Aridhia DRE - Trusted Research Environment

Introducing Flower on the Aridhia DRE

Deploying production-ready federated learning networks in days, not months

Federated learning allows organisations to train machine learning models across distributed datasets without centralising sensitive data.

Frameworks such as Flower are already mature and can be deployed with relative ease. The barriers we see to the adoption of federated learning generally relate to organisational factors like IT department capacity and priorities, or the governance processes needed to provision infrastructure inside regulated organisations.

Integrating federated learning capabilities with Trusted Research Environments (TRE) can help us break down these barriers and speed up network deployments from months to hours:

 

In this blog we detail how users can take advantage of this capability in the Aridhia DRE.

The infrastructure challenge

Standing up a federated learning network typically requires:

  • Identifying and provisioning secure compute environments at each participating site
  • Configuring network isolation and VPN connectivity between organisations
  • Deploying and maintaining federated learning orchestration software
  • Implementing authentication and access control
  • Building governance workflows for data access requests

Each of these steps introduces delay, and a multi-site collaboration can wait months or even years before infrastructure is agreed, built, and signed off by all partners. By that point funding cycles have moved on, staff have changed roles, and the research question may have evolved.

Flower on the Aridhia DRE

The Aridhia DRE is a fully certified, cloud-based Trusted Research Environment (TRE) used by research hospitals, global consortia, and life sciences organisations in more than 80 countries. As an enterprise-scale TRE, it already provides the base-level infrastructure that federated learning depends on:

  • Multi-organisation architecture. A single DRE hub can host multiple organisations, each operating within a secure, isolated slice of the infrastructure, with no cross-organisation data visibility without explicit governance approval.
  • Network-secure workspaces. Workspaces can be restricted to an organisation's VPN, with SSO, MFA, and defence-in-depth security. Researchers authenticate to the DRE and work within a controlled, auditable environment.
  • ISO 27001/27701 certification. The DRE holds the security and privacy certifications expected by healthcare, life sciences, and other regulated organisations.

Flower can now be deployed within this architecture. Each participating network member receives a dedicated organisation space within the DRE, a network-secure workspace for organisation-specific secure data storage, and a Flower SuperNode, in the same workspace and ready to take part in federated learning runs. Each workspace provides everything required to run the network out of the box, with no need for virtual machine configuration.

Flower on the Aridhia DRE — network architecture diagram showing SuperLink and SuperNode workspaces

 

Orchestration can be configured in two ways: via Flower's managed SuperGrid platform, for federations that span multiple independent deployments, or via a SuperLink deployed within the DRE hub itself, administered from a dedicated orchestration workspace.

 

Deployment timeline

Combining Aridhia's pre-built, pre-accredited infrastructure with Flower's standardised components compresses deployment considerably: a process that historically takes several months can now be done in hours. Certification, network isolation, and governance workflows are already in place, so the remaining work is provisioning organisation spaces and configuring SuperNodes for each site, rather than building infrastructure and accreditation from scratch.

Why this matters for adoption

The reduction in deployment time reflects a reduction in the underlying barriers organisations face when standing up a federated network:

  • Trust and security. Infosec teams do not have the time to independently evaluate every new tool a research team wants to use, so they rely on established accreditation. Because the DRE is already ISO 27001/27701 certified and independently penetration-tested, a Flower deployment within it inherits that accreditation rather than needing to establish it separately.
  • Bureaucracy. Central IT and governance processes remain important for regulated data, but where the infrastructure and its accreditation already exist, there is less for central teams to review from scratch. Therefore organisations with delegated authority over their own accredited DRE environment can move more quickly.

Getting started

Aridhia has demonstrated the ability to deliver Flower-enabled federated learning networks as an out-of-the-box feature of the DRE platform, including provisioning a multi-organisation DRE hub, configuring Flower SuperNodes for participating sites, establishing governance workflows for federated data access, and integrating with existing research data management systems.

Organisations interested in deploying federated learning infrastructure can contact us to find out more.