IP Library Granted Patent US 12,407,496
Granted Patent B2
US 12,407,496 · App. 18/249,659 · Granted Sep 2, 2025

Program execution system, data processing apparatus, program execution method and program

Inventors: Tetsuya Okuda (Tokyo, JP); Koji Chida (Tokyo, JP); Yuichiro Dan (Tokyo, JP); Ryohei Suzuki (Tokyo, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L9/0825G06F21/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,496
App. No.
18/249,659
Granted
Sep 2, 2025
Kind
B2
Abstract

A program execution system includes a data holding apparatus, a program providing apparatus, and a data processing apparatus that performs computing in a secure region. The data holding apparatus transmits encrypted data, encrypted with a first common key, to the data processing apparatus, and the program providing apparatus transmits an encrypted program, encrypted with a second common key, to the data processing apparatus. In the secure region, the data processing apparatus acquires data by decrypting the encrypted data with the first common key, acquires a program by decrypting the encrypted program with the second common key, executes the program for the data, and encrypts a result of the execution with a public key of the data holding apparatus or the first common key. The data holding apparatus acquires the result of the execution by decrypting the encrypted result of the execution with a secret key or the first common key.

Claims (24)

1. A program execution system comprising:

a data holding apparatus; a program providing apparatus; and a data processing apparatus having a mechanism that performs secret computing in a secure region,

wherein

the data holding apparatus transmits encrypted data to the data processing apparatus, and the program providing apparatus transmits an encrypted program to the data processing apparatus, the encrypted data being encrypted with a first common key, the encrypted program being encrypted with a second common key,

in the secure region, the data processing apparatus acquires data by decrypting the encrypted data transmitted by the data holding apparatus with the first common key, acquires a program by decrypting the encrypted program transmitted by the program providing apparatus with the second common key, executes the program acquired by decrypting the encrypted program transmitted by the program providing apparatus for the data acquired by decrypting the encrypted data transmitted by the data holding apparatus, and encrypts a result of the execution with a public key of the data holding apparatus or the first common key,

the data processing apparatus transmits the encrypted result of the execution to the data holding apparatus, and

the data holding apparatus acquires the result of the execution by decrypting the encrypted result of the execution with a secret key or the first common key.

2. The program execution system according to claim 1 , wherein

the data processing apparatus executes an application including an interpreter, to activate the secure region including the encrypted program, and cause the interpreter to interpret the decrypted program.

3. The program execution system according to claim 1 , wherein

the data processing apparatus discards the data and the result of the execution after executing the program in the secure region.

4. A data processing apparatus in a program execution system that includes a data holding apparatus, a program providing apparatus, and the data processing apparatus having a mechanism that performs secret computing in a secure region,

the data processing apparatus comprising:

a memory; and

a processor coupled to the memory and configured to

receive encrypted data encrypted with a first common key from the data holding apparatus, and receive an encrypted program encrypted with a second common key from the program providing apparatus;

acquire data by decrypting the encrypted data transmitted by the data holding apparatus with the first common key, acquire a program by decrypting the encrypted program transmitted by the program providing apparatus with the second common key, execute the program acquired by decrypting the encrypted program transmitted by the program providing apparatus for the data acquired by decrypting the encrypted data transmitted by the data holding apparatus, and encrypt a result of the execution with a public key of the data holding apparatus or the first common key in the secure region; and

transmit the encrypted result of the execution to the data holding apparatus.

5. A non-transitory computer-readable storage medium storing a program for causing a computer to function as the data processing apparatus according to claim 4 .

6. A program execution method in a program execution system that includes a data holding apparatus, a program providing apparatus, and a data processing apparatus having a mechanism that performs secret computing in a secure region, the program execution method comprising:

causing the data holding apparatus to transmit encrypted data to the data processing apparatus and the program providing apparatus to transmit an encrypted program to the data processing apparatus, the encrypted data being encrypted with a first common key, the encrypted program being encrypted with a second common key,

causing, in the secure region, the data processing apparatus to acquire data by decrypting the encrypted data transmitted by the data holding apparatus with the first common key, acquire a program by decrypting the encrypted program acquired by decrypting the encrypted program transmitted by the program providing apparatus with the second common key, execute the program transmitted by the program providing apparatus for the data acquired by decrypting the encrypted data transmitted by the data holding apparatus, and encrypt a result of the execution with a public key of the data holding apparatus or the first common key,

causing the data processing apparatus to transmit the encrypted result of the execution to the data holding apparatus, and

causing the data holding apparatus to acquire the result of the execution by decrypting the encrypted result of the execution with a secret key or the first common key.

Assignments (2)
CHANGE OF NAME Recorded Aug 15, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072490/0664 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2023
From: OKUDA, TETSUYA; CHIDA, KOJI; DAN, YUICHIRO; SUZUKI, RYOHEI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 063379/0775 →
Continuity (1)
Related Publication 20230396415A1 · Dec 7, 2023
References Cited (21)
US 6986044B1 · Inada · 2006 [cited by examiner]
US 10956585B2 · Ortiz · 2021 [cited by examiner]
US 11626976B2 · Imabayashi · 2023 [cited by examiner]
US 20030126458A1 · Teramoto · 2003 [cited by examiner]
US 20080046763A1 · Teramoto · 2008 [cited by examiner]
US 20080084998A1 · Kontani · 2008 [cited by examiner]
US 20090016537A1 · Ju · 2009 [cited by examiner]
US 20090225988A1 · Yamazaki · 2009 [cited by examiner]
US 20100195830A1 · Kubotera · 2010 [cited by examiner]
US 20130151846A1 · Baumann · 2013 [cited by examiner]
US 20160218864A1 · Mutou · 2016 [cited by examiner]
US 20190362083A1 · Ortiz · 2019 [cited by examiner]
US 20200125772A1 · Volos · 2020 [cited by examiner]
US 20220092207A1 · Ozaki · 2022 [cited by examiner]
US 20220303249A1 · Imabayashi · 2022 [cited by examiner]
US 20220385455A1 · Imabayashi · 2022 [cited by examiner]
JP 2001353678A · 2001 [cited by examiner]
WO 2019227208 · 2019 [cited by applicant]
Microsoft Azure Confidential Computing Official Web Page https://docs.microsoft.com/ja-jp/azure/confidential-computing/overview, Aug. 23, 2022. [cited by applicant]
Google Confidential VM Official Web Page https://cloud.google.com/compute/confidential-vm/docs?hl=ja, Jul. 2022. [cited by applicant]
Andreas Fischer et al., “Computation on Encrypted Data using Data Flow Authentication”, Arxiv. Org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Oct. 1, 2017 (Oct. 1, 2017), XP080825… [cited by applicant]