arXiv:2609.21728v1 Announce Type: cross Abstract: We present an architecture that enables data owners to combine private data into data pools using Trusted Execution Environments (TEEs) and manage these pools by issuing narrowly scoped computational rights, encoded as Digital Rights Tokens (DRTs), to third-party data analysts. Each DRT binds specific open-source code to a pool and is issued and r
Verifiable Computation with Trusted Execution Environments and On-Chain Digital Rights Tokens (arXiv:2609.21728v1) proposes a control-centric privacy architecture where data owners pool private data in Trusted Execution Environments (TEEs) and issue Digital Rights Tokens (DRTs) on a distributed ledger to authorize specific computations.
The paper proposes a privacy-preserving architecture for controlled data analytics in which data owners can pool private datasets inside Trusted Execution Environments (TEEs) while granting third-party analysts only limited, verifiable rights to compute over that data. Rather than exposing raw data or relying on a fully trusted intermediary, the system uses TEEs to create isolated execution contexts in which approved analytical code can operate on pooled data. The key design goal is to make data sharing both private and auditable: analysts gain enough access to perform useful computations, but owners retain control over what code may run, on which data pool, and under what constraints.
A central contribution is the use of on-chain Digital Rights Tokens (DRTs) as the mechanism for expressing and enforcing those computational rights. Each DRT is described as narrowly scoped and bound to a specific data pool and a specific open-source code artifact, suggesting a model in which access is not a blanket permission to query data, but a programmable license to execute a particular, inspectable computation. The on-chain component provides a durable, verifiable record of issuance, scope, and likely revocation, enabling external parties to check whether a computation was authorized. Combined with TEE attestation, the architecture aims to ensure that only authorized, known code runs inside the enclave and that the resulting computation can be tied back to a valid rights token.
The work matters because it addresses a persistent tension in data-intensive systems: how to allow useful third-party analytics without surrendering raw data or placing excessive trust in the analyst. By coupling hardware-backed confidentiality with fine-grained, on-chain rights management, the paper points toward a more composable model for data marketplaces, regulated data sharing, and privacy-sensitive analytics. It is particularly relevant for domains where data owners need provable compliance, such as finance, health, or enterprise data collaboration, because it shifts trust from “the analyst will not misuse the data” to a combination of measured execution, code transparency, and verifiable authorization.