IP Library Granted Patent US 8,782,086
Granted Patent B2
US 8,782,086 · App. 12/759,703 · Granted Jul 15, 2014

Updating dispersed storage network access control information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,782,086
App. No.
12/759,703
Granted
Jul 15, 2014
Kind
B2
Abstract

In a dispersed storage network where slices of secure user data are stored on geographically separated storage units, a managing unit connected to the network may seek to broadcast and update secure access control list information across the network. Upon a target device receiving the broadcast the target device creates and sends an access control list change notification message to all other system devices that should have received the same broadcast if the broadcast is a valid request to update access control list information. The target device waits for responses from the other system devices to validate that the broadcast has been properly sent to a threshold number of other system devices before taking action to operationally change local data in accordance with the broadcast.

Claims (51)

1. A method comprises:

receiving, by each dispersed storage (DS) of a set of DS units of a distributed computing system, a corresponding one of a set of access requests regarding a set of error coded data slices, wherein a data segment is encoded using an error coding algorithm to produce the set of error coded data slices, wherein each DS unit of the set of DS units stores a corresponding error coded data slice of the set of error coded data slices, wherein the corresponding one of the set of access requests is regarding the corresponding error coded data slice of the set of error coded data slices;

determining, via a computing core of each DS unit of the set of DS units, whether a local access control list is fresh with respect to the corresponding encoded data slices of the set of encoded data slices, wherein the local access control list includes access permissions;

when, for one of the set of DS units, the local access control list is not fresh with respect to a corresponding one or more of the encoded data slices:

requesting, by the one of the set of DS units, a fresh access control list from a DS managing unit, wherein the DS managing unit maintains an access control list for the distributed computing system;

storing, by the one of the set of DS units, the fresh access control list as the local access control list;

verifying, by each of the DS units in the set of DS units, the corresponding one of the set of access requests in accordance with the access permissions of corresponding local access control lists; and

executing, by the computing core of each of the DS units in the set of DS units, the corresponding one of the set of access requests regarding the corresponding error coded data slice when the corresponding one of the set of access requests are verified.

2. The method of claim 1 wherein an access request of the set of access requests comprises one of:

a dispersed data write operation that instructs the DS unit to store the error coded data slice; and

a dispersed data read operation that instructs the DS unit to read and output the error coded data slice.

3. The method of claim 1 wherein the verifying the corresponding one of the set of access requests comprises:

sending, by the one of the set of DS units, an update notification to other DS units of the set of DS units regarding the fresh access control list;

utilizing, by the one of the set of DS units, responses from at least some of the other DS units of the set of units to verify the fresh access control list; and

utilizing, by one or more of the other DS units, the update notification regarding the fresh access control list to verify that a local DS unit access control list is correspondingly fresh.

4. The method of claim 1 , wherein the determining whether the local access control list is fresh comprises at least one of:

when a passage of time exceeds a threshold time since a last storage of the local access control list;

verifying a checksum corresponding to the local access control list;

verifying signatures; and

detecting setting of one or more dirty bits of the local access control list.

5. The method of claim 1 wherein the access permissions comprises:

a plurality of permissions in a permission list that indicates which valid users can perform which valid operations within a dispersed storage network.

6. The method of claim 1 wherein the requesting the fresh access control list comprises:

sending a permissions list request based on at least one of a signed certificate from a certificate authority and private key of the one of the set of DS units.

7. The method of claim 1 wherein the set of DS units comprises:

at least a read threshold number of DS units.

8. A dispersed storage (DS) unit of a set of DS units in a distributed computing system, the DS unit comprises:

a network interface;

memory; and

a processing module operable to:

receive, via the network interface, a corresponding one of a set of access requests regarding a corresponding one of a set of error coded data slices, wherein a data segment is encoded using an error coding algorithm to produce the set of error coded data slices, wherein each DS unit of the set of DS units stores a corresponding error coded data slice of the set of error coded data slices, wherein the corresponding one of the set of access requests is regarding the corresponding error coded data slice of the set of error coded data slices;

determine whether a local access control list is fresh with respect to the corresponding one of the set of error coded data slices, wherein the local access control list includes access permissions;

when, the local access control list is not fresh with respect to a corresponding one or more of the encoded data slices:

request a fresh access control list from a DS managing unit, wherein the DS managing unit maintains an access control list for the distributed computing system;

store the fresh access control list as the local access control list;

verify the corresponding one of the set of access requests in accordance with the access permissions of the local access control lists; and

execute the corresponding one of the set of access requests regarding the corresponding error coded data slice when the corresponding one of the set of access requests is verified.

9. The DS unit of claim 8 , wherein the corresponding one of the set of access requests comprises one of:

a dispersed data write operation that instructs the DS unit to store the corresponding one of the set of error coded data slices.

10. The DS unit of claim 8 , wherein the processing module is further operable to verify the corresponding one of the set of access requests by:

sending, via the network interface, an update notification to other DS units of the set of DS units regarding the fresh access control list; and

utilizing responses from at least some of the other DS units of the set of units to verify the fresh access control list.

11. The DS unit of claim 8 , wherein the processing module is further operable to determining whether the local access control list is fresh comprises at least one of:

when a passage of time exceeds a threshold time since a last storage of the local access control list;

verifying a checksum corresponding to the local access control list;

verifying signatures; and

detecting setting of one or more dirty bits of the local access control list.

12. The DS unit of claim 8 , wherein the access permissions comprises:

a plurality of permissions in a permission list that indicates which valid users can perform which valid operations within a dispersed storage network.

13. The DS unit of claim 8 , wherein the processing module is further operable to request the fresh access control list by:

sending a permissions list request based on at least one of a signed certificate from a certificate authority and private key of the DS unit.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038687/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2010
From: RESCH, JASON K.
To: CLEVERSAFE, INC.
Reel/Frame 024227/0499 →