Distributed Trust for AI (DTAI) Model Confidentiality
AI model weights are valuable intellectual property and increasingly important security assets. Conventional cloud deployments commonly encrypt model weights with a data encryption key, or DEK, and protect that key with a key encryption key managed by the same cloud provider that stores or processes the model. This envelope-encryption pattern protects against storage compromise, but it can concentrate control over the encrypted model, key-management infrastructure, authorization plane, and execution environment within a single administrative trust domain. This paper proposes the Distributed Trust Architecture for AI, or DTAI, an attestationbased, multi-authority architecture for protecting high-value AI model weights. DTAI separates the information required to derive a model DEK across two independently administered key authorities. One authority stores key contribution K1, while another stores key contribution K2. Neither contribution is itself the DEK. An approved workload running inside a hardware-backed trusted execution environment, or TEE, obtains both contributions only after satisfying workload identity, platform security, freshness, authorization, and proof-of-possession requirements. The workload derives the DEK inside the TEE by applying a standards-based key derivation function to K1 and K2.
Authors
- Vishal Chandwani (ORCID: https://orcid.org/0009-0002-3373-9218)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-28
- DOI
- https://doi.org/10.5281/zenodo.23020022
- Primary Topic
- Security and Verification in Computing
- Type
- article
- Field-Weighted Citation Impact
- 0.00