submission to confirmed result.

Subject of Research: Verifiable and robust query processing for multi-owner secret-shared databases under malicious data owners

Article Title: Verifiable and robust query processing for multi-owner secret-shared databases under malicious owners

Article References: Gu, L., Li, J., & Shi, J. (2026). Verifiable and robust query processing for multi-owner secret-shared databases under malicious owners. Cybersecurity, 9(1), Article 231. https://doi.org/10.1186/s42400-026-00674-4

Image Credits: AI Generated

DOI: 10.1186/s42400-026-00674-4

Keywords: privacy-preserving computation, secret sharing, verifiable secret sharing, zero-knowledge proofs, private set intersection, outsourced databases, Byzantine consensus, query governance, malicious data owners, data integrity, multi-party computation, cybersecurity

Cite Scienmag News

Denise Maddox. (October 9, 2026). New Security Framework Guards Shared Encrypted Databases Against Their Own Owners. Scienmag. https://scienmag.com/new-security-framework-guards-shared-encrypted-databases-against-their-own-owners/

Denise Maddox. "New Security Framework Guards Shared Encrypted Databases Against Their Own Owners." Scienmag, 9 October 2026, https://scienmag.com/new-security-framework-guards-shared-encrypted-databases-against-their-own-owners/. Accessed 9 October 2026.

Denise Maddox. "New Security Framework Guards Shared Encrypted Databases Against Their Own Owners." Scienmag. October 9, 2026. https://scienmag.com/new-security-framework-guards-shared-encrypted-databases-against-their-own-owners/

Tags: Byzantine consensuscollaborative cybersecurity solutionscollaborative encrypted databasescryptographic data sharingcryptography in shared databasescybersecuritydata integrityencrypted database security protocolsfraud detection in financial institutionsmalicious data ownersmulti-party computationoutsourced databasesprivacy-preserving computationprivacy-preserving query frameworksprivacy-preserving set computationprivate set intersectionquery governancesafeguarding data owners' integritysecret sharingsecure multi-party computationsecurity against malicious insidersverifiable privacy-preserving data analysisverifiable secret sharingzero-knowledge proofs
Share26Tweet16
Previous Post

Gold Nanoparticles Turn a Smartphone Into a Pesticide Detector

Next Post

Diabetes Drug Metformin Surprisingly Blocks Ferroptotic Cell Death in Cancer Cells

Related Posts

Chip-Based Quantum Memory Stores Light for Over a Microsecond
Technology and Engineering

Chip-Based Quantum Memory Stores Light for Over a Microsecond

October 9, 2026
Evolutionary Algorithm Designs and Trains Neural Networks Simultaneously, Beating Classic Methods
Technology and Engineering

Evolutionary Algorithm Designs and Trains Neural Networks Simultaneously, Beating Classic Methods

October 9, 2026
Deep Learning Spots Cell Division in Breast Cancer Slides With Near-Perfect Accuracy
Technology and Engineering

Deep Learning Spots Cell Division in Breast Cancer Slides With Near-Perfect Accuracy

October 9, 2026
Cheap CO2 Sensor Matches Scientific Gold Standard in Field Trial
Athmospheric

Cheap CO2 Sensor Matches Scientific Gold Standard in Field Trial

October 9, 2026
Virtual Time Travel Through Old Hong Kong Boosts Memory and Well-Being in Older Adults
Technology and Engineering

Virtual Time Travel Through Old Hong Kong Boosts Memory and Well-Being in Older Adults

October 9, 2026
Quantum-Inspired Scheduler Cuts Cloud Task Times by Up to 25 Percent
Technology and Engineering

Quantum-Inspired Scheduler Cuts Cloud Task Times by Up to 25 Percent

October 9, 2026
Next Post
Diabetes Drug Metformin Surprisingly Blocks Ferroptotic Cell Death in Cancer Cells

Diabetes Drug Metformin Surprisingly Blocks Ferroptotic Cell Death in Cancer Cells

  • Mothers who receive childcare support from maternal grandparents show more optimized

    Mothers who receive childcare support from maternal grandparents show more parental warmth, finds NTU Singapore study

    27656 shares
    Share 11059 Tweet 6912
  • University of Seville Breaks 120-Year-Old Mystery, Revises a Key Einstein Concept

    1061 shares
    Share 424 Tweet 265
  • Bee body mass, pathogens and local climate influence heat tolerance

    682 shares
    Share 273 Tweet 171
  • Researchers record first-ever images and data of a shark experiencing a boat strike

    546 shares
    Share 218 Tweet 137
  • Groundbreaking Clinical Trial Reveals Lubiprostone Enhances Kidney Function

    531 shares
    Share 212 Tweet 133
Science

Embark on a thrilling journey of discovery with Scienmag.com—your ultimate source for cutting-edge breakthroughs. Immerse yourself in a world where curiosity knows no limits and tomorrow’s possibilities become today’s reality!

RECENT NEWS

  • Diabetes Drug Metformin Surprisingly Blocks Ferroptotic Cell Death in Cancer Cells
  • New Security Framework Guards Shared Encrypted Databases Against Their Own Owners
  • Gold Nanoparticles Turn a Smartphone Into a Pesticide Detector
  • Hospital Isolation for Bone Infections Rests on Tradition, Not Evidence, Study Finds

Categories

  • Agriculture
  • Anthropology
  • Archaeology
  • Athmospheric
  • Biology
  • Biotechnology
  • Blog
  • Bussines
  • Cancer
  • Chemistry
  • Climate
  • Earth Science
  • Editorial Policy
  • Marine
  • Mathematics
  • Medicine
  • Pediatry
  • Policy
  • Psychology & Psychiatry
  • Science Education
  • Science News
  • Social Science
  • Space
  • Technology and Engineering

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 5,150 other subscribers

© 2025 Scienmag - Science Magazine

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • SCIENCE NEWS
  • CONTACT US

© 2025 Scienmag - Science Magazine

Discover more from Science

Subscribe now to keep reading and get access to the full archive.

Continue reading