Securely providing data from a source entity for training a model of a model entity
In one aspect, in general, a system for securely providing data for training a model comprises: a source entity comprising at least one processor and configured to: receive data configuration instructions associated with training the model, transform unprepared data from one or more data sources into prepared data based at least in part on the data configuration instructions, the prepared data comprising one or more prepared data units, and produce, using a signing module, a data package comprising the one or more prepared data units and a respective signature object associated with each of the one or more prepared data units; wherein the signing module comprises specialized circuitry configured for accelerating at least one quantum resistant computational operation.
1 . A method for securely providing data from a source entity for training a model of a model entity, the method comprising:
at the source entity:
receiving data configuration instructions associated with the model entity,
transforming unprepared data from one or more data sources into prepared data based at least in part on the data configuration instructions, the prepared data comprising one or more prepared data units,
producing, using a signing module, a data package comprising the one or more prepared data units and a respective signature object associated with each of the one or more prepared data units, and
providing the data package to the model entity; and
at the model entity:
accessing the provided data package,
verifying, using a verification module, each of the signature objects associated with the prepared data units in the provided data package, and
providing the prepared data to a trainer module using a secure communication channel configured to provide a trusted link between the verification module and the trainer module.
2 . The method of claim 1 , wherein providing the data package to the model entity comprises transmitting the data package from the source entity to the model entity over one or more communication channels.
3 . The method of claim 2 , wherein at least one communication channel of the one or more communication channels is routed through one or more intermediate entities configured to receive the data package and transmit the data package to a subsequent intermediate entity.
4 . The method of claim 1 , wherein providing the data package to the model entity comprises storing the data package at a storage medium for a period of time after which the model entity accesses the storage medium and verifies each of the signature objects associated with the prepared data units.
5 . The method of claim 4 , wherein providing the data package to the model entity further comprises verifying each of the signature objects associated with the prepared data units before storing the data package at the storage medium.
6 . The method of claim 1 , wherein the secure communication channel comprises a wired connection between the verification module and the trainer module.
7 . The method of claim 6 , wherein the wired connection comprises a peripheral component interconnect express connection.
8 . The method of claim 1 , wherein the secure communication channel comprises a wireless private network connection between the verification module and the trainer module.
9 . The method of claim 1 , wherein the trainer module comprises a hardware configuration and the data configuration instructions are based at least in part on the hardware configuration.
10 . The method of claim 9 , wherein the hardware configuration comprises one or more graphics processing units.
11 . The method of claim 9 , wherein the hardware configuration comprises one or more central processing units.
12 . The method of claim 1 , wherein the trainer module of the model entity comprises a model configuration and the data configuration instructions are based at least in part on the model configuration.
13 . The method of claim 1 , wherein the trainer module of the model entity comprises a machine learning framework and the data configuration instructions are based at least in part on the machine learning framework.
14 . The method of claim 1 , wherein the trainer module of the model entity comprises a development environment and the data configuration instructions are based at least in part on the development environment.
15 . The method of claim 1 , wherein the signature objects associated with each of the one or more prepared data units are generated based at least in part on at least one quantum resistant operation.
16 . The method of claim 1 , wherein the signature objects associated with each of the one or more prepared data units are generated based at least in part on a hash function.
17 . The method of claim 1 , wherein the signing module comprises a cryptographic module configured to generate signature objects associated with each of the one or more prepared data units, and the signature objects are based at least in part on at least one quantum resistant operation.
18 . The method of claim 1 , wherein the source entity comprises the signing module and the verification module.
19 . The method of claim 1 , wherein the signing module comprises specialized circuitry configured to produce the signature objects.
20 . The method of claim 1 , wherein the signing module comprises a particular hardware and software architecture, and the verification module comprise the same particular hardware and software architecture.
21 . A system comprising:
a source entity configured to:
receive data configuration instructions associated with the model entity,
transform unprepared data from one or more data sources into prepared data based at least in part on the data configuration instructions, the prepared data comprising one or more prepared data units,
produce, using a signing module, a data package comprising the one or more prepared data units and a respective signature object associated with each of the one or more prepared data units, and
transmit the data package to the model entity over one or more communication channels; and
a model entity configured to:
receive the transmitted data package from the model entity,
verify, using a verification module, each of the signature objects associated with the prepared data units in the provided data package, and
provide the prepared data to a trainer module using a secure communication channel configured to provide a trusted link between the verification module and the trainer module.
22 . The system of claim 21 , wherein the signing module comprises specialized circuitry configured for accelerating at least one quantum resistant computational operation.
23 . The system of claim 21 , wherein the verification module comprises specialized circuitry configured for accelerating at least one quantum resistant computational operation.
24 . The system of claim 21 , wherein the data configuration instructions comprise a hardware configuration associated with the model entity.
25 . The system of claim 21 , wherein the data configuration instructions comprise a development environment associated with the model entity.
26 . The system of claim 21 , wherein the secure communication channel comprises a wired connection, a wireless connection, or some combination thereof.
27 . A system comprising:
a storage medium;
a source entity configured to:
receive data configuration instructions associated with the model entity,
transform unprepared data from one or more data sources into prepared data based at least in part on the data configuration instructions, the prepared data comprising one or more prepared data units,
produce, using a signing module, a data package comprising the one or more prepared data units and a respective signature object associated with each of the one or more prepared data units, and
store the data package in the storage medium; and
a model entity configured to:
access the provided data package from the storage medium,
verify, using a verification module, each of the signature objects associated with the prepared data units in the provided data package, and
provide the prepared data to a trainer module using a secure communication channel configured to provide a trusted link between the verification module and the trainer module.
28 . The system of claim 27 , wherein the signing module comprises specialized circuitry configured for accelerating at least one quantum resistant computational operation.
29 . The system of claim 27 , wherein the verification module comprises specialized circuitry configured for accelerating at least one quantum resistant computational operation.
30 . The system of claim 27 , wherein the source entity prepares a plurality of data packages each associated with different respective data configuration instructions and stores the plurality of data packages in the storage medium.
31 . A system for securely providing data for training a model, the system comprising:
a source entity comprising at least one processor and configured to:
receive data configuration instructions associated with training the model,
transform unprepared data from one or more data sources into prepared data based at least in part on the data configuration instructions, the prepared data comprising one or more prepared data units, and
produce, using a signing module, a data package comprising the one or more prepared data units and a respective signature object associated with each of the one or more prepared data units;
wherein the signing module comprises specialized circuitry configured for accelerating at least one quantum resistant computational operation.
32 . The system of claim 31 , wherein a quantum resistant operation that the specialized circuitry is configured to accelerate is a post-quantum cryptography algorithm.
33 . The system of claim 32 , wherein the specialized circuitry includes circuitry configured to accelerate one or more of the following operations: modular exponentiation of large integers, multiplication of points on an elliptical curve, polynomial multiplication, or Keccak algorithms.
34 . The system of claim 31 , wherein each signature object is generated at least in part using a hash function.
35 . The system of claim 31 , wherein the data configuration instructions comprise a hardware configuration associated with training the model.
36 . A system for securely receiving data for training a model, the system comprising:
a model entity comprising at least one processor and configured to:
access a data package comprising the one or more prepared data units and a respective signature object associated with each of the one or more prepared data units, where the prepared data units were prepared based at least in part on the data configuration instructions associated with training the model,
verify, using a verification module, each of the signature objects associated with the prepared data units in the provided data package, and
provide the prepared data to a trainer module using a secure communication channel configured to provide a trusted link between the verification module and the trainer module;
wherein the verification module comprises specialized circuitry configured for accelerating at least one quantum resistant computational operation.
37 . The system of claim 36 , wherein the specialized circuitry of the verification module is configured for accelerating at least one quantum resistant computational operation associated with a post-quantum cryptography algorithm.
38 . The system of claim 36 , wherein the secure communication channel comprises a wired connection between the verification module and the trainer module.
39 . The system of claim 36 , wherein the secure communication channel comprises a wireless connection between the verification module and the trainer module.
40 . The system of claim 36 , wherein the secure communication channel comprises a combination of at least one wireless connection and at least one wired connection between the verification module and the trainer module.
41 . The system of claim 36 , wherein a quantum resistant operation that the specialized circuitry is configured to accelerate is a post-quantum cryptography algorithm.
42 . The system of claim 41 , wherein the specialized circuitry includes circuitry configured to accelerate one or more of the following operations: modular exponentiation of large integers, multiplication of points on an elliptical curve, polynomial multiplication, or Keccak algorithms.