Together, (S1), (S2) and (S3) guarantee that data resulting
from a private execution cannot be disclosed without access
to the corresponding secret. (S4) ensures that users cannot
be coerced into divulging their personal information, as they
do not know the requisite secret, and hence, cannot provide
it. (S5) implies that once a private execution has ended, it
is computationally infeasible to recover the data produced
during that execution.