IP Library Granted Patent US 9,244,770
Granted Patent B2
US 9,244,770 · App. 13/527,881 · Granted Jan 26, 2016

Responding to a maintenance free storage container security threat

Inventors: S. Christopher Gladwin (Chicago, IL); Jason K. Resch (Chicago, IL); Gary W. Grube (Barrington Hills, IL); Timothy W. Markison (Mesa, AZ)
Assignee: International Business Machines Corporation
G06F11/1084G06F11/1096G06F2211/1028
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,244,770
App. No.
13/527,881
Granted
Jan 26, 2016
Kind
B2
Abstract

A method for responding to a security threat for a maintenance free storage container begins by a dispersed storage (DS) processing module identifying a security threat for the maintenance free storage container, wherein the maintenance free storage container allows for multiple storage servers of a plurality of storage servers to be in a failure mode without replacement. The method continues with the DS processing module determining a failure mode level that is indicative of whether one or more of the multiple storage servers are in the failure mode. The method continues with the DS processing module selecting a security threat countermeasure based on the security threat and the failure mode level. The method continues with the DS processing module implementing the security threat countermeasure.

Claims (63)

1. A method for responding to a security threat for a maintenance free storage container, the method comprises:

identifying a security threat for the maintenance free storage container, wherein the maintenance free storage container allows for multiple storage servers of a plurality of storage servers to be in a failure mode without replacement, wherein a set of the storage servers of the plurality of storage servers stores a set of encoded data slices, wherein a data segment of a data object is dispersed storage error encoded to produce the set of encoded data slices, wherein the data segment is recoverable from a decode threshold number of encoded data slices of the set of encoded data slices, and wherein the security threat is regarding integrity of data stored within the maintenance free storage container;

determining a failure mode level that is indicative of whether one or more of the multiple storage servers are in the failure mode;

selecting a security threat countermeasure based on the security threat and the failure mode level; and

implementing the security threat countermeasure.

2. The method of claim 1 , wherein the determining the failure mode level of the maintenance free storage container comprises at least one of:

determining that one or more storage locations within a first storage server of the plurality of storage servers has failed;

determining that a second storage server of the plurality of storage servers has failed;

determining that a third storage server of the plurality of storage servers is operating at less than a desired storage level but greater than a storage failure level; and

identifying one or more failure impacted storage vaults associated with at least one of the first storage server, the second storage server, and the third storage server.

3. The method of claim 2 , wherein the selecting the security threat countermeasure further comprises:

deleting a selected number of encoded data slices for one or more sets of encoded data slices of a plurality of sets of encoded data slices corresponding to a storage vault in accordance with the failure mode level of the maintenance free storage container and the one or more failure impacted storage vaults.

4. The method of claim 1 further comprises:

indicating a physical security threat type when detecting a physical anomaly condition of the maintenance free storage container; and

selecting a physical security threat type countermeasure.

5. The method of claim 4 , wherein the physical security threat type countermeasure comprises one of:

migrating at least some data stored in the plurality of storage servers to another maintenance free storage container;

deleting one or more encryption keys utilized to access the data;

deleting at least some of the data stored in the plurality of storage servers; and

deactivating one or more storage servers of the plurality of storage servers.

6. The method of claim 1 further comprises:

indicating a data access security threat type when detecting unauthorized access of data from one or more storage servers of the plurality of storage servers; and

selecting a data access security threat type countermeasure.

7. The method of claim 6 , wherein the data access security threat type countermeasure comprises one or more of:

randomly accessing the data to produce a pseudorandom electromagnetic pattern;

outputting random data in response to a data request from a requesting entity associated with a threat pattern;

migrating at least some data stored in the plurality of storage servers to another maintenance free storage container;

deleting one or more encryption keys utilized to access the data;

deleting at least some of the data stored in the plurality of storage servers; and

deactivating one or more storage servers of the plurality of storage servers.

8. A dispersed storage (DS) module comprises:

a first module, when operable within a computing device, causes the computing device to:

identify a security threat for a maintenance free storage container, wherein the maintenance free storage container allows for multiple storage servers of a plurality of storage servers to be in a failure mode without replacement, wherein a set of the storage servers of the plurality of storage servers stores a set of encoded data slices, wherein a data segment of a data object is dispersed storage error encoded to produce the set of encoded data slices, wherein the data segment is recoverable from a decode threshold number of encoded data slices of the set of encoded data slices, and wherein the security threat is regarding integrity of data stored within the maintenance free storage container;

a second module, when operable within the computing device, causes the computing device to:

determine a failure mode level that is indicative of whether one or more of the multiple storage servers are in the failure mode; and

a third module, when operable within the computing device, causes the computing device to:

select a security threat countermeasure based on the security threat and the failure mode level; and

implement the security threat countermeasure.

9. The DS module of claim 8 , wherein the second module functions to determine the failure mode level of the maintenance free storage container by least one of:

determining that one or more storage locations within a first storage server of the plurality of storage servers has failed;

determining that a second storage server of the plurality of storage servers has failed;

determining that a third storage server of the plurality of storage servers is operating at less than a desired storage level but greater than a storage failure level; and

identifying one or more failure impacted storage vaults associated with at least one of the first storage server, the second storage server, and the third storage server.

10. The DS module of claim 9 , wherein the third module further functions to select the security threat countermeasure by:

deleting a selected number of encoded data slices for one or more sets of encoded data slices of a plurality of sets of encoded data slices corresponding to a storage vault in accordance with the failure mode level of the maintenance free storage container and the one or more failure impacted storage vaults.

11. The DS module of claim 8 further comprises:

the first module further functions to indicate a physical security threat type when detecting a physical anomaly condition of the maintenance free storage container; and

the third module further functions to select a physical security threat type countermeasure.

12. The DS module of claim 11 , wherein the physical security threat type countermeasure comprises one of:

migrating at least some data stored in the plurality of storage servers to another maintenance free storage container;

deleting one or more encryption keys utilized to access the data;

deleting at least some of the data stored in the plurality of storage servers; and

deactivating one or more storage servers of the plurality of storage servers.

13. The DS module of claim 8 further comprises:

the first module further functions to indicate a data access security threat type when detecting unauthorized access of data from one or more storage servers of the plurality of storage servers; and

the third module further functions to select a data access security threat type countermeasure.

14. The DS module of claim 13 , wherein the data access security threat type countermeasure comprises one or more of:

randomly accessing the data to produce a pseudorandom electromagnetic pattern;

outputting random data in response to a data request from a requesting entity associated with a threat pattern;

migrating at least some data stored in the plurality of storage servers to another maintenance free storage container;

deleting one or more encryption keys utilized to access the data;

deleting at least some of the data stored in the plurality of storage servers; and

deactivating one or more storage servers of the plurality of storage servers.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038687/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2012
From: GLADWIN, S. CHRISTOPHER; RESCH, JASON K.; GRUBE, GARY W.; MARKISON, TIMOTHY W.
To: CLEVERSAFE, INC.
Reel/Frame 028777/0608 →
Continuity (2)
Provisional Application 61505010 · Jul 6, 2011
Related Publication 20130014254A1 · Jan 10, 2013