I-0010 / Isolation & architecture

RAND secure inference data center (SIDC) design

A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.

R1 ProposedSource reviewed 2026-09-25Provider-reported evidence

01 / The mechanism and its boundary

What the technique establishes

RAND's secure inference data center (SIDC) is a design for a compact, purpose-built facility that serves already-trained AI models, for example to national-security users. It aims to keep model weights, inference algorithms, prompts and responses confidential and intact against a well-resourced, state-backed attacker. The facility is split into physically isolated realms linked only by one-way data diodes in a fixed layout, with formally verified protocols at every boundary, human screening of each prompt and response, and checks of loaded weights against reference measurements. RAND estimates $37–50 million for a proof-of-concept and $277–345 million for an enterprise-scale facility, built in as few as 14 months under emergency or national-priority conditions. It is a published design, and RAND recommends prototyping its key security features now. It describes no way for an outside party to check the facility's properties, and its guarantees rest on an uncompromised setup phase.

Threat model
Semi-trusted prover
Adversarial evaluation
Published analysis
Hardware needed
Retrofit device
Prover cooperation
Required
Confidentiality
Partial
Category
Isolation & architecture
Technical detail and cited results
  • Assurance chain. The report sets out a step-by-step assurance chain for the cross-realm solution that mediates every boundary crossing S-1510. A hazard analysis (STPA-Sec) justifies the component, and the requirements are allocated in a system model. A finite-state protocol specification fixes authorized behaviour, sequencing, timing and fail-secure transitions. Cryptographic protocol analysis with Tamarin and CryptoVerif would cover end-point authentication, secrecy, replay resistance and key freshness under stated assumptions. The authors report modelling the channel's control logic in TLA+ and machine-checking its safety properties, and say they have begun mapping the design to formal verification artifacts. The report does not publish the analyses. The specified behaviour can then be translated into synthesizable hardware logic, such as FPGA-based channel control, and circuit-level assertions can check selected temporal properties at the register-transfer level S-1510.
  • Hardware assumptions. Cost estimates assume 150 GPUs at about 250 kW for the proof-of-concept and 375 GPUs at about 3 MW at enterprise scale; the design is agnostic to the accelerator type S-1510.
  • Staffing. About 100 cleared staff for a proof-of-concept and 300 for a deployment-scale facility S-1510.
  • Schedule. The 14-month estimate assumes emergency or national-priority conditions and a government-owned facility built inside an existing hangar or warehouse. Otherwise RAND expects two to two and a half years to deploy, plus about a year for accreditation S-1510.

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R1 Proposed

Assessed use: the operator's own weight security, with no outside verification described

low confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

The design is detailed and costed but has no prototype. Its stated objectives are security properties for the operator, not claims an outside party could check.

  • R1 met for the security design: the report states its protection objectives and the further claim that each inference response is verifiable given valid weights, architecture and retrieved context. It also states its threat model and assumptions, such as a trusted setup and likely supply-chain compromise of commodity hardware S-1510.
  • R2 not met: no facility or prototype has been published, and RAND recommends prototyping key security features now S-1510.

Confidence is low because the stated verification use is only partly addressed. The report describes internal integrity checks and audit logging, but no way for a party outside the operator to verify the facility's properties, and it omits architectural blueprints and detailed implementations from the public version S-1510.

Evidence needed for the next level

  • A public working prototype, or reproducible published results, for key features such as the diode-gated realm topology and cross-realm protocols.

  • A published way for a party other than the operator to verify the facility's claims, for example weight confidentiality or which model is served.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / theoretical argument

Everything rests on the trusted setup

Reference measurements for model weights and reference data are established in a trusted setup phase. The report states that the system cannot detect compromise that happened before ingestion if the trusted setup itself is compromised.

S-1510

minor / open / theoretical argument

Security weakens over long operation

The authors claim that the facility can withstand attacks at the OC5 level for a five-year operational period. They expect its ability to withstand long OC5 campaigns to become less robust the longer the facility remains in operation.

S-1510

What still blocks use or stronger assurance

  1. No prototype exists; RAND recommends prototyping key security features and integration now.

    S-1510
  2. The report describes internal integrity checks, audit logging and accreditation, but no way for a party outside the operator to verify the facility's properties.

    S-1510
  3. Human review of every prompt and response makes each request take three to five minutes, with the review steps as the rate-limiting factor.

    S-1510
  4. Detailed design information is withheld from the public report and is to be evaluated privately with stakeholders, which limits independent public scrutiny.

    S-1510

Connections in the research map

Depends on

Mechanisms implemented

Concepts used

Organizations and developers

Sources and provenance

  1. S-1510 / Tier B

    Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering ↗

    S. F. Comer, H. Pavela, V. Gandhi, K. Siler-Evans, E. Devendorf, B. Kelley, J. Gimbi, J. Aguirre, G. Kulp, M. Stalczynski, M. J. Malone · 2026 · RAND Corporation (Research Report RR-A4827-1)

    Supports: title, authors and date; objectives; OC5 threat model; realm architecture; request lifecycle; hazards and energy monitoring; trusted setup; formal-methods chain; costs, schedule and staffing; limitations; recommendations

    Locator: Summary (p. v); ch. 1 (pp. 1-3); ch. 3 (pp. 9-15); ch. 4 (pp. 18-22); ch. 5 (p. 24); Appendix B (pp. 27-30), GPU counts from Table B.1; Appendix C (pp. 34-35) for TLA+

    Version and catalogue details
  2. S-1706 / Tier B

    Intelligence Security Laboratories: Building secure infrastructure for transformative AI ↗

    · 2026 · Intelligence Security Laboratories

    Supports: Intelligence Security Laboratories' stated aim, its use of STPA-Sec, and its reference to this report

    Version and catalogue details
  3. S-1707 / Tier B

    Our Team: Intelligence Security Laboratories ↗

    · 2026 · Intelligence Security Laboratories

    Supports: ISL's executive director, Gabriel Kulp, a co-author of the report

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review