IP Library Granted Patent US 9,443,099
Granted Patent B2
US 9,443,099 · App. 14/230,169 · Granted Sep 13, 2016

Method and apparatus for accessing secure data in a dispersed storage system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,443,099
App. No.
14/230,169
Granted
Sep 13, 2016
Kind
B2
Abstract

A method begins with a first computing device receiving a first request from a user device to access secure data. The method continues with the first computing device processing the first request to determine a level of access. When the level of access is acceptable, the method continues with the first computing device facilitating sending a set of encoded data slices to the user device. The method continues with a second computing device receiving a second request from the user device. The method continues with the second computing device processing the second request to determine the level of access. When the level of access is acceptable, the method continues with the second computing device facilitating sending a second set of encoded data slices to the user device. When the level of access is at a given level, the sets include a reconstruction threshold number of encoded data slices.

Claims (80)

1. A method comprises:

receiving, by a first computing device, a first request from a user device to access secure data, wherein the first request includes a user identification code (ID) and at least one object name for the secure data;

processing, by the first computing device, the first request to determine a level of access to the secure data for the user device;

when the level of access is of an acceptable level, facilitating, by the first computing device, sending a set of encoded data slices to the user device, wherein the set of encoded data slices includes less than a reconstruction threshold number of encoded data slices to reconstruct at least a segment of the secure data;

receiving, by a second computing device, a second request from the user device to access the secure data, wherein the second request includes the user ID, the at least one object name for the secure data, and a representation of the first request;

processing, by the second computing device, the second request to determine the level of access to the secure data for the user device; and

when the level of access is of the acceptable level, facilitating, by the second computing device, sending a second set of encoded data slices to the user device, wherein the second set of encoded data slices includes less than the reconstruction threshold number of encoded data slices and wherein, when the level of access is at a given level, the set of encoded data slices and the second set of encoded data slices includes at least the reconstruction threshold number of encoded data slices.

2. The method of claim 1 , wherein the processing the first request comprises:

determining a security level associated with the user device; and

determining security parameters associated with the secure data, wherein the first computing device determines the level of access to the secure data based on the security level associated with the user device and the security parameters.

3. The method of claim 1 , wherein the facilitating the sending of the set of encoded data slices to the user device comprises:

when the acceptable level is a partial access level:

retrieving the set of encoded data slices from dispersed storage units;

generating a response that includes the set of encoded data slices; and

sending the response to the user device.

4. The method of claim 1 , wherein the processing the first request further comprises:

communicating with a dispersed storage (DS) managing unit regarding a security level associated with the user device; and

communicating with the dispersed storage (DS) managing unit regarding security parameters associated with the secure data, wherein the first computing device determines the level of access to the secure data based on the security level associated with the user device and the security parameters.

5. The method of claim 1 , wherein the processing the first request comprises:

determining whether the first request includes a representation of a response from another computing device;

when the first request does not include the representation, determining whether the first request is an initial request for the secure data by the user device; and

when the first request is not the initial request, determining that the level of access is not acceptable for facilitating sending of the set of encoded data slices.

6. The method of claim 1 , wherein the processing the first request comprises:

determining a number of encoded data slices to include in the set of encoded data slices based on a variable function of security parameters and a security level associated with the user ID, wherein the security parameters includes at least one of: a secrecy level of data, an amount of data, codec information regarding the data, and error coding dispersal storage function parameters.

7. The method of claim 1 , wherein the processing the second request comprises:

determining a security level associated with the user device;

determining security parameters associated with the secure data;

verifying the representation of the first request; and

when the representation of the first request is verified, determining the level of access to the secure data based on the security level associated with the user device and the security parameters.

8. The method of claim 1 , wherein the facilitating the sending of the second set of encoded data slices to the user device comprises:

when the acceptable level is a partial access level:

retrieving the second set of encoded data slices from dispersed storage units;

generating a response that includes the second set of encoded data slices; and

sending the response to the user device.

9. The method of claim 1 , wherein the secure data includes one or more of:

financial account information;

user password information;

security credential information; or

personal data.

10. A non-transitory computer readable storage medium comprises:

a first memory portion that stores operational instructions that, when executed by a first computing device, causes the first computing device to:

receive a first request from a user device to access secure data, wherein the first request includes a user identification code (ID) and at least one object name for the secure data;

process the first request to determine a level of access to the secure data for the user device;

when the level of access is of an acceptable level, facilitate sending a set of encoded data slices to the user device, wherein the set of encoded data slices includes less than a reconstruction threshold number of encoded data slices to reconstruct at least a segment of the secure data;

a second memory portion that stores operational instructions that, when executed by a second computing device, causes the second computing device to:

receive a second request from the user device to access the secure data, wherein the second request includes the user ID, the at least one object name for the secure data, and a representation of the first request;

process the second request to determine the level of access to the secure data for the user device; and

when the level of access is of the acceptable level, facilitate sending a second set of encoded data slices to the user device, wherein the second set of encoded data slices includes less than the reconstruction threshold number of encoded data slices and wherein, when the level of access is at a given level, the set of encoded data slices and the second set of encoded data slices includes at least the reconstruction threshold number of encoded data slices.

11. The non-transitory computer readable storage medium of claim 10 , wherein the first memory portion further stores operational instructions that, when executed by the first computing device, causes the first computing device to process the first request by:

determining a security level associated with the user device; and

determining security parameters associated with the secure data, wherein the first computing device determines the level of access to the secure data based on the security level associated with the user device and the security parameters.

12. The non-transitory computer readable storage medium of claim 10 , wherein the first memory portion further stores operational instructions that, when executed by the first computing device, causes the first computing device to facilitate the sending of the set of encoded data slices to the user device by:

when the acceptable level is a partial access level:

retrieving the set of encoded data slices from dispersed storage units;

generating a response that includes the set of encoded data slices; and

sending the response to the user device.

13. The non-transitory computer readable storage medium of claim 10 , wherein the first memory portion further stores operational instructions that, when executed by the first computing device, causes the first computing device to process the first request further by:

communicating with a dispersed storage (DS) managing unit regarding a security level associated with the user device; and

communicating with the dispersed storage (DS) managing unit regarding security parameters associated with the secure data, wherein the first computing device determines the level of access to the secure data based on the security level associated with the user device and the security parameters.

14. The non-transitory computer readable storage medium of claim 10 , wherein the first memory portion further stores operational instructions that, when executed by the first computing device, causes the first computing device to process the first request by:

determining whether the first request includes a representation of a response from another computing device;

when the first request does not include the representation, determining whether the first request is an initial request for the secure data by the user device; and

when the first request is not the initial request, determining that the level of access is not acceptable for facilitating sending of the set of encoded data slices.

15. The non-transitory computer readable storage medium of claim 10 , wherein the first memory portion further stores operational instructions that, when executed by the first computing device, causes the first computing device to process the first request by:

determining a number of encoded data slices to include in the set of encoded data slices based on a variable function of security parameters and a security level associated with the user ID, wherein the security parameters includes at least one of: a secrecy level of data, an amount of data, codec information regarding the data, and error coding dispersal storage function parameters.

16. The non-transitory computer readable storage medium of claim 10 , wherein the second memory portion further stores operational instructions that, when executed by the second computing device, causes the second computing device to process the second request by:

determining a security level associated with the user device;

determining security parameters associated with the secure data;

verifying the representation of the first request; and

when the representation of the first request is verified, determining the level of access to the secure data based on the security level associated with the user device and the security parameters.

17. The non-transitory computer readable storage medium of claim 10 , wherein the second memory portion further stores operational instructions that, when executed by the second computing device, causes the second computing device to facilitate the sending of the second set of encoded data slices to the user device by:

when the acceptable level is a partial access level:

retrieving the second set of encoded data slices from dispersed storage units;

generating a response that includes the second set of encoded data slices; and

sending the response to the user device.

18. The non-transitory computer readable storage medium of claim 10 , wherein the secure data includes one or more of:

financial account information;

user password information;

security credential information; or

personal data.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038629/0015 →