Implementation · RAND secure inference data center (SIDC) design

Technical detail

On this page
  • Assurance chain. The report sets out a step-by-step assurance chain for the cross-realm solution that mediates every boundary crossing 1. A hazard analysis (STPA-Sec) justifies the component, and the requirements are allocated in a system model. A finite-state protocol specification fixes authorized behaviour, sequencing, timing and fail-secure transitions. Cryptographic protocol analysis with Tamarin and CryptoVerif would cover end-point authentication, secrecy, replay resistance and key freshness under stated assumptions. The authors report modelling the channel's control logic in TLA+ and machine-checking its safety properties, and say they have begun mapping the design to formal verification artifacts. The report does not publish the analyses. The specified behaviour can then be translated into synthesizable hardware logic, such as FPGA-based channel control, and circuit-level assertions can check selected temporal properties at the register-transfer level 1.
  • Hardware assumptions. Cost estimates assume 150 GPUs at about 250 kW for the proof-of-concept and 375 GPUs at about 3 MW at enterprise scale; the design is agnostic to the accelerator type 1.
  • Staffing. About 100 cleared staff for a proof-of-concept and 300 for a deployment-scale facility 1.
  • Schedule. The 14-month estimate assumes emergency or national-priority conditions and a government-owned facility built inside an existing hangar or warehouse. Otherwise RAND expects two to two and a half years to deploy, plus about a year for accreditation 1.

Search

Full search page