IP Library Granted Patent US 8,990,585
Granted Patent B2
US 8,990,585 · App. 12/886,368 · Granted Mar 24, 2015

Time based dispersed storage access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,990,585
App. No.
12/886,368
Granted
Mar 24, 2015
Kind
B2
Abstract

A method begins with a processing module receiving a data retrieval request and obtaining a real-time indicator corresponding to when the data retrieval request was received. The method continues with the processing module determining a time-based data access policy based on the data retrieval request and the real-time indicator and accessing a plurality of dispersed storage (DS) units in accordance with the time-based data access policy to retrieve encoded data slices. The method continues with the processing module decoding the threshold number of encoded data slices in accordance with an error coding dispersal storage function when a threshold number of the encoded data slices have been retrieved.

Claims (80)

1. A method comprises:

receiving a data retrieval request to retrieve data, wherein the data is segmented into a plurality of data segments and respective data segments are encoded into a plurality of encoded data slices and stored in different dispersed storage (DS) units of a plurality of DS units of a dispersed storage network, in which respective numbered slices of the plurality of data segments are stored in a same DS unit of the plurality of DS units, and wherein only a threshold number of encoded data slices for a particular data segment are needed to recover the particular data segment;

determining based on an access policy which of the plurality of DS units storing the encoded data slices of the data segments are available for access to retrieve the encoded data slices for day and time corresponding to the data retrieval request;

determining if a requestor or a requesting device requesting the data retrieval has authorized access to the plurality of DS units;

accessing available DS units to retrieve the encoded data slices from the available DS units based on the access policy, provided the requestor or requesting device requesting the data retrieval has the authorized access; and

retrieving a threshold number of encoded data slices from the available DS units for each of the data segments to recover the data.

2. The method of claim 1 , wherein the accessing the available DS units comprises:

identifying a first set of DS units of the plurality of DS units that are accessible during a first time interval in accordance with the access policy; and

identifying a second set of DS units of the plurality of DS units that are accessible during a second time interval in accordance with the access policy, wherein a number of DS units in each of the first and second sets of DS units is less than the threshold number of encoded data slices.

3. The method of claim 1 further comprises:

when the threshold number of encoded data slices for the respective data segments are not accessible for retrieval, generating a status message in accordance with the access policy.

4. The method of claim 1 , wherein the determining based on the access policy is based on one or more of:

a previous time-based data access policy;

a policy schedule;

a data identifier;

a real-time indicator;

a requester identifier;

a data type;

a priority indicator;

a security indicator; and

a dispersed storage network (DSN) status indicator.

5. The method of claim 1 , wherein the determining based on the access policy further comprises:

adjusting the access policy based on priority of the requesting device issuing the data retrieval request.

6. The method of claim 1 , wherein the determining based on the access policy comprises:

extracting the access policy from the data retrieval request when priority of the requesting device issuing the data retrieval request is at a first priority level.

7. A method comprises:

receiving a data write request to store data from a requesting device;

segmenting the data into a plurality of data segments;

encoding respective data segments in accordance with an error coding dispersal storage function to generate a plurality of encoded data slices for storage in different dispersed storage (DS) units of a plurality of DS units of a dispersed storage network, in which respective numbered slices of the plurality of data segments are to be stored in a same DS unit of the plurality of DS units, and wherein only a threshold number of encoded data slices for a particular data segment are needed to recover the particular data segment;

identifying based on an access policy which of the plurality of DS units for storing the encoded data slices of the data segments are available for access to store the encoded data slices for day and time corresponding to storing the encoded data slices

outputting the encoded data slices to the available DS units in accordance with the access policy.

8. The method of claim 7 further comprises:

identifying the available DS units based on a privilege set for the requesting device.

9. The method of claim 7 , wherein the identifying the available DS units based on the access policy comprises:

obtaining a real-time indicator corresponding to when the data write request was received; and

using the access policy based on the real-time indicator.

10. The method of claim 7 , wherein the identifying the available DS units comprises:

identifying a priority level of the requesting device.

11. A computer comprises:

an interface; and

a processing module operable to:

receive, via the interface, a data retrieval request to retrieve data, wherein the data is segmented into a plurality of data segments and respective data segments are encoded into a plurality of encoded data slices and stored in different dispersed storage (DS) units of a plurality of DS units of a dispersed storage network, in which respective numbered slices of the plurality of data segments are stored in a same DS unit of the plurality of DS units, and wherein only a threshold number of encoded data slices for a particular data segment are needed to recover the particular data segment;

determine based on an access policy which of the plurality of DS units storing the encoded data slices of the data segments are available for access to retrieve the encoded data slices for day and time corresponding to the data retrieval request;

determine if a requestor or a requesting device requesting the data retrieval has authorized access to the plurality of DS units;

access, via the interface, available DS units to retrieve the encoded data slices from the available DS units based on the access policy, provided the requestor or requesting device requesting the data retrieval has the authorized access; and

decode a threshold number of encoded data slices from the available DS units for each of the data segments to recover the data.

12. The computer of claim 11 , wherein the processing module further functions to access the available DS units by:

identifying a first set of DS units of the plurality of DS units that are accessible during a first time interval in accordance with the access policy; and

identifying a second set of DS units of the plurality of DS units that are accessible during a second time interval in accordance with the access policy, wherein a number of DS units in each of the first and second sets of DS units is less than the threshold number of encoded data slices.

13. The computer of claim 11 , wherein the processing module further functions to:

generate a status message in accordance with the access policy when the threshold number of encoded data slices for the respective data segments are not accessible for retrieval.

14. The computer of claim 11 , wherein the processing module further functions to determine based on the access policy, which is based on one or more of:

a previous time-based data access policy;

a policy schedule;

a data identifier;

a real-time indicator;

a requester identifier;

a data type;

a priority indicator;

a security indicator; and

a dispersed storage network (DSN) status indicator.

15. The computer of claim 11 , wherein the processing module further functions to determine based on the access policy by:

adjusting the access policy based on priority of the requesting device issuing the data retrieval request.

16. The computer of claim 11 , wherein the processing module further functions to determine based on the access policy by:

extracting the access policy from the data retrieval request when priority of the requesting device issuing the data retrieval request is at a first priority level.

17. A computer comprises:

an interface; and

a processing module operable to:

receive, via the interface, a data write request to store data from a requesting device

segment the data into a plurality of data segments;

encode respective data segments in accordance with an error coding dispersal storage function to generate a plurality of encoded data slices for storage in different dispersed storage (DS) units of a plurality of DS units of a dispersed storage network, in which respective numbered slices of the plurality of data segments are to be stored in a same DS unit of the plurality of DS units, and wherein only a threshold number of encoded data slices for a particular data segment are needed to recover the particular data segment;

identify based on an access policy which of the plurality of DS units for storing the encoded data slices of the data segments are available for access to store the encoded data slices for day and time corresponding to storing the encoded data slices

output, via the interface, the encoded data slices to the available DS units in accordance with the access policy.

18. The computer of claim 17 , wherein the processing module further functions to:

identify the DS units based on a privilege set for the requesting device.

19. The computer of claim 17 , wherein the processing module further functions to identify the available DS units based on the access policy by:

obtaining a real-time indicator corresponding to when the data write request was received; and

using the access policy based on the real-time indicator.

20. The computer of claim 17 , wherein the processing module further functions to identify the available DS units by:

identifying a priority level of the requesting device.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038687/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2011
From: GRUBE, GARY W.; MARKISON, TIMOTHY W.
To: CLEVERSAFE, INC.
Reel/Frame 025794/0063 →