IP Library Patent Application 19132456
Patent Application
App. No. 19/132,456

PROGRAM EXECUTION SYSTEM, PROGRAM EXECUTION METHOD, AND PROGRAM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/132,456
Abstract

A program execution system includes a data holding apparatus configured to transmit a second ciphertext obtained by encrypting a common key with a public key, to a data processing apparatus, and includes the data processing apparatus configured to acquire the common key that is obtained by decrypting the second ciphertext with a secret key, and acquire data by decrypting a first ciphertext with the common key in an isolated region. In the isolated region, the data processing apparatus is configured to calculate a result of processing the data by a program that is held in the isolated region.

Claims (65)

1 . A program execution system comprising:

a data holding apparatus including first circuitry configured to transmit a first ciphertext obtained by encrypting data with a common key, to a data processing apparatus; and

the data processing apparatus that includes second circuitry configured to transmit, to the data holding apparatus, both:

a public key corresponding to a secret key that is held in an isolated region, and

a hash value that is obtained by applying a hash function to the public key and to which a signature is added by a hardware secret key included in hardware that implements the isolated region, wherein

the first circuitry of the data holding apparatus is configured to transmit a second ciphertext obtained by encrypting the common key with the public key, to the data processing apparatus,

the second circuitry of the data processing apparatus is configured to:

acquire the common key that is obtained by decrypting the second ciphertext with the secret key, and

acquire the data by decrypting the first ciphertext with the common key in the isolated region, and

in the isolated region, the second circuitry of the data processing apparatus is configured to calculate a result of processing the data by a program that is held in the isolated region.

2 . The program execution system according to claim 1 , further comprising an execution result acquisition apparatus including third circuitry, wherein

the second circuitry of the data processing apparatus is configured to transmit, to the execution result acquisition apparatus, both:

the public key, and

the hash value obtained by applying the hash function to the public key and to which the signature is added by the hardware secret key,

the third circuitry of the execution result acquisition apparatus is configured to transmit a third ciphertext obtained by encrypting a second common key with the public key, to the data processing apparatus, and

the second circuitry of the data processing apparatus is configured to:

acquire the second common key by decrypting the third ciphertext with the secret key in the isolated region, and

transmit a fourth ciphertext obtained by encrypting the result with the second common key, to the execution result acquisition apparatus.

3 . The program execution system according to claim 2 , wherein the first circuitry of the data holding apparatus is configured to transmit a random number to the data processing apparatus,

the second circuitry of the data processing apparatus is configured to:

transmit, to the data holding apparatus, the random number to which a second signature is added by the secret key, and

transmit, to the data holding apparatus, both:

a second hash value representing a hash value of a character string obtained by combining either the random number or the second signature and a hash value of information representing a state of the isolated region, and

a third signature for the second hash value by the hardware secret key,

the first circuitry of the data holding apparatus is configured to:

verify the second signature with the public key, and

verify whether the hash value of the character string, obtained by combining either the random number or the second signature and a hash value of a character string that is obtained by combining information representing an initial state of the isolated region and a hash value of the program, matches the second hash value,

the third circuitry of the execution result acquisition apparatus is configured to transmit a second random number to the data processing apparatus,

the second circuitry of the data processing apparatus is configured to:

transmit the second random number to which a third signature is added by the secret key, to the execution result acquisition apparatus, and

transmit, to the execution result acquisition apparatus, both:

a third hash value representing a hash value of a character string obtained by combining either the second random number or the third signature and the hash value of the information representing the state of the isolated region, and

a fourth signature added to the third hash value by the hardware secret key, and

the third circuitry of the execution result acquisition apparatus is configured to:

verify the third signature with the public key, and

verify whether the hash value of the character string, obtained by combining either the second random number or the third signature and the hash value of the character string that is obtained by combining the information representing the initial state of the isolated region, the hash value of the program, and a hash value of the data, matches the third hash value.

4 . The program execution system according to claim 1 , wherein

when a policy of the isolated region includes

a hash value that is obtained by applying the hash function to the program, and

a hash value that is obtained by applying the hash function to the data,

the second circuitry of the data processing apparatus is configured to transmit, to the data holding apparatus, at least one of:

a hash value of a character string obtained by combing a hash value of the public key and a hash value of the policy through the hash function, wherein the signature is added to the hash value of the character string by the hardware secret key, or

a hash value that is obtained by applying the hash function to the policy, and to which a signature is added by the secret key,

the first circuitry of the data holding apparatus is configured to verify at least one of the hash value of the character string, or the hash value obtained by applying the hash function to the policy, and

the second circuitry of the data processing apparatus is configured to:

acquire the program by decrypting a third ciphertext with a second common key,

after acquiring the program, verify whether a hash value of the acquired program matches the hash value obtained by applying the hash function to the program, and

acquire the data by decrypting the second ciphertext with the common key, and

after acquiring the data, verify whether a hash value of the acquired data matches the hash value obtained by applying the hash function to the data.

5 . The program execution system according to claim 1 , further comprising a program providing apparatus including third circuitry configured to:

transmit a third ciphertext obtained by encrypting the program with a second common key, to the data processing apparatus, and

transmit a fourth ciphertext obtained by encrypting the second common key with the public key, to the data processing apparatus, wherein

the second circuitry of the data processing apparatus is configured to:

acquire the second common key that is obtained by decrypting the fourth ciphertext with the secret key, and

acquire the program by decrypting the third ciphertext with the second common key in the isolated region.

6 . A program execution method executed by a program execution system including a data holding apparatus and a data processing apparatus, comprising:

transmitting, by the data holding apparatus, a first ciphertext obtained by encrypting data with a common key, to the data processing apparatus;

transmitting, by the data processing apparatus, to the data holding apparatus, both:

a public key corresponding to a secret key that is held in an isolated region, and

a hash value that is obtained by applying a hash function to the public key and to which a signature is added by a hardware secret key included in hardware that implements the isolated region;

transmitting, by the data holding apparatus, to the data processing apparatus, a second ciphertext obtained by encrypting the common key with the public key;

acquiring, by the data processing apparatus, the common key that is obtained by decrypting the second ciphertext with the secret key;

acquiring, by the data processing apparatus, the data by decrypting the first ciphertext with the common key in the isolated region; and

calculating, by the data processing apparatus, a result of processing the data by a program that is held in the isolated region.

7 . A non-transitory computer readable storage medium storing a program configured to cause a computer to execute the program execution method of claim 6 .

Assignments (2)
CHANGE OF NAME Recorded Aug 15, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072473/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2025
From: OKUDA, TETSUYA; IZUMI, MASAMI; UMAKOSHI, KENJI; KASHIWAGI, KEIICHIRO; MITANI, KOKI; INOUE, TOMOHIRO; YOKOZEKI, DAIGORO; OSHIMA, YOSHIHITO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 071206/0812 →