IP Library › Granted Patent US 10,126,961
Granted Patent B2
US 10,126,961 · App. 15/221,299 · Granted Nov 13, 2018

Securely recovering stored data in a dispersed storage network

Inventor: Jason K. Resch (Chicago, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F3/0619G06F3/064G06F3/067G06F3/0611G06F3/0622G06F3/0637G06F3/0644G06F3/0659G06F3/0665G06F3/0689G06F11/1076G06F11/1092G06F11/3034G06F11/3409G06F12/1408H04L67/1097G06F2212/1052H03M13/1515
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,126,961
App. No.
15/221,299
Filed
Jul 27, 2016
Granted
Nov 13, 2018
Kind
B2
Art Unit
2431
USPC
713/193
Abstract

A method for execution by a dispersed storage and task (DST) execution unit that includes a processor includes receiving a slice pre-image request from a computing device via a network that indicates a data slice, a requesting entity and a plurality of storage units. A data pre-image is generated by performing a pre-image function on the data slice based on the plurality of storage units. An encrypted data pre-image is generated for transmission to the computing device by performing an encryption function on the data pre-image based on a key associated with the requesting entity.

Claims (35)

1. A method for execution by a dispersed storage and task (DST) execution unit that includes a hardware processor, the method comprises:

receiving a slice pre-image request from a computing device via a network, wherein the slice pre-image request indicates a data slice, a requesting entity, and a plurality of storage units;

generating a data pre-image by performing a pre-image function on the data slice based on the plurality of storage units; and

generating an encrypted data pre-image for transmission to the computing device by performing an encryption function on the data pre-image based on a key associated with the requesting entity;

wherein the computing device receives a plurality of encrypted data pre-images from a plurality of storage units that includes the DST execution unit for transmission to the requesting entity for decoding;

wherein the requesting entity receives a plurality of storage unit identifiers corresponding to the plurality of storage units from the computing device, and wherein the requesting entity decodes the plurality of encrypted data pre-images by utilizing a plurality of unique keys, each associated with one of the plurality of storage units; and

wherein the requesting entity receives a sum of the encrypted data pre-images from the computing device, and wherein decoding includes subtracting each of the plurality of unique keys from the sum of the encrypted data pre-images.

2. The method of claim 1 , wherein the pre-image function includes creating a vector that includes the data slice, creating a decode matrix based on the plurality of storage units, and performing matrix multiplication on the vector and the decode matrix.

3. The method of claim 1 , wherein generating the encryption function includes applying the key additively to the data pre-image.

4. The method of claim 1 , further comprising generating a message authentication code based on the data slice for transmission to the computing device via the network.

5. The method of claim 1 , wherein the key is established based on at least one of: a public-key system or a key agreement protocol.

6. A processing system of a dispersed storage and task (DST) execution unit comprises:

at least one hardware processor;

a memory that stores operational instructions, that when executed by the at least one hardware processor cause the processing system to:

receive a slice pre-image request from a computing device via a network, wherein the slice pre-image request indicates a data slice, a requesting entity, and a plurality of storage units;

generate a data pre-image by performing a pre-image function on the data slice based on the plurality of storage units; and

generate an encrypted data pre-image for transmission to the computing device by performing an encryption function on the data pre-image based on a key associated with the requesting entity;

wherein the computing device receives a plurality of encrypted data pre-images from a plurality of storage units that includes the DST execution unit for transmission to the requesting entity for decoding;

wherein the requesting entity receives a plurality of storage unit identifiers corresponding to the plurality of storage units from the computing device, and wherein the requesting entity decodes the plurality of encrypted data pre-images by utilizing a plurality of unique keys, each associated with one of the plurality of storage units; and

wherein the requesting entity receives a sum of the encrypted data pre-images from the computing device, and wherein decoding includes subtracting each of the plurality of unique keys from the sum of the encrypted data pre-images.

7. The processing system of claim 6 , wherein the pre-image function includes creating a vector that includes the data slice, creating a decode matrix based on the plurality of storage units, and performing matrix multiplication on the vector and the decode matrix.

8. The processing system of claim 6 , wherein generating the encryption function includes applying the key additively to the data pre-image.

9. The processing system of claim 6 , wherein the operational instructions, when execution by the at least one hardware processor, further cause the processing system to generate a message authentication code based on the data slice for transmission to the computing device via the network.

10. The processing system of claim 6 , wherein the key is established based on at least one of: a public-key system or a key agreement protocol.

11. A non-transitory computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by a processing system of a dispersed storage network (DSN) that includes a hardware processor and a memory, causes the processing system to:

receive a slice pre-image request from a computing device via a network, wherein the slice pre-image request indicates a data slice, a requesting entity, and a plurality of storage units;

generate a data pre-image by performing a pre-image function on the data slice based on the plurality of storage units; and

generate an encrypted data pre-image for transmission to the computing device by performing an encryption function on the data pre-image based on a key associated with) the requesting entity;

wherein the computing device receives a plurality of encrypted data pre-images from a plurality of storage units that includes the DST execution unit for transmission to the requesting entity for decoding;

wherein the requesting entity receives a plurality of storage unit identifiers corresponding to the plurality of storage units from the computing device, and wherein the requesting entity decodes the plurality of encrypted data pre-images by utilizing a plurality of unique keys, each associated with one of the plurality of storage units; and

wherein the requesting entity receives a sum of the encrypted data pre-images from the computing device, and wherein decoding includes subtracting each of the plurality of unique keys from the sum of the encrypted data pre-images.

12. The non-transitory computer readable storage medium of claim 11 , wherein the pre-image function includes creating a vector that includes the data slice, creating a decode matrix based on the plurality of storage units, and performing matrix multiplication on the vector and the decode matrix.

13. The non-transitory computer readable storage medium of claim 11 , wherein generating the encryption function includes applying the key additively to the data pre-image.

14. The non-transitory computer readable storage medium of claim 11 , wherein the operational instructions, when executed by the processing system, further cause the non-transitory computer readable storage medium to generate a message authentication code based on the data slice for transmission to the computing device via the network.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2016
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039274/0224 →
Continuity (2)
Provisional Application 62211975 · Aug 31, 2015
Related Publication 20170060778A1 · Mar 2, 2017