IP Library Patent Application 14675070
Patent Application
App. No. 14/675,070

SECURE DATA ACCESS IN A DISPERSED STORAGE NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/675,070
Abstract

A method begins by a processing module of a dispersed storage network (DSN) dividing data into a plurality of data units and generating a plurality of encryption keys from a master key associated with the data and a data identifier associated with the data. The method continues with the processing module encrypting the plurality of data units using the plurality of encryption keys to produce a plurality of encrypted data units and sending the plurality of encrypted data units to a first set of storage units of the DSN for storage. The method continues with the processing module encoding the master key to produce a plurality of encoded master key units and sending the plurality of encoded master key units to a second set of storage units of the DSN for storage.

Claims (68)

1 . A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:

dividing data into a plurality of data units;

generating a plurality of encryption keys from a master key associated with the data and a data identifier associated with the data;

encrypting the plurality of data units using the plurality of encryption keys to produce a plurality of encrypted data units;

sending the plurality of encrypted data units to a first set of storage units of the DSN for storage therein;

encoding the master key to produce a plurality of encoded master key units; and

sending the plurality of encoded master key units to a second set of storage units of the DSN for storage therein.

2 . The method of claim 1 , wherein the dividing the data comprises:

dispersed storage error encoding the data to produce a plurality of encoded data slices as the plurality of data units.

3 . The method of claim 1 , wherein the data identifier comprises one or more of:

a data name;

a user password;

a personal identification number;

a plurality of data unit names; and

a random value.

4 . The method of claim 1 , wherein the generating the plurality of encryption keys comprises:

performing a one-way deterministic function on the master key and a plurality of data unit names to produce the plurality of encryption keys, wherein the data identifier includes the plurality of data unit names.

5 . The method of claim 1 , wherein the generating the plurality of encryption keys comprises:

performing a series of one-way deterministic functions on the master key and the data identifier to produce the plurality of encryption keys.

6 . The method of claim 1 , wherein the encoding the master key comprises:

performing an all-or-nothing transformation on the master key to produce a secure master key; and

dispersed storage error encoding the secure master key to produce a plurality of encoded master key slices as the plurality of encoded master key units.

7 . The method of claim 1 , wherein the encoding master key comprises:

performing a Shamir secret sharing encoding function on the master key to produce a plurality of secret master key shares as the plurality of encoded master key units.

8 . The method of claim 1 further comprises:

the first and second sets of storage units include at least one storage unit in common.

9 . The method of claim 1 further comprises:

receiving a request to retrieve a data unit of the plurality of data units;

retrieving an encrypted data unit of the plurality of encrypted data units from a storage unit of the first set of storage units, wherein the encrypted data unit corresponds to the data unit;

retrieving at least some of the plurality of encoded master key units from the second set of storage units;

decoding the at least some of the plurality of encoded master key units to produce a recovered master key;

generating an encryption key of the plurality of encryption keys from the recovered master key and the data identifier; and

decrypting the encrypted data unit using the encryption key to recover the data unit.

10 . A non-transitory computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), causes the one or more computing devices to:

divide data into a plurality of data units;

generate a plurality of encryption keys from a master key associated with the data and a data identifier associated with the data;

encrypt the plurality of data units using the plurality of encryption keys to produce a plurality of encrypted data units;

send the plurality of encrypted data units to a first set of storage units of the DSN for storage therein;

encode the master key to produce a plurality of encoded master key units; and

send the plurality of encoded master key units to a second set of storage units of the DSN for storage therein.

11 . The non-transitory computer readable storage medium of claim 10 , wherein the one or more processing modules functions to execute the operational instructions stored by the at least one memory section to cause the one or more computing devices of the DSN to divide the data by:

dispersed storage error encoding the data to produce a plurality of encoded data slices as the plurality of data units.

12 . The non-transitory computer readable storage medium of claim 10 , wherein the data identifier comprises one or more of:

a data name;

a user password;

a personal identification number;

a plurality of data unit names; and

a random value.

13 . The non-transitory computer readable storage medium of claim 10 , wherein the one or more processing modules functions to execute the operational instructions stored by the at least one memory section to cause the one or more computing devices of the DSN to generate the plurality of encryption keys by:

performing a one-way deterministic function on the master key and a plurality of data unit names to produce the plurality of encryption keys, wherein the data identifier includes the plurality of data unit names.

14 . The non-transitory computer readable storage medium of claim 10 , wherein the one or more processing modules functions to execute the operational instructions stored by the at least one memory section to cause the one or more computing devices of the DSN to generate the plurality of encryption keys by:

performing a series of one-way deterministic functions on the master key and the data identifier to produce the plurality of encryption keys.

15 . The non-transitory computer readable storage medium of claim 10 , wherein the one or more processing modules functions to execute the operational instructions stored by the at least one memory section to cause the one or more computing devices of the DSN to encode the master key by:

performing an all-or-nothing transformation on the master key to produce a secure master key; and

dispersed storage error encoding the secure master key to produce a plurality of encoded master key slices as the plurality of encoded master key units.

16 . The non-transitory computer readable storage medium of claim 10 , wherein the one or more processing modules functions to execute the operational instructions stored by the at least one memory section to cause the one or more computing devices of the DSN to encode the master key by:

performing a Shamir secret sharing encoding function on the master key to produce a plurality of secret master key shares as the plurality of encoded master key units.

17 . The non-transitory computer readable storage medium of claim 10 further comprises:

the first and second sets of storage units include at least one storage unit in common.

18 . The non-transitory computer readable storage medium of claim 10 further comprises:

the at least one memory section stores further operational instructions that, when executed by the one or more processing modules, causes the one or more computing devices of the DSN to:

receive a request to retrieve a data unit of the plurality of data units;

retrieve an encrypted data unit of the plurality of encrypted data units from a storage unit of the first set of storage units, wherein the encrypted data unit corresponds to the data unit;

retrieve at least some of the plurality of encoded master key units from the second set of storage units;

decode the at least some of the plurality of encoded master key units to produce a recovered master key;

generate an encryption key of the plurality of encryption keys from the recovered master key and the data identifier; and

decrypt the encrypted data unit using the encryption key to recover the data unit.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE DELETE 15/174/279 AND 15/174/596 PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 49555 FRAME: 530. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 7, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 051495/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049555/0530 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038629/0015 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2015
From: VOLVOVSKI, ILYA; CABRAL, BRUNO HENNIG; MOTWANI, MANISH; COCAGNE, THOMAS DARREL; MARKISON, TIMOTHY W.; GRUBE, GARY W.; LEGGETTE, WESLEY; RESCH, JASON K.; STORM, MICHAEL COLIN; DHUSE, GREG; VEDPATHAK, YOGESH RAMESH; KHADIWALA, RAVI
To: CLEVERSAFE, INC.
Reel/Frame 036685/0049 →