IP Library Granted Patent US 9,992,019
Granted Patent B2
US 9,992,019 · App. 14/954,527 · Granted Jun 5, 2018

Storage and retrieval of dispersed storage network access information

Inventors: Jason K. Resch (Chicago, IL); S. Christopher Gladwin (Chicago, IL); Andrew Baptist (Mt. Pleasant, WI); Thomas Franklin Shirley, Jr. (Wauwatosa, WI)
Assignee: International Business Machines Corporation
H04L9/0894G06F3/06G06F3/0604G06F3/067G06F11/00G06F11/1612G06F15/17331H04L9/085H04L9/0863H04L9/0869H04L9/0877H04L9/32H04L9/321H04L9/3263G06F11/1446G06F21/00G06F2211/1028H04L9/00H04L29/06H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,992,019
App. No.
14/954,527
Granted
Jun 5, 2018
Kind
B2
Abstract

A method includes affiliating an authentication token with user information of a user. The method further includes generating a private/public key pairing associated with the user information. The method further includes applying a share encoding function on a private key of the private/public key pairing to produce a set of encoded shares. The method further includes generating a set of random numbers and generating a set of hidden passwords based on the user information. The method further includes generating a set of encryption keys based on the set of hidden passwords and the set of random numbers. The method further includes encrypting the set of encoded shares utilizing the set of encryption keys to produce a set of encrypted shares. The method further includes outputting the set of encrypted shares to the authentication token for storage therein and outputting the set of random numbers to a set of authenticating units.

Claims (53)

1. A method comprises:

affiliating an authentication token with user information of a user;

generating a private/public key pairing associated with the user information;

applying a share encoding function on a private key of the private/public key pairing to produce a set of encoded shares;

generating a set of random numbers;

generating a set of hidden passwords based on the user information;

generating a set of encryption keys based on the set of hidden passwords and the set of random numbers;

encrypting the set of encoded shares utilizing the set of encryption keys to produce a set of encrypted shares;

outputting the set of encrypted shares to the authentication token for storage therein; and

outputting the set of random numbers to a set of authenticating units.

2. The method of claim 1 , wherein the share encoding function comprises at least one of:

a dispersed storage error encoding function; and

a secret sharing function.

3. The method of claim 1 , wherein the generating the set of random numbers comprises:

obtaining a set of base random numbers; and

expanding each base random number of the set of base random numbers based on security parameters to produce the set of random numbers.

4. The method of claim 1 , wherein the generating the set of hidden passwords comprises:

transforming a set of personalized authenticating values of the user information in accordance with a set of transformation functions to produce a set of transformed personalized authenticating values; and

for each password of the set of hidden passwords:

combining, in accordance with a combining function, one of the set of transformed personalized authenticating values with at least one of a constant and another one of the set of transformed personalized authenticating values to produce the password.

5. The method of claim 1 further comprises:

for each encoded share of the set of encoded shares:

generating an encryption key based on a corresponding one of the set of hidden passwords and a corresponding one of the set of random numbers; and

encrypting the encoded share utilizing the encryption key to produce an encrypted share.

6. A managing unit comprises:

a first module, when operable within a computing device, causes the computing device to:

affiliate an authentication token with user information of a user;

generate a private/public key pairing associated with the user information; and

apply a share encoding function on a private key of the private/public key pairing to produce a set of encoded shares;

a second module, when operable within a computing device, causes the computing device to:

generate a set of random numbers;

a third module, when operable within a computing device, causes the computing device to:

generate a set of hidden passwords based on the user information;

a fourth module, when operable within a computing device, causes the computing device to:

generate a set of encryption keys based on the set of hidden passwords and the set of random numbers; and

encrypt the set of encoded shares utilizing the set of encryption keys to produce a set of encrypted shares; and

a fifth module, when operable within a computing device, causes the computing device to:

output the set of encrypted shares to the authentication token for storage therein; and

output the set of random numbers to a set of authenticating units.

7. The managing unit of claim 6 , wherein the share encoding function comprises at least one of:

a dispersed storage error encoding function; and

a secret sharing function.

8. The managing unit of claim 6 , wherein the second module, when operable, generates the set of random numbers by:

obtaining a set of base random numbers; and

expanding each base random number of the set of base random numbers based on security parameters to produce the set of random numbers.

9. The managing unit of claim 6 , wherein the third module, when operable, generates the set of hidden passwords by:

transforming a set of personalized authenticating values of the user information in accordance with a set of transformation functions to produce a set of transformed personalized authenticating values; and

for each hidden password of the set of hidden passwords:

combining, in accordance with a combining function, one of the set of transformed personalized authenticating values with at least one of a constant and another one of the set of transformed personalized authenticating values to produce the hidden password.

10. The managing unit of claim 6 further comprises:

the fourth module is further operable to, for each encoded share of the set of encoded shares:

generate an encryption key based on a corresponding one of the set of hidden passwords and a corresponding one of the set of random numbers; and

encrypt the encoded share utilizing the encryption key to produce an encrypted share.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2016
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038629/0015 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2016
From: RESCH, JASON K.; GLADWIN, S. CHRISTOPHER; BAPTIST, ANDREW; SHIRLEY, THOMAS FRANKLIN, JR.
To: CLEVERSAFE, INC.
Reel/Frame 037600/0936 →
Continuity (3)
Division 13587277 · Aug 16, 2012
Provisional Application 61524521 · Aug 17, 2011
Related Publication 20160191242A1 · Jun 30, 2016