01 / The mechanism and its boundary
What the technique establishes
RAND's secure inference data center (SIDC) is a design for a compact, purpose-built facility that serves already-trained AI models, for example to national-security users. It aims to keep model weights, inference algorithms, prompts and responses confidential and intact against a well-resourced, state-backed attacker. The facility is split into physically isolated realms linked only by one-way data diodes in a fixed layout, with formally verified protocols at every boundary, human screening of each prompt and response, and checks of loaded weights against reference measurements. RAND estimates $37–50 million for a proof-of-concept and $277–345 million for an enterprise-scale facility, built in as few as 14 months under emergency or national-priority conditions. It is a published design, and RAND recommends prototyping its key security features now. It describes no way for an outside party to check the facility's properties, and its guarantees rest on an uncompromised setup phase.
- Threat model
- Semi-trusted prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- Retrofit device
- Prover cooperation
- Required
- Confidentiality
- Partial
- Category
- Isolation & architecture
Technical detail and cited results
- Assurance chain. The report sets out a step-by-step assurance chain for the cross-realm solution that mediates every boundary crossing S-1510. A hazard analysis (STPA-Sec) justifies the component, and the requirements are allocated in a system model. A finite-state protocol specification fixes authorized behaviour, sequencing, timing and fail-secure transitions. Cryptographic protocol analysis with Tamarin and CryptoVerif would cover end-point authentication, secrecy, replay resistance and key freshness under stated assumptions. The authors report modelling the channel's control logic in TLA+ and machine-checking its safety properties, and say they have begun mapping the design to formal verification artifacts. The report does not publish the analyses. The specified behaviour can then be translated into synthesizable hardware logic, such as FPGA-based channel control, and circuit-level assertions can check selected temporal properties at the register-transfer level S-1510.
- Hardware assumptions. Cost estimates assume 150 GPUs at about 250 kW for the proof-of-concept and 375 GPUs at about 3 MW at enterprise scale; the design is agnostic to the accelerator type S-1510.
- Staffing. About 100 cleared staff for a proof-of-concept and 300 for a deployment-scale facility S-1510.
- Schedule. The 14-month estimate assumes emergency or national-priority conditions and a government-owned facility built inside an existing hangar or warehouse. Otherwise RAND expects two to two and a half years to deploy, plus about a year for accreditation S-1510.
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
Model weights have not left the facility
A security architecture for keeping weights and inference data inside the facility; the report does not describe how an external party would verify this (S-1510).
The declared model is the one being served
The compute sanctum checks resident weights against reference measurements before serving.
Communication between compute groups is bounded
Physically isolated realms communicate only through one-way data diodes in a fixed topology (S-1510); no external check of that boundary is described.
Readiness for a stated use
Assessed use: the operator's own weight security, with no outside verification described
low confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
The design is detailed and costed but has no prototype. Its stated objectives are security properties for the operator, not claims an outside party could check.
- R1 met for the security design: the report states its protection objectives and the further claim that each inference response is verifiable given valid weights, architecture and retrieved context. It also states its threat model and assumptions, such as a trusted setup and likely supply-chain compromise of commodity hardware S-1510.
- R2 not met: no facility or prototype has been published, and RAND recommends prototyping key security features now S-1510.
Confidence is low because the stated verification use is only partly addressed. The report describes internal integrity checks and audit logging, but no way for a party outside the operator to verify the facility's properties, and it omits architectural blueprints and detailed implementations from the public version S-1510.
Evidence needed for the next level
A public working prototype, or reproducible published results, for key features such as the diode-gated realm topology and cross-realm protocols.
A published way for a party other than the operator to verify the facility's claims, for example weight confidentiality or which model is served.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / theoretical argument
Everything rests on the trusted setup
Reference measurements for model weights and reference data are established in a trusted setup phase. The report states that the system cannot detect compromise that happened before ingestion if the trusted setup itself is compromised.
minor / open / theoretical argument
Security weakens over long operation
The authors claim that the facility can withstand attacks at the OC5 level for a five-year operational period. They expect its ability to withstand long OC5 campaigns to become less robust the longer the facility remains in operation.
What still blocks use or stronger assurance
- S-1510
No prototype exists; RAND recommends prototyping key security features and integration now.
- S-1510
The report describes internal integrity checks, audit logging and accreditation, but no way for a party outside the operator to verify the facility's properties.
- S-1510
Human review of every prompt and response makes each request take three to five minutes, with the review steps as the rate-limiting factor.
- S-1510
Detailed design information is withheld from the public report and is to be evaluated privately with stakeholders, which limits independent public scrutiny.
Connections in the research map
Depends on
- Model identity attestation
Integrity checks compare loaded weights with reference measurements from a trusted setup.
Mechanisms implemented
Concepts used
Organizations and developers
Sources and provenance
- S-1510 / Tier B
Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering ↗
S. F. Comer, H. Pavela, V. Gandhi, K. Siler-Evans, E. Devendorf, B. Kelley, J. Gimbi, J. Aguirre, G. Kulp, M. Stalczynski, M. J. Malone · 2026 · RAND Corporation (Research Report RR-A4827-1)
Supports: title, authors and date; objectives; OC5 threat model; realm architecture; request lifecycle; hazards and energy monitoring; trusted setup; formal-methods chain; costs, schedule and staffing; limitations; recommendations
Locator: Summary (p. v); ch. 1 (pp. 1-3); ch. 3 (pp. 9-15); ch. 4 (pp. 18-22); ch. 5 (p. 24); Appendix B (pp. 27-30), GPU counts from Table B.1; Appendix C (pp. 34-35) for TLA+
Version and catalogue details - S-1706 / Tier B
Intelligence Security Laboratories: Building secure infrastructure for transformative AI ↗
· 2026 · Intelligence Security Laboratories
Supports: Intelligence Security Laboratories' stated aim, its use of STPA-Sec, and its reference to this report
Version and catalogue details - S-1707 / Tier B
Our Team: Intelligence Security Laboratories ↗
· 2026 · Intelligence Security Laboratories
Supports: ISL's executive director, Gabriel Kulp, a co-author of the report
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review