IP Library Granted Patent US 8,683,231
Granted Patent B2
US 8,683,231 · App. 13/309,432 · Granted Mar 25, 2014

Obfuscating data stored in a dispersed storage network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,683,231
App. No.
13/309,432
Granted
Mar 25, 2014
Kind
B2
Abstract

A method begins by a processing module dispersed storage error encoding secret data in accordance with first dispersed storage error encoding parameters to produce at least one set of encoded secret slices and dispersed storage error encoding data in accordance with second dispersed storage error encoding parameters to produce a plurality of sets of encoded data slices. The method continues with the processing module determining an inter-dispersing function for outputting the sets of encoded secret slices and the plurality of sets of encoded data slices, and for a set of the plurality of encoded data slices: identifying at least one encoded data slice of the set of encoded data slices based on the inter-dispersing function, replacing the at least one encoded data slice with at least one encoded secret slice to produce a mixed set of encoded slices, and outputting the mixed set of encoded slices.

Claims (91)

1. A method for execution by a computing device, the method comprises:

dispersed storage error encoding secret data in accordance with first dispersed storage error encoding parameters to produce at least one set of encoded secret slices;

dispersed storage error encoding data in accordance with second dispersed storage error encoding parameters to produce a plurality of sets of encoded data slices;

determining an inter-dispersing function for outputting the sets of encoded secret slices and the plurality of sets of encoded data slices, wherein the determining the inter-dispersing function including:

identifying a first decode threshold and a first pillar width based on the first dispersed storage error encoding parameters; and

identifying a second decode threshold and a second pillar width based on the second dispersed storage error encoding parameters, wherein the first decode threshold is less than or equal to a difference between the second pillar width and the second decode threshold; and

for a set of the plurality of encoded data slices:

identifying at least one encoded data slice of the set of encoded data slices based on the inter-dispersing function, wherein the identifying the at least one encoded data slice including identifying a number of encoded data slices of the set of encoded data slices as the at least one encoded data slice to be equal to or greater than the first decode threshold;

replacing the at least one encoded data slice with at least one encoded secret slice of the at least one set of encoded secret slices to produce a mixed set of encoded slices, wherein the replacing the at least one encoded data slice including replacing the number of encoded data slices with at least a first decode threshold number of encoded secret slices of a set of the least one set of encoded secret slices; and

outputting the mixed set of encoded slices.

2. The method of claim 1 further comprises:

the replacing the at least one encoded data slice with the at least one encoded secret slice including:

generating a slice name for an encoded data slice of the at least one encoded data slice; and

assigning the slice name to an encoded secret slice of the at least one encoded secret slice; and

the outputting the mixed set of encoded slices including:

outputting the encoded secret slice using the slice name of the encoded data slice.

3. The method of claim 1 further comprises:

the secret data relating to information regarding the data.

4. The method of claim 1 further comprises:

the secret data contains information that is unrelated to the data.

5. The method of claim 1 , wherein the outputting the set of mixed slices comprises:

updating a directory regarding a set of slice names corresponding to the mixed set of encoded slices.

6. A method for execution by a computing device, the method comprises:

dispersed storage error encoding secret data in accordance with first dispersed storage error encoding parameters to produce at least one set of encoded secret slices;

dispersed storage error encoding data in accordance with second dispersed storage error encoding parameters to produce a plurality of sets of encoded data slices;

determining an inter-dispersing function for outputting the sets of encoded secret slices and the plurality of sets of encoded data slices, wherein the determining the inter-dispersing function including identifying a first decode threshold and a first pillar width based on the first dispersed storage error encoding parameters;

for a set of the plurality of encoded data slices:

identifying at least one encoded data slice of the set of encoded data slices based on the inter-dispersing function, wherein the identifying the at least one encoded data slice including identifying a number of encoded data slices of the set of encoded data slices as the at least one encoded data slice to be less than the first decode threshold;

replacing the at least one encoded data slice with at least one encoded secret slice of the at least one set of encoded secret slices to produce a mixed set of encoded slices, wherein the replacing the at least one encoded data slice including replacing the number of encoded data slices with less than a first decode threshold number of encoded secret slices of a set of the least one set of encoded secret slices; and

for a second set of the plurality of encoded data slices:

identifying a second number of encoded data slices of the second set of encoded data slices to be less than the first decode threshold; and

replacing the second number of encoded data slices with at least one other encoded secret slice of the set of the least one set of encoded secret slices

outputting the mixed set of encoded slices.

7. The method of claim 6 further comprises:

the replacing the at least one encoded data slice with the at least one encoded secret slice including:

generating a slice name for an encoded data slice of the at least one encoded data slice; and

assigning the slice name to an encoded secret slice of the at least one encoded secret slice; and

the outputting the mixed set of encoded slices including:

outputting the encoded secret slice using the slice name of the encoded data slice.

8. The method of claim 6 further comprises:

the secret data relating to information regarding the data.

9. The method of claim 6 further comprises:

the secret data contains information that is unrelated to the data.

10. The method of claim 6 , wherein the outputting the set of mixed slices comprises:

updating a directory regarding a set of slice names corresponding to the mixed set of encoded slices.

11. A dispersed storage (DS) module comprises:

a first module for dispersed storage error encoding secret data in accordance with first dispersed storage error encoding parameters to produce at least one set of encoded secret slices;

a second module for dispersed storage error encoding data in accordance with second dispersed storage error encoding parameters to produce a plurality of sets of encoded data slices;

a third module for determining an inter-dispersing function for outputting the sets of encoded secret slices and the plurality of sets of encoded data slices, wherein the determining the inter-dispersing function includes:

identifying a first decode threshold and a first pillar width based on the first dispersed storage error encoding parameters; and

identifying a second decode threshold and a second pillar width based on the second dispersed storage error encoding parameters, wherein the first decode threshold is less than or equal to a difference between the second pillar width and the second decode threshold; and

for a set of the plurality of encoded data slices:

a fourth module for:

identifying at least one encoded data slice of the set of encoded data slices based on the inter-dispersing function, wherein the identifying the at least one encoded data slice includes identifying a number of encoded data slices of the set of encoded data slices as the at least one encoded data slice to be equal to or greater than the first decode threshold; and

replacing the at least one encoded data slice with at least one encoded secret slice of the at least one set of encoded secret slices to produce a mixed set of encoded slices, wherein the replacing the at least one encoded data slice includes replacing the number of encoded data slices with at least a first decode threshold number of encoded secret slices of a set of the least one set of encoded secret slices; and

a fifth module for facilitating outputting the mixed set of encoded slices.

12. The DS module of claim 11 further comprises:

the fourth module replaces the at least one encoded data slice with the at least one encoded secret slice by:

generating a slice name for an encoded data slice of the at least one encoded data slice; and

assigning the slice name to an encoded secret slice of the at least one encoded secret slice; and

the fifth module outputs the mixed set of encoded slices by:

outputting the encoded secret slice using the slice name of the encoded data slice.

13. The DS module of claim 11 further comprises:

the secret data relating to information regarding the data.

14. The DS module of claim 11 further comprises:

the secret data contains information that is unrelated to the data.

15. The DS module of claim 11 , wherein the fifth module outputs the set of mixed slices by:

updating a directory regarding a set of slice names corresponding to the mixed set of encoded slices.

16. A dispersed storage (DS) module comprises:

a first module for dispersed storage error encoding secret data in accordance with first dispersed storage error encoding parameters to produce at least one set of encoded secret slices;

a second module for dispersed storage error encoding data in accordance with second dispersed storage error encoding parameters to produce a plurality of sets of encoded data slices;

a third module for determining an inter-dispersing function for outputting the sets of encoded secret slices and the plurality of sets of encoded data slices, wherein the determining the inter-dispersing function includes identifying a first decode threshold and a first pillar width based on the first dispersed storage error encoding parameters;

for a set of the plurality of encoded data slices:

a fourth module for:

identifying at least one encoded data slice of the set of encoded data slices based on the inter-dispersing function, wherein the identifying the at least one encoded data slice includes identifying a number of encoded data slices of the set of encoded data slices as the at least one encoded data slice to be less than the first decode threshold; and

replacing the at least one encoded data slice with at least one encoded secret slice of the at least one set of encoded secret slices to produce a mixed set of encoded slices, wherein the replacing the at least one encoded data slice includes replacing the number of encoded data slices with less than a first decode threshold number of encoded secret slices of a set of the least one set of encoded secret slices; and

for a second set of the plurality of encoded data slices:

the fourth module identifies a second number of encoded data slices of the second set of encoded data slices to be less than the first decode threshold; and

the fourth module replaces the second number of encoded data slices with at least one other encoded secret slice of the set of the least one set of encoded secret slices a fifth module for facilitating outputting the mixed set of encoded slices.

17. The DS module of claim 16 further comprises:

the fourth module replaces the at least one encoded data slice with the at least one encoded secret slice by:

generating a slice name for an encoded data slice of the at least one encoded data slice; and

assigning the slice name to an encoded secret slice of the at least one encoded secret slice; and

the fifth module outputs the mixed set of encoded slices by:

outputting the encoded secret slice using the slice name of the encoded data slice.

18. The DS module of claim 16 further comprises:

the secret data relating to information regarding the data.

19. The DS module of claim 16 further comprises:

the secret data contains information that is unrelated to the data.

20. The DS module of claim 16 , wherein the fifth module outputs the set of mixed slices by:

updating a directory regarding a set of slice names corresponding to the mixed set of encoded slices.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038687/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2011
From: GRUBE, GARY W.; MARKISON, TIMOTHY W.
To: CLEVERSAFE, INC.
Reel/Frame 027376/0299 →