IP Library Granted Patent US 12,621,146
Granted Patent B2
US 12,621,146 · App. 18/834,381 · Granted May 5, 2026

Program execution system, data processing apparatus, program execution method, and program

Inventors: Tetsuya Okuda (Tokyo, JP); Kenji Umakoshi (Tokyo, JP)
Assignee: NTT, Inc.
H04L9/14H04L9/088H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,146
App. No.
18/834,381
Granted
May 5, 2026
Kind
B2
Abstract

A program execution system includes a data processing apparatus that performs secret calculation in a secure area. The data processing apparatus includes circuitry configured to calculate a result that is obtained by executing a program on data in the secure area, the program being obtained by decrypting a re-encrypted program with a first secret key, and the data being obtained by decrypting re-encrypted data with a second secret key.

Claims (43)

1 . A program execution system comprising:

a data holding device including first circuitry;

a program providing device including second circuitry; and

a data processing apparatus including third circuitry configured to perform secret calculation in a secure area, wherein:

the second circuitry of the program providing device is configured to transmit, to the data processing apparatus, an encrypted program that is obtained by encrypting a program with a first public key, the first public key corresponding to a first role,

the first circuitry of the data holding device is configured to transmit, to the data processing apparatus, encrypted data that is obtained by encrypting data with a second public key, the second public key corresponding to a second role,

the third circuitry of the data processing apparatus is configured to confirm whether the program providing device belongs to the first role, and generate a re-encrypted program that is obtained by re-encrypting the encrypted program with a third public key for the program providing device, upon determining that the program providing device belongs to the first role,

the second circuitry of the program providing device is configured to transmit, to the data processing apparatus, a first secret key encrypted with a first shared key, the first shared key being shared with the data processing apparatus,

the third circuitry of the data processing apparatus is configured to confirm whether the data holding device belongs to the second role, and generate re-encrypted data that is obtained by re-encrypting the encrypted data with a fourth public key for the data holding device, upon determining that the data holding device belongs to the second role,

the first circuitry of the data holding device is configured to transmit, to the data processing apparatus, a second secret key encrypted with a second shared key, the second shared key being shared with the data processing apparatus, and

the third circuitry of the data processing apparatus is configured to calculate a result that is obtained by executing the program on the data in the secure area, the program being obtained by decrypting the re-encrypted program with the first secret key, and the data being obtained by decrypting the re-encrypted data with the second secret key.

2 . The program execution system according to claim 1 , wherein the third circuitry of the data processing apparatus is configured to

set, as the secure area, a first encrypted container whose owner is a user of the program providing device, and

calculate the result obtained by executing the program on the data in a set secure area.

3 . The program execution system according to claim 1 , wherein the third circuitry of the data processing apparatus is configured to

set, as the secure area, a second encrypted container whose owner is a first user having a trusted relationship with a second user of the program providing device and a third user of the data holding device, and

calculate the result obtained by executing the program on the data in a set secure area.

4 . The program execution system according to claim 3 , wherein the third circuitry of the data processing apparatus is configured to

transmit, to the program providing device and the data holding device, information indicating that a proposal of a policy for controlling access to the second encrypted container is received, and

control, upon occurrence of a condition in which a permission for the policy is sent from each of the program providing device and the data holding device, the access to the second encrypted container according to the policy.

5 . The program execution system according to claim 1 , wherein the third circuitry of the data processing apparatus is configured to

confirm whether the program providing device belongs to the first role, on an encrypted container corresponding to the first role,

generate the re-encrypted program obtained by re-encrypting the encrypted program with the first public key for the program providing device, upon determining that the program providing device belongs to the first role,

confirm whether the data holding device belongs to the second role, on an encrypted container corresponding to the second role, and

generate the re-encrypted data obtained by re-encrypting the encrypted data with the second public key for the data holding device, upon determining that the data holding device belongs to the second role.

6 . A data processing apparatus in a program execution system including a data holding device, a program providing device, and the data processing apparatus configured to perform secret calculation in a secure area, the data processing apparatus comprising:

circuitry configured to perform

receiving, from the program providing device, an encrypted program obtained by encrypting a program with a first public key, the first public key corresponding to a first role;

receiving, from the data holding device, encrypted data obtained by encrypting data with a second public key, the second public key corresponding to a second role;

confirming whether the program providing device belongs to the first role, and generating a re-encrypted program obtained by re-encrypting the encrypted program with a third public key for the program providing device, upon determining that the program providing device belongs to the first role;

receiving, from the program providing device, a first secret key encrypted with a first shared key, the first shared key being shared with the data processing apparatus;

confirming whether the data holding device belongs to the second role, and generating re-encrypted data obtained by re-encrypting the encrypted data with a fourth public key for the data holding device, upon determining that the data holding device belongs to the second role;

receiving, from the data holding device, a second secret key encrypted with a second shared key, the second shared key being shared with the data processing apparatus; and

calculating a result that is obtained by of executing the program on the data in the secure area, the program being obtained by decrypting the re-encrypted program with the first secret key, and the data being obtained by decrypting the re-encrypted data with the second secret key.

7 . A program execution method in a program execution system including a data holding device, a program providing device, and a data processing apparatus that performs secret calculation in a secure area, the program execution method comprising:

transmitting, by the program providing device, an encrypted program obtained by encrypting a program with a first public key, the first public key corresponding to a first role, and the encrypted program being transmitted to the data processing apparatus;

transmitting, by the data holding device, encrypted data that is obtained by encrypting data with a second public key, the second public key corresponding to a second role, and the encrypted data being transmitted to the data processing apparatus;

confirming, by the data processing apparatus, whether the program providing device belongs to the first role, and generating a re-encrypted program obtained by re-encrypting the encrypted program with a third public key for the program providing device, upon determining that the program providing device belongs to the first role;

transmitting, by the program providing device, a first secret key encrypted with a first shared key, the first shared key being shared with the data processing apparatus, and the first secret key being transmitted to the data processing apparatus;

confirming, by the data processing apparatus, whether the data holding device belongs to the second role, and generating re-encrypted data that is obtained by re-encrypting the encrypted data with a fourth public key for the data holding device, upon determining that the data holding device belongs to the second role;

transmitting, by the data holding device, a second secret key encrypted with a second shared key, the second shared key being shared with the data processing apparatus, and the second secret key being transmitted to the data processing apparatus; and

calculating, by the data processing apparatus, a result that is obtained by executing the program on the data in the secure area, the program being obtained by decrypting the re-encrypted program with the first secret key, and the data being obtained by decrypting the re-encrypted data with the second secret key.

8 . A non-transitory computer readable storage medium storing a program for causing a computer to execute the program execution method of claim 7 .

Assignments (2)
CHANGE OF NAME Recorded Aug 15, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072490/0664 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2024
From: OKUDA, TETSUYA; UMAKOSHI, KENJI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 068125/0098 →
Continuity (1)
Related Publication 20250132912A1 · Apr 24, 2025
References Cited (7)
US 12067119B1 · Brandwine · 2024 [cited by examiner]
US 20210328787A1 · Grieder · 2021 [cited by examiner]
EP 4064090A1 · 2022 [cited by examiner]
EP 4145762A1 · 2023 [cited by examiner]
GB 2610861A · 2023 [cited by examiner]
Microsoft Azure Confidential Computing, official website, “What is confidential computing?”, https://docs.microsoft.com/ja-jp/azure/confidential-computing/overview, May 22, 2024. [cited by applicant]
Google Confidential VM, official website, https://cloud.google.com/compute/confidential-vm/docs?hl=ja, viewed Mar. 2, 2022. [cited by applicant]