IP Library Granted Patent US 8,656,187
Granted Patent B2
US 8,656,187 · App. 12/547,753 · Granted Feb 18, 2014

Dispersed storage secure data decoding

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,656,187
App. No.
12/547,753
Granted
Feb 18, 2014
Kind
B2
Abstract

A method operating on a computer begins by generating a read command to read at least some of a plurality of data slices from a dispersed storage network. The method continues by receiving the at least some of the plurality of data slices. The method continues by performing a reverse information dispersal algorithm on at least some of the plurality of data slices to produce a plurality of transposed data elements. The method continues by reverse transposing the plurality of transposed data elements to recover data elements of a data segment.

Claims (30)

1. A method operating on a computer and comprising the steps of:

generating, by a processor of the computer, a read command to read at least some of a plurality of data slices from a dispersed storage network;

de-slicing, by the processor, the at least some of the plurality of data slices using a reverse information dispersal algorithm to produce an all-or-nothing encrypted data segment; and

applying, by the processor, a reverse all-or-nothing transformation on the all-or-nothing encrypted data segment to recover a data segment, wherein the reverse all-or-nothing transformation includes:

retrieving an obfuscated encryption key and an encrypted data segment from the all-or-nothing encrypted data segment;

calculating a digest from the encrypted data segment;

recovering the encryption key from the obfuscated encryption key based on the digest; and

decrypting the encrypted data segment based on the encryption key to produce the data segment.

2. The method of claim 1 wherein the recovering the encryption key from the obfuscated encryption key based on the digest comprises:

exclusive-ORing the obfuscated encryption key and the digest to produce the encryption key.

3. The method of claim 1 further comprises:

decrypting, by the processor, the all-or-nothing encrypted data segment using a first block cipher prior to the applying the reverse all-or-nothing transformation.

4. The method of claim 1 , wherein the calculating the digest from the encrypted data segment comprises:

performing a hash function on the encrypted data segment to produce the digest.

5. A computer comprising:

a network port adapted to couple with a network and receive at least some of a plurality of data slices; and

a processor coupled to said network port wherein said processor:

receives the at least some of a plurality of data slices from the network port;

de-slices the at least some of the plurality of data slices using a reverse information dispersal algorithm to produce an all-or-nothing encrypted data segment; and

applies a reverse all-or-nothing transformation on the all-or-nothing encrypted data segment to recover a data segment, wherein the reverse all-or-nothing transformation includes:

retrieving an obfuscated encryption key and an encrypted data segment from the all-or-nothing encrypted data segment;

calculating a digest from the encrypted data segment;

recovering the encryption key from the obfuscated encryption key based on the digest; and

decrypting the encrypted data segment based on the encryption key to produce the data segment.

6. The computer of claim 5 , wherein the processor further functions to recover the encryption key from the obfuscated encryption key based on the digest by:

exclusive-ORing the obfuscated encryption key and the digest to produce the encryption key.

7. The computer of claim 5 , wherein the processor further functions to:

decrypt the all-or-nothing encrypted data segment using a first block cipher prior to the applying the reverse all-or-nothing transformation.

8. The computer of claim 5 , wherein the processor further functions to calculate the digest from the encrypted data segment by:

performing a hash function on the encrypted data segment to produce the digest.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038687/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2009
From: LEGGETTE, WESLEY; RESCH, JASON K.
To: CLEVERSAFE, INC.
Reel/Frame 023147/0191 →