IP Library › Granted Patent US 12,639,423
Granted Patent B2
US 12,639,423 · App. 18/897,790 · Granted May 26, 2026

Secure modular machine learning platform

Inventors: Madalasa Venkataraman (Bangalore, IN); Paul Deepakraj Retinraj (Fremont, CA); Pradeep Sanchana (Srikakulam, IN); Rohit Sukumaran (Bangalore, IN); Oleksandr Khimich (Kyle, TX)
Assignee: Oracle International Corporation
G06F21/53G06F21/56G06F2221/03
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,423
App. No.
18/897,790
Granted
May 26, 2026
Kind
B2
Abstract

A secure, modular multi-tenant machine learning platform is configured to: receive untrusted code supplied by a first tenant; perform a security scan of the untrusted code to determine whether the untrusted code satisfies a set of one or more security requirements; responsive to determining that the untrusted code satisfies the security requirement(s): deploy the untrusted code to a runtime execution environment; deploy a machine learning model associated with the first tenant to the runtime execution environment, the untrusted code being configured to perform one or more functions using the machine learning model; receive a set of untrusted code supplied by a second tenant; perform a security scan of the untrusted code to determine whether the untrusted code satisfies the security requirement(s); and responsive to determining that the untrusted code does not satisfy the security requirement(s): refraining from deploying the untrusted code to a runtime execution environment.

Claims (73)

1 . One or more non-transitory machine-readable media storing instructions that, when executed by one or more processors, cause performance of operations comprising:

receiving, by a multi-tenant machine learning platform, a first set of untrusted code supplied by a first tenant of the multi-tenant machine learning platform;

performing a first security scan, by the multi-tenant machine learning platform, of the first set of untrusted code to determine whether the first set of untrusted code satisfies a set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the first set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform: deploying, by the multi-tenant machine learning platform, the first set of untrusted code to a first runtime execution environment of the multi-tenant machine learning platform;

deploying, by the multi-tenant machine learning platform, a first machine learning model associated with the first tenant to the first runtime execution environment, the first set of untrusted code being configured to perform one or more functions using the first machine learning model;

receiving, by the multi-tenant machine learning platform, a second set of untrusted code supplied by a second tenant of the multi-tenant machine learning platform;

performing a second security scan, by the multi-tenant machine learning platform, of the second set of untrusted code to determine whether the second set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the second set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform: storing, by the multi-tenant machine learning platform, the second set of untrusted code in a second runtime execution environment of the multi-tenant machine learning platform;

deploying, by the multi-tenant machine learning platform, a second machine learning model associated with the second tenant to the second runtime execution environment, the second set of untrusted code being configured to perform one or more functions using the second machine learning model;

wherein the first runtime execution environment and the second runtime execution environment are logically separated, such that the first set of untrusted code is not authorized to access the second runtime execution environment and the second set of untrusted code is not authorized to access the first runtime execution environment.

2 . The one or more non-transitory machine-readable media of claim 1 , the operations further comprising:

receiving, by the multi-tenant machine learning platform, the first machine learning model from the first tenant.

3 . The one or more non-transitory machine-readable media of claim 2 , the operations further comprising:

performing an anti-virus scan of the first machine learning model to determine whether the first machine learning model is infected by any virus detectable by the anti-virus scan,

wherein deploying the first machine learning model associated with the first tenant to the first runtime execution environment is performed responsive to the first machine learning model passing the anti-virus scan.

4 . The one or more non-transitory machine-readable media of claim 1 , the operations further comprising:

receiving, by the multi-tenant machine learning platform, a third set of untrusted code supplied by a third tenant of the multi-tenant machine learning platform;

performing a third security scan, by the multi-tenant machine learning platform, of the third set of untrusted code to determine whether the third set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the third set of untrusted code does not satisfy the set of one or more security requirements of the multi-tenant machine learning platform: refraining from deploying the third set of untrusted code to a third runtime execution environment of the multi-tenant machine learning platform.

5 . The one or more non-transitory machine-readable media of claim 4 , wherein the third runtime execution environment is uniquely associated with the third tenant and inaccessible to other tenants of the multi-tenant machine learning platform.

6 . The one or more non-transitory machine-readable media of claim 1 , wherein performing the first security scan comprises one or more of (a) determining whether one or more software components in the first set of untrusted code is up-to-date or (b) performing a virus scan of the first set of untrusted code.

7 . The one or more non-transitory machine-readable media of claim 1 , wherein receiving the first set of untrusted code comprises receiving a container image comprising the first set of untrusted code.

8 . The one or more non-transitory machine-readable media of claim 1 , wherein the first runtime execution environment of the multi-tenant machine learning platform executes in a cluster that is uniquely associated with the first tenant and deployed to a physical machine that is uniquely designated for the first tenant.

9 . The one or more non-transitory machine-readable media of claim 1 , wherein the first runtime executable environment is uniquely associated with the first tenant and inaccessible to other tenants of the multi-tenant machine learning platform.

10 . The one or more non-transitory machine-readable media of claim 1 , wherein the first set of untrusted code is configured to perform one or more of:

data scoring, at least by applying the first machine learning model to a data set;

generating predictions, at least by applying the first machine learning model to the data set; or

implementing a feedback loop that uses outputs of the first machine learning model to train the first machine learning model on an ongoing basis.

11 . The one or more non-transitory machine-readable media of claim 1 , wherein deploying the first machine learning model associated with the first tenant to the first runtime execution environment is performed responsive to determining that the first set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform.

12 . The one or more non-transitory machine-readable media of claim 1 , the operations further comprising:

bundling the first set of untrusted code and the first machine learning model before deploying the first set of untrusted code and the first machine learning model to the first runtime execution environment.

13 . A system comprising:

one or more hardware processors;

one or more non-transitory computer-readable media; and

program instructions stored on the one or more non-transitory computer-readable media which, when executed by one or more hardware processors, cause the system to perform operations comprising:

receiving, by a multi-tenant machine learning platform, a first set of untrusted code supplied by a first tenant of the multi-tenant machine learning platform;

performing a first security scan, by the multi-tenant machine learning platform, of the first set of untrusted code to determine whether the first set of untrusted code satisfies a set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the first set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform: deploying, by the multi-tenant machine learning platform, the first set of untrusted code to a first runtime execution environment of the multi-tenant machine learning platform;

deploying, by the multi-tenant machine learning platform, a first machine learning model associated with the first tenant to the first runtime execution environment, the first set of untrusted code being configured to perform one or more functions using the first machine learning model;

receiving, by the multi-tenant machine learning platform, a second set of untrusted code supplied by a second tenant of the multi-tenant machine learning platform;

performing a second security scan, by the multi-tenant machine learning platform, of the second set of untrusted code to determine whether the second set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the second set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform: storing, by the multi-tenant machine learning platform, the second set of untrusted code in a second runtime execution environment of the multi-tenant machine learning platform;

deploying, by the multi-tenant machine learning platform, a second machine learning model associated with the second tenant to the second runtime execution environment, the second set of untrusted code being configured to perform one or more functions using the second machine learning model;

wherein the first runtime execution environment and the second runtime execution environment are logically separated, such that the first set of untrusted code is not authorized to access the second runtime execution environment and the second set of untrusted code is not authorized to access the first runtime execution environment.

14 . The system of claim 13 , the operations further comprising:

receiving, by the multi-tenant machine learning platform, the first machine learning model from the first tenant.

15 . The system of claim 14 , the operations further comprising:

performing an anti-virus scan of the first machine learning model to determine whether the first machine learning model is infected by any virus detectable by the anti-virus scan,

wherein deploying the first machine learning model associated with the first tenant to the first runtime execution environment is performed responsive to the first machine learning model passing the anti-virus scan.

16 . The system of claim 13 , the operations further comprising:

receiving, by the multi-tenant machine learning platform, a third set of untrusted code supplied by a third tenant of the multi-tenant machine learning platform;

performing a third security scan, by the multi-tenant machine learning platform, of the third set of untrusted code to determine whether the third set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the third set of untrusted code does not satisfy the set of one or more security requirements of the multi-tenant machine learning platform: refraining from deploying the third set of untrusted code to a third runtime execution environment of the multi-tenant machine learning platform.

17 . A method comprising:

receiving, by a multi-tenant machine learning platform, a first set of untrusted code supplied by a first tenant of the multi-tenant machine learning platform;

performing a first security scan, by the multi-tenant machine learning platform, of the first set of untrusted code to determine whether the first set of untrusted code satisfies a set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the first set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform: deploying, by the multi-tenant machine learning platform, the first set of untrusted code to a first runtime execution environment of the multi-tenant machine learning platform;

deploying, by the multi-tenant machine learning platform, a first machine learning model associated with the first tenant to the first runtime execution environment, the first set of untrusted code being configured to perform one or more functions using the first machine learning model;

receiving, by the multi-tenant machine learning platform, a second set of untrusted code supplied by a second tenant of the multi-tenant machine learning platform;

performing a second security scan, by the multi-tenant machine learning platform, of the second set of untrusted code to determine whether the second set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the second set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform: storing, by the multi-tenant machine learning platform, the second set of untrusted code in a second runtime execution environment of the multi-tenant machine learning platform;

deploying, by the multi-tenant machine learning platform, a second machine learning model associated with the second tenant to the second runtime execution environment, the second set of untrusted code being configured to perform one or more functions using the second machine learning model;

wherein the first runtime execution environment and the second runtime execution environment are logically separated, such that the first set of untrusted code is not authorized to access the second runtime execution environment and the second set of untrusted code is not authorized to access the first runtime execution environment;

wherein the method is performed by at least one device including a hardware processor.

18 . The method of claim 17 , further comprising:

receiving, by the multi-tenant machine learning platform, the first machine learning model from the first tenant.

19 . The method of claim 18 , further comprising:

performing an anti-virus scan of the first machine learning model to determine whether the first machine learning model is infected by any virus detectable by the anti-virus scan,

wherein deploying the first machine learning model associated with the first tenant to the first runtime execution environment is performed responsive to the first machine learning model passing the anti-virus scan.

20 . The method of claim 17 , further comprising:

receiving, by the multi-tenant machine learning platform, a third set of untrusted code supplied by a third tenant of the multi-tenant machine learning platform;

performing a third security scan, by the multi-tenant machine learning platform, of the third set of untrusted code to determine whether the third set of untrusted code satisfies the set of one or more security requirements of the multi-tenant machine learning platform;

responsive to determining that the third set of untrusted code does not satisfy the set of one or more security requirements of the multi-tenant machine learning platform: refraining from deploying the third set of untrusted code to a third runtime execution environment of the multi-tenant machine learning platform.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: VENKATARAMAN, MADALASA; RETINRAJ, PAUL DEEPAKRAJ; SANCHANA, PRADEEP; SUKUMARAN, ROHIT; KHIMICH, OLEKSANDR
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 068710/0754 →
Continuity (3)
Continuation 17870403 · Jul 21, 2022
Provisional Application 63330645 · Apr 13, 2022
Related Publication 20250021641A1 · Jan 16, 2025
References Cited (17)
US 8356351B2 · Fu et al. · 2013 [cited by applicant]
US 8627451B2 · Walsh · 2014 [cited by examiner]
US 8850574B1 · Ansel et al. · 2014 [cited by applicant]
US 10162617B2 · Eltsin et al. · 2018 [cited by applicant]
US 10496824B2 · Raj · 2019 [cited by examiner]
US 11470053B2 · Karame et al. · 2022 [cited by applicant]
US 11675648B2 · Chen et al. · 2023 [cited by applicant]
US 20100199357A1 · Hoffman · 2010 [cited by examiner]
US 20150319192A1 · Cabrera · 2015 [cited by examiner]
US 20190005228A1 · Singh · 2019 [cited by examiner]
US 20200234184A1 · Kesarwani et al. · 2020 [cited by applicant]
US 20200372307A1 · Arun et al. · 2020 [cited by applicant]
US 20210397999A1 · Bernat et al. · 2021 [cited by applicant]
US 20220391199A1 · Ashrafzadeh et al. · 2022 [cited by applicant]
US 20220391239A1 · Feldman et al. · 2022 [cited by applicant]
US 20230153447A1 · Pankaj · 2023 [cited by applicant]
US 20230188516A1 · Danilov · 2023 [cited by examiner]