IP Library Granted Patent US 8,689,354
Granted Patent B2
US 8,689,354 · App. 12/797,165 · Granted Apr 1, 2014

Method and apparatus for accessing secure data in a dispersed storage system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,689,354
App. No.
12/797,165
Granted
Apr 1, 2014
Kind
B2
Abstract

A method begins by a processing module receiving, from a user device, a request to access secure data, wherein the request includes a user identification code and at least one object name for the secure data. The method continues with the processing module processing the request to determine a security level associated with the user device and to determine security parameters associated with the secure data. The method continues with the processing module determining a level of access to the secure data based on the security level associated with the user device and the security parameters. The method continues with the processing module retrieving a set of encoded data slices from dispersed storage units, wherein the set of encoded data slices includes less than a reconstruction threshold number of encoded data slices and generating a response that includes the set of encoded data slices when the level of access is a partial access level.

Claims (32)

1. A method for a computing device to securely access dispersedly stored data, the method comprises:

generating, by a processor of the computing device, a request to access secure data, wherein the request includes a user identification code (ID) and at least one object name for the secure data and wherein the secure data includes one or more of: financial account information, user password information, security credential information, and personal data;

transmitting the request to a first dispersed storage network (DSN) access portal;

receiving, from the first DSN access portal, a first response that includes, for a data segment of the secure data, a first set of encoded data slices, wherein the first set of encoded data slices includes less than a reconstruction threshold number of encoded data slices, wherein the first response is based on security level associated with the user ID and security parameters of the secure data, and wherein the security parameters includes at least one of a secrecy level of data, an amount of data, encryption information regarding the data, codec information regarding the data, and error coding dispersal storage function parameters;

generating a second request to access the secure data in response to receiving the first response, wherein the second request includes the user ID and the at least one object name for the secure data;

transmitting the second request to a second DSN access portal;

receiving, from the second DSN access portal, a second response that includes, for the data segment of the secure data, a second set of encoded data slices, wherein the second set of encoded data slices includes less than the reconstruction threshold number of encoded data slices, wherein the second response is based on the security level associated with the user ID, the first response, and the security parameters of the secure data; and

when the first and second sets of encoded data slices include at least the reconstruction threshold number of encoded data slices, decoding the first and second sets of encoded data slices to reconstruct the data segment.

2. The method of claim 1 , wherein the second request further comprises a representation of the first response.

3. The method of claim 1 further comprises:

when the first and second sets of encoded data slices do not include at least the reconstruction threshold number of encoded data slices:

generating a third request to access the secure data in response to receiving the first response and the second response, wherein the third request includes the user ID and the at least one object name for the secure data;

transmitting the third request to a third DSN access portal;

receiving, from the third DSN access portal, a third response that includes, for the data segment of the secure data, a third set of encoded data slices, wherein the third set of encoded data slices includes less than the reconstruction threshold number of encoded data slices, wherein the third response is based on the security level associated with the user ID, the first response, the second response, and the security parameters of the secure data; and

when the first, second, and third sets of encoded data slices include at least the reconstruction threshold number of encoded data slices, decoding the first, second, and third sets of encoded data slices to reconstruct the data segment.

4. A computing device comprises:

an interface; and

a hardware processing module operable to:

generate a request to access secure data, wherein the request includes a user identification code (ID) and at least one object name for the secure data and wherein the secure data includes one or more of: financial account information, user password information, security credential information, and personal data;

transmit, via the interface, the request to a first dispersed storage network (DSN) access portal;

receive, from the first DSN access portal via the interface, a first response that includes, for a data segment of the secure data, a first set of encoded data slices, wherein the first set of encoded data slices includes less than a reconstruction threshold number of encoded data slices, and wherein the first response is based on security level associated with the user ID and security parameters of the secure data, and wherein the security parameters includes at least one of a secrecy level of data, an amount of data, encryption information regarding the data, codec information regarding the data, and error coding dispersal storage function parameters;

generate a second request to access the secure data in response to receiving the first response, wherein the second request includes the user ID and the at least one object name for the secure data;

transmit, via the interface, the second request to a second DSN access portal;

receive, from the second DSN access portal via the interface, a second response that includes, for the data segment of the secure data, a second set of encoded data slices, wherein the second set of encoded data slices includes less than the reconstruction threshold number of encoded data slices, wherein the second response is based on the security level associated with the user ID, the first response, and the security parameters of the secure data; and

when the first and second sets of encoded data slices include at least the reconstruction threshold number of encoded data slices, decode the first and second sets of encoded data slices to reconstruct the data segment.

5. The computing device of claim 4 , wherein the second request further comprises a representation of the first response.

6. The computing device of claim 4 , wherein the hardware processing module further functions to:

when the first and second sets of encoded data slices do not include at least the reconstruction threshold number of encoded data slices:

generate a third request to access the secure data in response to receiving the first response and the second response, wherein the third request includes the user ID and the at least one object name for the secure data;

transmit, via the interface, the third request to a third DSN access portal;

receive, from the third DSN access portal via the interface, a third response that includes, for the data segment of the secure data, a third set of encoded data slices, wherein the third set of encoded data slices includes less than the reconstruction threshold number of encoded data slices, wherein the third response is based on the security level associated with the user ID, the first response, the second response, and the security parameters of the secure data; and

when the first, second, and third sets of encoded data slices include at least the reconstruction threshold number of encoded data slices, decode the first, second, and third sets of encoded data slices to reconstruct the data segment.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038687/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2010
From: GRUBE, GARY W.; MARKISON, TIMOTHY W.
To: CLEVERSAFE, INC.
Reel/Frame 024511/0700 →