IP Library Granted Patent US 12,621,142
Granted Patent B2
US 12,621,142 · App. 18/899,444 · Granted May 5, 2026

System and method for privately hosting machine learning models and collaborative computations

Inventors: Andrew Rademacher (Kansas City, MO); Gharib Gharibi (Overland Park, KS); Craig Gentry (New York, NY); Riddhiman Das (Parkville, MO)
Assignee: Agentic Healthcare, Inc.
H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,142
App. No.
18/899,444
Granted
May 5, 2026
Kind
B2
Abstract

Systems and methods are disclosed for offering a secure model as a service. A system can be configured to implement, via a trusted execution environment comprising an enclave virtual machine and a customer key host, a distributed privacy policy in which a master decryption key is split-shared between the trusted execution environment the customer key host; perform a decryption of the master decryption key according to the distributed privacy policy to obtain a decrypted master key; and, based on the decrypted master key, perform, in the trusted execution environment, a private collaborative computation using one or more of customer data and a customer model. Secure multiparty computation can be used to perform the decryption of the master decryption key.

Claims (43)

1 . A method of managing an artificial intelligence model lifecycle, the method comprising:

initializing, by a service provider and in a secure virtual machine compute enclave, a model host from an image that has secure software preinstalled and configured to start on boot;

connecting the model host to block storage volumes that are mounted with an encrypted file system;

providing a key host to the secure virtual machine compute enclave, the key host providing an implementation of a component that ensures that encryption and decryption operations require participation both by a first party and a second party;

providing a customer key host to a customer computer system;

running, by the encrypted file system, a hardware attestation report comprising a cryptographically signed statement validating that the model host is running on a genuine processor manufactured by an enclave manufacturer with a secure compute element enabled and that guest measurements were taken of the secure virtual machine compute enclave to obtain a report;

transmitting, from the encrypted file system and to the key host, the report to signal that participation in decryption of the encrypted file system used by the model host is safe; and

initiating a trusted execution environment on the secure virtual machine compute enclave by implementing distributed access policy enforcement between the first party and the second party, for data access or computation authorization in which both the first party and the second party exchange data to unlock a master decryption key.

2 . The method of claim 1 , wherein the image only comprises the secure software for networking and has all other networking software removed including an open secure shell server.

3 . The method of claim 1 , wherein the image comprises the guest measurements as defined by a hardware secure compute element.

4 . The method of claim 1 , wherein the secure software comprises a white list of allowable operations.

5 . The method of claim 1 , wherein the model host is configured to run machine learning models on behalf of one of the first party or the second party.

6 . The method of claim 1 , wherein the distributed access policy enforcement between the first party and the second party comprises using secure multiparty computations between the first party and the second party exchange data to unlock the master decryption key.

7 . The method of claim 6 , wherein the secure multiparty computations cause the first party having data X 1 and the second party having data X 2 to learn a computing result C(X 1 , X 2 ) without the first party revealing X 1 to the second party or the second party revealing X 2 to the first party.

8 . The method of claim 6 , wherein X 1 and X 2 represent respective outputs from respective encryption algorithms operated by the first party or the second party.

9 . A system for managing an artificial intelligence model lifecycle, the system comprising:

at least one memory; and

at least one processor coupled to the at least one memory and configured to:

initialize, by a service provider and in a secure virtual machine compute enclave, a model host from an image that has secure software preinstalled and configured to start on boot;

connect the model host to block storage volumes that are mounted with an encrypted file system;

provide a key host to the secure virtual machine compute enclave, the key host providing an implementation of a component that ensures that encryption and decryption operations require participation both by a first party and a second party;

provide a customer key host to a customer computer system;

run, by the encrypted file system, a hardware attestation report comprising a cryptographically signed statement validating that the model host is running on a genuine processor manufactured by an enclave manufacturer with a secure compute element enabled and that guest measurements were taken of the secure virtual machine compute enclave to obtain a report;

transmit, from the encrypted file system and to the key host, the report to signal that participation in decryption of the encrypted file system used by the model host is safe; and

initiate a trusted execution environment on the secure virtual machine compute enclave by implementing distributed access policy enforcement between the first party and the second party, for data access or computation authorization in which both the first party and the second party exchange data to unlock a master decryption key.

10 . The system of claim 9 , wherein the image only comprises the secure software for networking and has all other networking software removed including an open secure shell server.

11 . The system of claim 9 , wherein the image comprises the guest measurements as defined by a hardware secure compute element.

12 . The system of claim 9 , wherein the secure software comprises a white list of allowable operations.

13 . The system of claim 9 , wherein the model host is configured to run machine learning models on behalf of one of the first party or the second party.

14 . The system of claim 9 , wherein the distributed access policy enforcement between the first party and the second party comprises using secure multiparty computations between the first party and the second party exchange data to unlock the master decryption key.

15 . The system of claim 14 , wherein the secure multiparty computations cause the first party having data X 1 and the second party having data X 2 to learn a computing result C(X 1 , X 2 ) without the first party revealing X 1 to the second party or the second party revealing X 2 to the first party.

16 . The system of claim 14 , wherein X 1 and X 2 represent respective outputs from respective encryption algorithms operated by the first party or the second party.

17 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to:

initialize, by a service provider and in a secure virtual machine compute enclave, a model host from an image that has secure software preinstalled and configured to start on boot;

connect the model host to block storage volumes that are mounted with an encrypted file system;

provide a key host to the secure virtual machine compute enclave, the key host providing an implementation of a component that ensures that encryption and decryption operations require participation both by a first party and a second party;

provide a customer key host to a customer computer system;

run, by the encrypted file system, a hardware attestation report comprising a cryptographically signed statement validating that the model host is running on a genuine processor manufactured by an enclave manufacturer with a secure compute element enabled and that guest measurements were taken of the secure virtual machine compute enclave to obtain a report;

transmit, from the encrypted file system and to the key host, the report to signal that participation in decryption of the encrypted file system used by the model host is safe; and

initiate a trusted execution environment on the secure virtual machine compute enclave by implementing distributed access policy enforcement between the first party and the second party, for data access or computation authorization in which both the first party and the second party exchange data to unlock a master decryption key.

18 . The non-transitory computer-readable medium of claim 17 , wherein the distributed access policy enforcement between the first party and the second party comprises using secure multiparty computations between the first party and the second party exchange data to unlock the master decryption key.

19 . The non-transitory computer-readable medium of claim 18 , wherein the secure multiparty computations cause the first party having data X 1 and the second party having data X 2 to learn a computing result C(X 1 , X 2 ) without the first party revealing X 1 to the second party or the second party revealing X 2 to the first party.

20 . The non-transitory computer-readable medium of claim 18 , wherein X 1 and X 2 represent respective outputs from respective encryption algorithms operated by the first party or the second party.

Continuity (2)
Provisional Application 63540787 · Sep 27, 2023
Related Publication 20250106019A1 · Mar 27, 2025
References Cited (11)
US 11113400B1 · Emelyanov · 2021 [cited by examiner]
US 20060253704A1 · Kempf · 2006 [cited by examiner]
US 20180183578A1 · Chakrabarti · 2018 [cited by examiner]
US 20180183580A1 · Scarlata · 2018 [cited by examiner]
US 20180247082A1 · Durham · 2018 [cited by examiner]
US 20180255023A1 · Whaley · 2018 [cited by examiner]
US 20200259799A1 · Li · 2020 [cited by examiner]
US 20210019166A1 · Kataria · 2021 [cited by examiner]
US 20250007897A1 · Briongos · 2025 [cited by examiner]
US 20250343678A1 · Rush · 2025 [cited by examiner]
Gharibi et al., “TripleBlind: A Privacy-Preserving Framework for Decentralized Data and Algorithms”, Proceedings of Machine Learning Research 176:343-348, 2022 NeurIPS 2021 Competition and Demonstration Track. (Year: 20… [cited by examiner]