DISPERSED STORAGE NETWORK WITH ACCESS CONTROL AND METHODS FOR USE THEREWITH
In a dispersed storage network where slices of secure user data are stored on geographically separated storage units ( 44 ), a managing unit ( 18 ) connected to the network ( 20 ) may seek to broadcast and update secure access control list information across the network ( 20 ). Upon a target device (e.g., devices 12, 14, 16, 18 , or 44 ) receiving the broadcast, the target device creates and sends an access control list change notification message to all other system devices that should have received the same broadcast if the broadcast is a valid request to update access control list information. The target device waits for responses from the other system devices to validate that the broadcast has been properly sent to a threshold number of other system devices before taking action to operationally change local data in accordance with the broadcast.
1 . A method for authenticating, through use of a dispersed storage unit, a user device request from a user device to access a dispersed storage network (DSN), the method comprising:
receiving, from a first proxy system element of the DSN, a first authentication request regarding executing a first portion of the user device request;
verifying the first authentication request;
when the first authentication request is validated, determining when a permissions list indicates that the user device has access permission corresponding to the user device request;
sending, to the first proxy system element, a first favorable response such that the first proxy system element is allowed to execute the first portion of the user device request when the permissions list indicates that the user device has access permission corresponding to the user device request;
receiving, from a second proxy system element, a second authentication request regarding executing a second portion of the user device request;
verifying the second authentication request;
when the second authentication request is validated, determining when the permissions list indicates that the user device has access permission corresponding to the user device request;
sending, to the second proxy system element, a second favorable response such that the second proxy system element is allowed to execute the second portion of the user device request when the permissions list indicates that the user device has access permission corresponding to the user device request.
2 . The method of claim 1 , wherein when the user device request includes a read request, determining when the permissions list indicates that the user device has access permission includes determining the permissions list indicates that the user device has a read permission.
3 . The method of claim 1 , wherein when the user device request includes a write request, determining when the permissions list indicates that the user device has access permission includes determining the permissions list indicates that the user device has a write permission.
4 . The method of claim 1 wherein the user device request includes a filename and determining when the permissions list indicates that the user device has access permission corresponding to the user device request is further based on the filename.
5 . The method of claim 1 wherein the user device request includes a realm identifier and determining when the permissions list indicates that the user device has access permission corresponding to the user device request is further based on the realm identifier.
6 . The method of claim 1 wherein the user device request includes a vault identifier and determining when the permissions list indicates that the user device has access permission corresponding to the user device request is further based on the vault identifier.
7 . The method of claim 1 wherein verifying the first authentication request includes verifying that the first proxy system element is authenticated.
8 . The method of claim 7 wherein, when the first proxy system element is authenticated, verifying the first authentication request further includes verifying the user device is an authenticated user device.
9 . The method of claim 1 wherein verifying the second authentication request includes verifying that the second proxy system element is authenticated.
10 . The method of claim 9 wherein, when the second proxy system element is authenticated, verifying the second authentication request further includes verifying the user device is an authenticated user device.
11 . A dispersed storage unit adapted to be coupled to a dispersed storage network (DSN), the dispersed storage unit comprising:
input/output interface circuitry adapted to be coupled to the DSN;
memory; and
a processing module operably coupled to the memory and to the input/output interface circuitry, wherein the processing module is operable to:
receive from a first proxy system element of the DSN, a first authentication request regarding executing a first portion of a user device request from a user device;
verify the first authentication request;
when the first authentication request is validated, determine when a permissions list indicates that the user device has access permission corresponding to the user device request;
send to the first proxy system element, a first favorable response such that the first proxy system element is allowed to execute the first portion of the user device request when the permissions list indicates that the user device has access permission corresponding to the user device request;
receive from a second proxy system element, a second authentication request regarding executing a second portion of the user device request;
verify the second authentication request;
when the second authentication request is validated, determine when the permissions list indicates that the user device has access permission corresponding to the user device request;
send to the second proxy system element, a second favorable response such that the second proxy system element is allowed to execute the second portion of the user device request when the permissions list indicates that the user device has access permission corresponding to the user device request.
12 . The dispersed storage unit of claim 11 , wherein when the user device request includes a read request, the processing module determines when the permissions list indicates that the user device has access permission by determining that the permissions list indicates that the user device has a read permission.
13 . The dispersed storage unit of claim 11 , wherein when the user device request includes a write request, the processing module determines when the permissions list indicates that the user device has access permission by determining that the permissions list indicates that the user device has a write permission.
14 . The dispersed storage unit of claim 11 wherein the user device request includes a filename and the processing module determines when the permissions list indicates that the user device has access permission further based on the filename.
15 . The dispersed storage unit of claim 11 wherein the user device request includes a realm identifier and the processing module determines when the permissions list indicates that the user device has access permission further based on the realm identifier.
16 . The dispersed storage unit of claim 11 wherein the user device request includes a vault identifier and the processing module determines when the permissions list indicates that the user device has access permission further based on the vault identifier.
17 . The dispersed storage unit of claim 11 wherein verifying the first authentication request includes verifying that the first proxy system element is an authenticated proxy.
18 . The dispersed storage unit of claim 17 wherein, when the first proxy system element is an authenticated proxy, verifying the first authentication request further includes verifying the user device is an authenticated user device.
19 . The dispersed storage unit of claim 11 wherein verifying the second authentication request includes verifying that the second proxy system element is an authenticated proxy.
20 . The dispersed storage unit of claim 19 wherein, when the second proxy system element is an authenticated proxy, verifying the second authentication request further includes verifying the user device is an authenticated user device.