IP Library Granted Patent US 10,158,648
Granted Patent B2
US 10,158,648 · App. 15/221,344 · Granted Dec 18, 2018

Policy-based access in a dispersed storage network

Inventors: Gary W. Grube (Barrington Hills, IL); Jason K. Resch (Chicago, IL)
Assignee: International Business Machines Corporation
H04L63/108G06F11/00G06F11/1076G06F17/30194G06F21/60G06F21/62H04L29/08549H04L67/1097G06F2211/1028G06F2221/2137G06F2221/2141H04L2012/6467
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,158,648
App. No.
15/221,344
Granted
Dec 18, 2018
Kind
B2
Abstract

A method for execution by a dispersed storage and task (DST) execution unit operates to receive a slice retrieval request from a requester that includes a slice name of one or slices to be retrieved; determine an access policy to apply to the slice retrieval request; determine a timestamp; and determine, based on the timestamp, when the one or more slices are available for retrieval. When the one or more slices are available for retrieval, the method operates further to determine when the one or more slices are currently available to the requester; retrieves the one or more slices from memory and sends the one or more slices to the requester, when the one or more slices are currently available to the requester.

Claims (48)

1. A method for execution by a dispersed storage and task (DST) execution unit that includes a processor, the method comprises:

receiving a slice retrieval request from a requester that includes a slice name of one or more slices to be retrieved, wherein each slice of the one or more slices is a dispersed storage error encoded portion of a segment of a data object;

determining an access policy to apply to the slice retrieval request, the access policy including time varying availability patterns of one or more dispersed storage units in which the one or more slices to be retrieved are stored, wherein less than a read threshold number of the dispersed storage units are available for retrieval requests during any one time varying availability pattern of the time varying availability patterns;

determining a timestamp relating to the slice retrieval request;

determining, based on a comparison of the time varying availability patterns and the timestamp, when the one or more slices are available for retrieval; and

when the one or more slices are available for retrieval:

determining when the one or more slices are currently available to the requester; and

retrieving the one or more slices from memory and sending the one or more slices to the requester, when the one or more slices are currently available to the requester.

2. The method of claim 1 , wherein the requester is at least one of: a user device, a DST processing unit, a storage integrity processing unit, a managing unit, or another DST execution unit.

3. The method of claim 1 , wherein the slice retrieval request includes one or more of: a requester identifier (ID), a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

4. The method of claim 1 , wherein determining the access policy to apply to the slice retrieval request is based on a stored access policy associated with the slice name of the one or more slices.

5. The method of claim 1 , wherein determining the access policy to apply to the slice retrieval request is based on one or more of a lookup in memory of a previously received access policy, a requester ID, a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

6. The method of claim 1 , wherein determining when the one or more slices are currently available to the requester is based on one or more of: a memory status indicator, a dispersed storage unit status indicator, or a performance indicator.

7. The method of claim 1 , further comprising:

sending an unavailable message to the requester when the one or more slices are not available for retrieval.

8. The method of claim 1 , wherein determining when the one or more slices are currently available to the requester is based on when the access policy indicates that the requester has access authorization at the time indicated by the timestamp.

9. The method of claim 1 , further comprising:

sending an unavailable message to the requester when the one or more slices are not currently available to the requester.

10. A processing system of a dispersed storage and task (DST) execution unit comprises:

at least one processor;

a memory that stores operational instructions, that when executed by the at least one processor cause the processing system to:

receive a slice retrieval request from a requester that includes a slice name of one or more slices to be retrieved, wherein each slice of the one or more slices is a dispersed storage error encoded portion of a segment of a data object;

determine an access policy to apply to the slice retrieval request, the access policy including time varying availability patterns of one or more dispersed storage units in which the one or more slices to be retrieved are stored, wherein less than a read threshold number of the dispersed storage units are available for retrieval requests during any one time varying availability pattern of the time varying availability patterns;

determine a timestamp relating to the slice retrieval request;

determine, based on a comparison of the time varying availability patterns and the timestamp, when the one or more slices are available for retrieval; and

when the one or more slices are available for retrieval:

determine when the one or more slices are currently available to the requester; and

retrieve the one or more slices from memory and send the one or more slices to the requester, when the one or more slices are currently available to the requester.

11. The processing system of claim 10 , wherein the requester is at least one of: a user device, a DST processing unit, a storage integrity processing unit, a managing unit, or another DST execution unit.

12. The processing system of claim 10 , wherein the slice retrieval request includes one or more of: a requester identifier (ID), a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

13. The processing system of claim 10 , wherein determining the access policy to apply to the slice retrieval request is based on a stored access policy associated with the slice name of the one or more slices.

14. The processing system of claim 10 , wherein determining the access policy to apply to the slice retrieval request is based on one or more of a lookup in memory of a previously received access policy, a requester ID, a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

15. The processing system of claim 10 , wherein determining when the one or more slices are currently available to the requester is based on one or more of: a memory status indicator, a dispersed storage unit status indicator, or a performance indicator.

16. The processing system of claim 10 , wherein the operational instructions, when executed by the at least one processor, further cause the processing system to:

send an unavailable message to the requester when the one or more slices are not available for retrieval.

17. The processing system of claim 10 , wherein determining when the one or more slices are currently available to the requester is based on when the access policy indicates that the requester has access authorization at the time indicated by the timestamp.

18. The processing system of claim 10 , wherein the operational instructions, when executed by the at least one processor, further cause the processing system to:

send an unavailable message to the requester when the one or more slices are not currently available to the requester.

19. A non-transitory computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by a processing system of a dispersed storage network (DSN) that includes a processor and a memory, causes the processing system to:

receive a slice retrieval request from a requester that includes a slice name of one or more slices to be retrieved, wherein each slice of the one or more slices is a dispersed storage error encoded portion of a segment of a data object;

determine an access policy to apply to the slice retrieval request, the access policy including time varying availability patterns of one or more dispersed storage units in which the one or more slices to be retrieved are stored, wherein less than a read threshold number of the dispersed storage units are available for retrieval requests during any one time varying availability pattern of the time varying availability patterns;

determine a timestamp relating to the slice retrieval request;

determine, based on a comparison of the time varying availability patterns and the timestamp, when the one or more slices are available for retrieval; and

when the one or more slices are available for retrieval:

determine when the one or more slices are currently available to the requester; and

retrieve the one or more slices from memory and send the one or more slices to the requester, when the one or more slices are currently available to the requester.

20. The non-transitory computer readable storage medium of claim 19 , wherein determining the access policy to apply to the slice retrieval request is based on a stored access policy associated with the slice name of the one or more slices.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2016
From: GRUBE, GARY W.; RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039274/0742 →
Continuity (4)
Continuation In Part 14612422 · Feb 3, 2015
Continuation 12886368 · Sep 20, 2010
Provisional Application 61290757 · Dec 29, 2009
Related Publication 20160337376A1 · Nov 17, 2016