Research

Center for R&D on Secure Computer Systems

Trusted AI Exchange — A Secure Collaboration Infrastructure for People, Data, AI Models, and AI Services

With the spread of generative AI, the training and inference of AI now depend on the collaboration of data, AI models, programs, and computing resources across organizations and regions. At the same time, this expansion introduces risk at every stage — from the distribution of data to the training of AI, to the use of trained AI — including the leakage of confidential data and the unauthorized use or tampering of AI models. The Trusted AI Exchange envisioned by the center for R&D on Secure Computer Systems (CRADSEC) is an infrastructure that verifies the trustworthiness of users and execution environments, and safely distributes and uses data, AI models, and programs under defined conditions. CRADSEC researches and develops, as an integrated whole, the hardware and software that supports this. CRADSEC aims to establish technology that proves, through mathematically and machine-verifiable evidence, safety against anticipated threats.

Trusted Execution Environment for AI — Using AI and Data Safely, Only Within a Trusted Environment

A Trusted Execution Environment (TEE) is a technology that processes data, AI models, and programs within a secure area isolated from the outside world, enabling AI to be used only in a trusted environment. Both the assets that need to be protected and the threats they face vary across environments, ranging from IoT devices and personal computers to on-premises corporate servers and the cloud. The Universal TEE Architecture (UTA) proposed by CRADSEC is a flexible and unified TEE infrastructure applicable to those platforms. It allows the appropriate protected area and protection mechanism to be selected and configured according to the intended use and anticipated threat, while balancing security, performance, and power consumption. This makes it possible to achieve secure data generation and edge AI on IoT devices, personal-data protection on personal computers, countermeasures against internal fraud on in-house corporate servers, and isolation from administrators and other users on the cloud — ensuring the confidentiality and integrity of AI and data at every stage of storage, communication, training, and inference.

The TriniTEE Project — Development of Universal TEE Architecture with Trinity of Hardware, Software, and Theory

The TriniTEE Project is a five-year research and development effort, from FY2025 through FY2029, conducted as part of the Cabinet Office’s K Program (Program for the Development of Critical Technologies for Economic Security) with support from the Japan Science and Technology Agency (JST). The project aims to realize a Universal TEE Architecture capable of configuring the optimal protected area according to the intended use and anticipated threat, from IoT devices to the cloud, through the integrated development of hardware, software, formal verification, attestation, and middleware.

With CRADSEC at its core, the project brings together the National Institute of Informatics, The University of Tokyo, Waseda University, Keio University, Kyushu Institute of Technology, Tokyo University of Agriculture and Technology, INSTITUTE of INFORMATION SECURITY, NEC Corporation, SECOM CO., LTD. , and others. Students and young researchers gather at CRADSEC, cultivating the next generation of research talent through cross-disciplinary joint research. Results, including hardware IP, are published as open source, contributing to research and development communities in Japan and abroad, as well as to social implementation. For more information, please see CRADSEC’s website.

Members

Please refer to CRADSEC’s website.