Trusted Execution Environment Airlock for Secure ML Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing machine learning model training and deployment methods in shared or untrusted computing environments face challenges in protecting data confidentiality and integrity, with risks of unauthorized access, data exfiltration, model tampering, and side-channel attacks, especially in federated learning scenarios.

Innovation Solution

A machine learning model training airlock technique using a trusted execution environment (TEE) with multiple security checkpoints ensures secure data and model verification, incorporates noise to reduce side-channel leakage, and maintains an airgap between inputs and outputs, ensuring only validated models are released.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If machine learning model training is performed in shared or untrusted computing environments, then computational resources and flexibility are improved, but data confidentiality and model integrity are compromised

Engineering Contradiction:
Improvecomputational flexibilityVSAvoiddata confidentiality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a Trusted Execution Environment (TEE) as an intermediary layer between the untrusted cloud computing environment and the sensitive training data/models. The TEE acts as a secure enclave that isolates and protects data confidentiality while allowing the broader shared computing environment to provide computational resources. This mediator enables the system to leverage cloud flexibility without sacrificing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If machine learning model training is performed in shared or untrusted computing environments, then computational resources and flexibility are improved, but model integrity and protection from tampering are compromised

Engineering Contradiction:
Improvecomputational flexibilityVSAvoidmodel integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The TEE serves as a protective intermediary that isolates the model training process from potential tampering in the shared environment. By confining training operations within the secure enclave, the system maintains model integrity while still benefiting from the flexibility of cloud-based computational resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the computing environment into a secure isolated TEE region and the untrusted external environment. This segmentation ensures that even though the model trains in a shared cloud environment, the sensitive operations are confined to a protected segment, preventing unauthorized access and tampering.

Inventive Principle:
Principle #1Segmentation

3Productivity

If data and models are made accessible for training, then training efficiency and productivity are improved, but risk of unauthorized access and data exfiltration increases

Engineering Contradiction:
Improvetraining efficiencyVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The TEE acts as a secure intermediary that enables data and models to be accessed for training purposes while maintaining protection. The TEE provides controlled access within its boundaries, allowing training operations to proceed efficiently while preventing unauthorized access and data exfiltration to external systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-generated harmful factors

If side-channel attacks are implemented, then information leakage and security breaches are enabled, but the security and reliability of the training process are compromised

Engineering Contradiction:
Improveinformation leakageVSAvoidtraining process security
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The TEE functions as a security intermediary that blocks side-channel attack vectors by isolating the training process within a secure enclave. The TEE's hardware-level isolation prevents attackers from observing physical side-channels (power consumption, electromagnetic emissions, timing) that could leak information about the training data or models.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250355994A1Apparatus for secure machine learning model training, a method for secure machine learning model training and a non-transitory machine-readable storage medium
Publication Date: 2025.11.20 INTEL CORP
  • US20250355994A1 patent drawing
  • US20250355994A1 patent drawing
  • US20250355994A1 patent drawing

AI summary

It is provided an apparatus comprising interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions. The machine-readable instructions include instructions to obtain a machine learning model and data within a trusted execution environment. The data is configured for training of the machine learning model. The trusted execution environment secures a training of machine model against unauthorized access. The machine-readable instructions further include instructions to verify at least one of the machine learning model and the data and to perform training of the machine learning model based on the data, if the verification of the at least one of the data and the machine learning model is successful. The machine-readable instructions further include instructions to verify the training process of the machine learning model and to output the trained machine learning model from the trusted execution environment, if the verification of the training process is successful.