Distributed Trust for AI (DTAI) Model Confidentiality

AI model weights are valuable intellectual property and increasingly important security assets. Conventional cloud deployments commonly encrypt model weights with a data encryption key, or DEK, and protect that key with a key encryption key managed by the same cloud provider that stores or processes the model. This envelope-encryption pattern protects against storage compromise, but it can concentrate control over the encrypted model, key-management infrastructure, authorization plane, and execution environment within a single administrative trust domain. This paper proposes the Distributed Trust Architecture for AI, or DTAI, an attestationbased, multi-authority architecture for protecting high-value AI model weights. DTAI separates the information required to derive a model DEK across two independently administered key authorities. One authority stores key contribution K1, while another stores key contribution K2. Neither contribution is itself the DEK. An approved workload running inside a hardware-backed trusted execution environment, or TEE, obtains both contributions only after satisfying workload identity, platform security, freshness, authorization, and proof-of-possession requirements. The workload derives the DEK inside the TEE by applying a standards-based key derivation function to K1 and K2.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-28
DOI
https://doi.org/10.5281/zenodo.23020022
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Distributed Trust for AI (DTAI) Model Confidentiality

Vishal Chandwani
Zenodo (CERN European Organization for Nuclear Research)
Security and Verification in Computing
article

Distributed Trust for AI (DTAI) Model Confidentiality

Vishal Chandwani
article en

Abstract

AI model weights are valuable intellectual property and increasingly important security assets. Conventional cloud deployments commonly encrypt model weights with a data encryption key, or DEK, and protect that key with a key encryption key managed by the same cloud provider that stores or processes the model. This envelope-encryption pattern protects against storage compromise, but it can concentrate control over the encrypted model, key-management infrastructure, authorization plane, and execution environment within a single administrative trust domain. This paper proposes the Distributed Trust Architecture for AI, or DTAI, an attestationbased, multi-authority architecture for protecting high-value AI model weights. DTAI separates the information required to derive a model DEK across two independently administered key authorities. One authority stores key contribution K1, while another stores key contribution K2. Neither contribution is itself the DEK. An approved workload running inside a hardware-backed trusted execution environment, or TEE, obtains both contributions only after satisfying workload identity, platform security, freshness, authorization, and proof-of-possession requirements. The workload derives the DEK inside the TEE by applying a standards-based key derivation function to K1 and K2.

Zenodo (CERN European Organization for Nuclear Research)
Industry, innovation and infrastructure
Openalex Percentile: Top 9%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Distributed Trust for AI (DTAI) Model Confidentiality — Vishal Chandwani · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS