IP Library Granted Patent US 9,086,994
Granted Patent B2
US 9,086,994 · App. 14/051,588 · Granted Jul 21, 2015

Verification of dispersed storage network access control information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,086,994
App. No.
14/051,588
Granted
Jul 21, 2015
Kind
B2
Abstract

A method for securely publishing an access control list begins with a DS managing unit generating an authentic and time-stamped access control list from the access control list, wherein the access control list provides a list of authorized accesses to the DSN. The method continues with the DS managing unit sending the authentic and time-stamped access control list to a publisher unit. The method continues with the publishing unit sending the authentic and time-stamped access control list to a plurality of DS units.

Claims (45)

1. A method for securely publishing an access control list, the method comprises:

generating, by a dispersed storage (DS) managing unit of a dispersed storage network (DSN), an authentic and time-stamped access control list from the access control list, wherein the access control list provides a list of authorized accesses to the DSN, and wherein the authentic and time-stamped access control list includes a signature of the DS managing unit and a time-stamp value;

sending, by the DS managing unit, the authentic and time-stamped access control list to a publisher unit; and

sending, by the publisher unit, the authentic and time-stamped access control list to a plurality of DS units.

2. The method of claim 1 , wherein the generating the authentic and time-stamped access control list comprises:

generating the time-stamp value;

combining the time-stamp value with the access control list to produce a time-stamped access control list;

generating the signature based on the time-stamped access control list and a private key of the DS managing unit; and

combining the signature with the time-stamped access control list to produce the authentic and time-stamped access control list.

3. The method of claim 1 further comprises:

identifying, by the DS managing unit, the publisher unit based on the identity of the plurality of DS units, wherein the publisher unit is affiliated with the plurality of DS units.

4. The method of claim 1 further comprises:

receiving, by one of the plurality of DS units, the authentic and time-stamped access control list;

parsing, by the one of the plurality of DS units, the authentic and time-stamped access control list to produce a signature and a time-stamped access control list;

validating, by the one of the plurality of DS units, the signature based on a public key of the DS managing unit;

when the signature is validated, extracting, by the one of the plurality of DS units, a time-stamp value and the access control list from the time-stamped access control list; and

storing, by the one of the plurality of DS units, the access control list.

5. The method of claim 1 , wherein the access control list comprises at least one of:

a list of users allowed to access the DSN;

a list of user transactions allowed on the DSN;

a list of users allowed to access one or more vaults of the DSN; and

a list of user transactions allowed on the one or more vaults of the DSN.

6. A computer readable storage device comprises:

a first storage section that stores first operational instructions, that when executed by a dispersed storage (DS) managing unit of a dispersed storage network (DSN) causes the DS managing unit to generate an authentic and time-stamped access control list from the access control list, wherein the access control list provides a list of authorized accesses to the DSN, and wherein the authentic and time-stamped access control list includes a signature of the DS managing unit and a time-stamp value;

a second storage section that stores second operational instructions, that when executed by the DS managing unit, causes the DS managing unit to send the authentic and time-stamped access control list to a publisher unit; and

a third storage section that stores third operational instructions, that when executed by the publishing unit, causes the publishing unit to send the authentic and time-stamped access control list to a plurality of DS units.

7. The computer readable storage device of claim 6 , wherein the first operational instructions for generating the authentic and time-stamped access control list further include instructions for:

generating the time-stamp value;

combining the time-stamp value with the access control list to produce a time-stamped access control list;

generating the signature based on the time-stamped access control list and a private key of the DS managing unit; and

combining the signature with the time-stamped access control list to produce the authentic and time-stamped access control list.

8. The computer readable storage device of claim 6 further comprises:

a fourth storage section that stores fourth operational instructions, that when executed by the DS managing unit, causes the DS managing unit to identify the publisher unit based on the identity of the plurality of DS units, wherein the publisher unit is affiliated with the plurality of DS units.

9. The computer readable storage device of claim 6 further comprises:

a fourth storage section that stores fourth operational instructions, that when executed by one of the plurality of DS units, causes the one of the plurality of DS units to:

receive the authentic and time-stamped access control list;

parse the authentic and time-stamped access control list to produce a signature and a time-stamped access control list;

validate the signature based on a public key of the DS managing unit;

when the signature is validated, extract a time-stamp value and the access control list from the time-stamped access control list; and

store the access control list.

10. The computer readable storage device of claim 6 , wherein the access control list comprises at least one of:

a list of users allowed to access the DSN;

a list of user transactions allowed on the DSN;

a list of users allowed to access one or more vaults of the DSN; and

a list of user transactions allowed on the one or more vaults of the DSN.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038687/0596 →