IP Library Granted Patent US 9,672,108
Granted Patent B2
US 9,672,108 · App. 15/214,970 · Granted Jun 6, 2017

Dispersed storage network (DSN) and system with improved security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,672,108
App. No.
15/214,970
Granted
Jun 6, 2017
Kind
B2
Abstract

A computing device includes an interface configured to interface and communicate with a dispersed storage network (DSN), a memory that stores operational instructions, and a processing module operably coupled to the interface and to the memory, wherein the processing module, when operable within the computing device based on the operational instructions, is configured to perform various operations including to receive, via the interface, content retrieval messages for a data object. Then, based on the content retrieval messages for the data object and respectively for each associated data segment, the processing module determines respective groups of unique pillar combinations of at least read threshold number of EDSs, retrieves the respective groups of unique pillar combinations of at least read threshold number of EDSs from storage units (SUs) within the DSN, and provides the respective groups of unique pillar combinations of at least read threshold number of EDSs respectively to recipient device(s).

Claims (68)

1. A method for execution by one or more computing devices of a dispersed storage network (DSN) regarding recording of broadcast multi-media content that is to be broadcast at a particular broadcast time, the method comprising:

receiving a plurality of content retrieval messages for a data object, wherein the data object is segmented into a plurality of data segments, wherein a data segment of the plurality of data segments is dispersed error encoded in accordance with dispersed error encoding parameters to produce a set of encoded data slices (EDSs) that is of pillar width, wherein a read threshold number of EDSs provides for reconstruction of the data segment;

based on the plurality of content retrieval messages for the data object and respectively for each data segment of the plurality of data segments:

determining respective pluralities of unique pillar combinations of at least read threshold number of EDSs;

retrieving the respective pluralities of unique pillar combinations of at least read threshold number of EDSs from a plurality of storage units (SUs) within the DSN; and

providing the respective pluralities of unique pillar combinations of at least read threshold number of EDSs respectively to a plurality of recipient devices based on the plurality of content retrieval messages for the data object.

2. The method of claim 1 further comprising, for the data segment of the plurality of data segments:

providing a first unique pillar combination of at least read threshold number of EDSs to a first recipient device based on a first content retrieval message of the plurality of content retrieval messages for the data object; and

providing a second unique pillar combination of at least read threshold number of EDSs to a second recipient device based on a second content retrieval message of the plurality of content retrieval messages for the data object.

3. The method of claim 1 further comprising:

for a first data segment of the plurality of data segments:

providing a first unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments to a first recipient device based on a first content retrieval message of the plurality of content retrieval messages for the data object; and

providing a second unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments to a second recipient device based on a second content retrieval message of the plurality of content retrieval messages for the data object; and

for a second data segment of the plurality of data segments:

providing a first unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments to the first recipient device based on the first content retrieval message of the plurality of content retrieval messages for the data object; and

providing a second unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments to the second recipient device based on the second content retrieval message of the plurality of content retrieval messages for the data object.

4. The method of claim 1 further comprising:

determining a plurality of numbers or vectors for the plurality of content retrieval messages for the data object, wherein each number or vector is based on a different respective one of the plurality of content retrieval messages for the data object;

generating respective pluralities of sequences for the plurality of content retrieval messages for the data object by applying the plurality of numbers or vectors to a pseudorandom sequence generator, wherein each sequence is based on a different respective one of the plurality of numbers or vectors being applied to the pseudorandom sequence generator;

for a first data segment of the plurality of data segments:

determining a first unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments based on a first element of a first sequence of the respective pluralities of sequences; and

determining a second unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments based on a first element of a second sequence of the respective pluralities of sequences; and

for a second data segment of the plurality of data segments:

determining a first unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments based on a second element of the first sequence of the respective pluralities of sequences; and

determining a second unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments based on a second element of the second sequence of the respective pluralities of sequences.

5. The method of claim 1 , wherein a content retrieval message of the plurality of content retrieval messages for a data object includes at least one of:

a content identification code (ID), a user ID, digital rights management (DRM) information, DRM policy, read operational parameters utilized to retrieve EDSs of data segments of the data object from memory of the plurality of SUs within the DSN, or a content type indicator associated with the data object.

6. The method of claim 1 , wherein determining one of the respective pluralities of unique pillar combinations of at least read threshold number of EDSs is based on at least one of:

a user identification code (ID), a vault lookup, a pillar combination table lookup, a previously assigned unique pillar combination, a previously utilized pillar combination associated with the user ID, a list of data segments and pillar combinations, a data segment ID, write operational parameters utilized when the data object was stored in memory of the plurality of SUs within the DSN, content of a content retrieval message of the plurality of content retrieval messages for a data object, content ID, digital rights management (DRM) information, DRM policy, read operational parameters utilized to retrieve EDSs of data segments of the data object from memory of the plurality of SUs within the DSN, DSN system parameters, or a content type indicator associated with the data object.

7. The method of claim 1 , wherein a content retrieval message of the plurality of content retrieval messages for the data object is associated with at least one of a set top box, a user device, a DSN managing unit, a storage integrity processing unit, a DSN processing unit, a DSN unit, a SU of the plurality of SUs within the DSN, a wireless smart phone, a laptop, a tablet, a personal computers (PC), a work station, or a video game device.

8. The method of claim 1 , wherein the one or more computing devices includes a SU of the plurality of SUs within the DSN, a wireless smart phone, a laptop, a tablet, a personal computers (PC), a work station, or a video game device.

9. The method of claim 1 , wherein the DSN includes at least one of a wireless communication system, a wire lined communication systems, a non-public intranet system, a public internet system, a local area network (LAN), or a wide area network (WAN).

10. A computing device comprising:

an interface configured to interface and communicate with a dispersed storage network (DSN);

memory that stores operational instructions; and

a processing module operably coupled to the interface and to the memory, wherein the processing module, when operable within the computing device based on the operational instructions, is configured to:

receive, via the interface, a plurality of content retrieval messages for a data object, wherein the data object is segmented into a plurality of data segments, wherein a data segment of the plurality of data segments is dispersed error encoded in accordance with dispersed error encoding parameters to produce a set of encoded data slices (EDSs) that is of pillar width, wherein a read threshold number of EDSs provides for reconstruction of the data segment;

based on the plurality of content retrieval messages for the data object and respectively for each data segment of the plurality of data segments:

determine respective pluralities of unique pillar combinations of at least read threshold number of EDSs;

retrieve the respective pluralities of unique pillar combinations of at least read threshold number of EDSs from a plurality of storage units (SUs) within the DSN; and

provide the respective pluralities of unique pillar combinations of at least read threshold number of EDSs respectively to a plurality of recipient devices based on the plurality of content retrieval messages for the data object.

11. The computing device of claim 10 , wherein the processing module, when operable within the computing device based on the operational instructions, is further configured, for the data segment of the plurality of data segments, to:

provide a first unique pillar combination of at least read threshold number of EDSs to a first recipient device based on a first content retrieval message of the plurality of content retrieval messages for the data object; and

provide a second unique pillar combination of at least read threshold number of EDSs to a second recipient device based on a second content retrieval message of the plurality of content retrieval messages for the data object.

12. The computing device of claim 10 , wherein the processing module, when operable within the computing device based on the operational instructions, is further configured to:

for a first data segment of the plurality of data segments:

provide a first unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments to a first recipient device based on a first content retrieval message of the plurality of content retrieval messages for the data object; and

provide a second unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments to a second recipient device based on a second content retrieval message of the plurality of content retrieval messages for the data object; and

for a second data segment of the plurality of data segments:

provide a first unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments to the first recipient device based on the first content retrieval message of the plurality of content retrieval messages for the data object; and

provide a second unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments to the second recipient device based on the second content retrieval message of the plurality of content retrieval messages for the data object.

13. The computing device of claim 10 , wherein the processing module, when operable within the computing device based on the operational instructions, is further configured to:

determine a plurality of numbers or vectors for the plurality of content retrieval messages for the data object, wherein each number or vector is based on a different respective one of the plurality of content retrieval messages for the data object;

generate respective pluralities of sequences for the plurality of content retrieval messages for the data object by applying the plurality of numbers or vectors to a pseudorandom sequence generator, wherein each sequence is based on a different respective one of the plurality of numbers or vectors being applied to the pseudorandom sequence generator;

for a first data segment of the plurality of data segments:

determine a first unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments based on a first element of a first sequence of the respective pluralities of sequences; and

determine a second unique pillar combination of at least read threshold number of EDSs corresponding to the first data segment of the plurality of data segments based on a first element of a second sequence of the respective pluralities of sequences; and

for a second data segment of the plurality of data segments:

determine a first unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments based on a second element of the first sequence of the respective pluralities of sequences; and

determine a second unique pillar combination of at least read threshold number of EDSs corresponding to the second data segment of the plurality of data segments based on a second element of the second sequence of the respective pluralities of sequences.

14. The computing device of claim 10 , wherein a content retrieval message of the plurality of content retrieval messages for a data object includes at least one of:

a content identification code (ID), a user ID, digital rights management (DRM) information, DRM policy, read operational parameters utilized to retrieve EDSs of data segments of the data object from memory of the plurality of SUs within the DSN, or a content type indicator associated with the data object.

15. The computing device of claim 10 , wherein the processing module, when operable within the computing device based on the operational instructions, determining one of the respective pluralities of unique pillar combinations of at least read threshold number of EDSs is based on at least one of:

a user identification code (ID), a vault lookup, a pillar combination table lookup, a previously assigned unique pillar combination, a previously utilized pillar combination associated with the user ID, a list of data segments and pillar combinations, a data segment ID, write operational parameters utilized when the data object was stored in memory of the plurality of SUs within the DSN, content of a content retrieval message of the plurality of content retrieval messages for a data object, content ID, digital rights management (DRM) information, DRM policy, read operational parameters utilized to retrieve EDSs of data segments of the data object from memory of the plurality of SUs within the DSN, DSN system parameters, or a content type indicator associated with the data object.

16. The computing device of claim 10 , wherein a content retrieval message of the plurality of content retrieval messages for the data object is associated with at least one of a set top box, a user device, a DSN managing unit, a storage integrity processing unit, a DSN processing unit, a DSN unit, a SU of the plurality of SUs within the DSN, a wireless smart phone, a laptop, a tablet, a personal computers (PC), a work station, or a video game device.

17. The computing device of claim 10 further comprising:

a SU of the plurality of SUs within the DSN, a wireless smart phone, a laptop, a tablet, a personal computers (PC), a work station, or a video game device.

18. The computing device of claim 10 , wherein the DSN includes at least one of a wireless communication system, a wire lined communication systems, a non-public intranet system, a public internet system, a local area network (LAN), or a wide area network (WAN).

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2016
From: ABHIJEET, KUMAR; DHUSE, GREG R.; GLADWIN, S. CHRISTOPHER; GRUBE, GARY W.; MARKISON, TIMOTHY W.; RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039200/0706 →