IP Library Granted Patent US 10,237,281
Granted Patent B2
US 10,237,281 · App. 15/221,731 · Granted Mar 19, 2019

Access policy updates in a dispersed storage network

Inventors: Gary W. Grube (Barrington Hills, IL); Jason K. Resch (Chicago, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/108G06F11/00G06F11/1096G06F17/30194G06F21/62H04L29/08549H04L63/20H04L67/1097G06F11/08G06F2211/1028G06F2221/2137G06F2221/2141H04L2012/6467
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,237,281
App. No.
15/221,731
Filed
Jul 28, 2016
Granted
Mar 19, 2019
Kind
B2
Art Unit
2438
USPC
713/193
Abstract

A method for execution in a dispersed storage network operates to determine one or more slice names of one or more slices and determine whether to establish a new access policy corresponding to the one or more slices. When the new access policy is to be established, the method determines a timestamp; determines a new access policy; and sends the new access policy and the timestamp to one or more storage units that store the one or more slices.

Claims (49)

1. A method for execution by a processing system of a dispersed storage network (DSN) that includes a processor, the method comprises:

determining one or more slice names of one or more encoded data slices, wherein one or more data segments of data are dispersed storage error encoded to produce one more sets of encoded data slices, wherein the one or more sets of encoded data slices includes the one or more encoded data slices;

determining whether to establish a new access policy corresponding to the one or more encoded data slices;

when the new access policy is to be established:

determining a timestamp regarding the new access policy;

determining the new access policy, wherein the new access policy includes an access policy pattern; and

sending the new access policy and the timestamp to one or more storage units of the DSN that store the one or more encoded data slices; and

when the new access policy is not to be established:

repeating, the determining the one or more slice names of the one or more encoded data slices.

2. The method of claim 1 , wherein the one or more slice names include one of: a plurality of discrete and non-contiguous slice names, a contiguous range of slice names associated with a common data segment or a contiguous range of slice names associated with a common data object.

3. The method of claim 1 , wherein the determining one or more slice names is based on one or more of an access policy reconsideration request, where a previous access policy update ended, a starting DSN address, a lookup, a command, a request, a random number, a vault ID, a data object ID, or a virtual DSN address to a physical location table.

4. The method of claim 1 , wherein the determining whether to establish the new access policy is based on one or more of: an access policy reconsideration message, a current access policy for the one or more slice names, a command, a past history of access policy reconsiderations, a history of slice access sequences, a request, a predetermination, a data type, a security indicator, a priority indicator, a DSN memory system status indicator, a vault utilization indicator, or a DS managing unit message.

5. The method of claim 1 , wherein the determining the new access policy is based on one or more of: an access policy reconsideration message, a current access policy for the one or more slice names, a command, a past history of access policy reconsiderations, a history of slice access sequences, a request, a predetermination, a data type, a security indicator, a priority indicator, a DSN memory system status indicator, a vault utilization indicator, or a DS managing unit message.

6. The method of claim 1 , wherein the determining the one or more slice names and the determining whether to establish a new access policy are in response to receiving a reconsideration message that includes the one or more slice names.

7. The method of claim 6 , further comprising:

generating a reconsideration response message that indicates a denial of reconsideration when the new access policy is not established.

8. A processing system of a dispersed storage network (DSN) comprises:

at least one processor;

a memory that stores operational instructions, that when executed by the at least one processor cause the processing system to:

determine one or more slice names of one or more encoded data slices, wherein one or more data segments of data are dispersed storage error encoded to produce one more sets of encoded data slices, wherein the one or more sets of encoded data slices includes the one or more encoded data slices;

determine whether to establish a new access policy corresponding to the one or more encoded data slices;

when the new access policy is to be established:

determine a timestamp regarding the new access policy;

determine the new access policy, wherein the new access policy includes an access policy pattern; and

send the new access policy and the timestamp to one or more storage units of the DSN that store the one or more encoded data slices; and

when the new access policy is not to be established:

repeating, the determining the one or more slice names of the one or more encoded data slices.

9. The processing system of claim 8 , wherein the one or more slice names include one of: a plurality of discrete and non-contiguous slice names, a contiguous range of slice names associated with a common data segment or a contiguous range of slice names associated with a common data object.

10. The processing system of claim 8 , wherein the determining one or more slice names is based on one or more of an access policy reconsideration request, where a previous access policy update ended, a starting DSN address, a lookup, a command, a request, a random number, a vault ID, a data object ID, or a virtual DSN address to a physical location table.

11. The processing system of claim 8 , wherein the determining whether to establish the new access policy is based on one or more of: an access policy reconsideration message, a current access policy for the one or more slice names, a command, a past history of access policy reconsiderations, a history of slice access sequences, a request, a predetermination, a data type, a security indicator, a priority indicator, a DSN memory system status indicator, a vault utilization indicator, or a DS managing unit message.

12. The processing system of claim 8 , wherein the determining the new access policy is based on one or more of: an access policy reconsideration message, a current access policy for the one or more slice names, a command, a past history of access policy reconsiderations, a history of slice access sequences, a request, a predetermination, a data type, a security indicator, a priority indicator, a DSN memory system status indicator, a vault utilization indicator, or a DS managing unit message.

13. The processing system of claim 8 , wherein the determining the one or more slice names and the determining whether to establish a new access policy are in response to receiving a reconsideration message that includes the one or more slice names.

14. The processing system of claim 13 , wherein the operational instructions, when executed by the at least one processor, further cause the processing system to:

generate a reconsideration response message that indicates a denial of reconsideration when the new access policy is not established.

15. A non-transitory computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by a processing system of a dispersed storage network (DSN) that includes a processor and a memory, causes the processing system to:

determine one or more slice names of one or more encoded data slices;

determine whether to establish a new access policy corresponding to the one or more encoded data slices;

when the new access policy is to be established:

determine a timestamp regarding the new access policy;

determine the new access policy, wherein the new access policy includes an access policy pattern; and

send the new access policy and the timestamp to one or more storage units of the DSN that store the one or more encoded data slices; and

when the new access policy is not to be established:

repeating, the determining the one or more slice names of the one or more encoded data slices.

16. The non-transitory computer readable storage medium of claim 15 , wherein the one or more slice names include one of: a plurality of discrete and non-contiguous slice names, a contiguous range of slice names associated with a common data segment or a contiguous range of slice names associated with a common data object.

17. The non-transitory computer readable storage medium of claim 15 , wherein the determining one or more slice names is based on one or more of an access policy reconsideration request, where a previous access policy update ended, a starting DSN address, a lookup, a command, a request, a random number, a vault ID, a data object ID, or a virtual DSN address to a physical location table.

18. The non-transitory computer readable storage medium of claim 15 , wherein the determining whether to establish the new access policy is based on one or more of: an access policy reconsideration message, a current access policy for the one or more slice names, a command, a past history of access policy reconsiderations, a history of slice access sequences, a request, a predetermination, a data type, a security indicator, a priority indicator, a DSN memory system status indicator, a vault utilization indicator, or a DS managing unit message.

19. The non-transitory computer readable storage medium of claim 15 , wherein the determining the new access policy is based on one or more of an access policy reconsideration message, a current access policy for the one or more slice names, a command, a past history of access policy reconsiderations, a history of slice access sequences, a request, a predetermination, a data type, a security indicator, a priority indicator, a DSN memory system status indicator, a vault utilization indicator, or a DS managing unit message.

20. The non-transitory computer readable storage medium of claim 15 , wherein the determining the one or more slice names and the determining whether to establish a new access policy are in response to receiving a reconsideration message that includes the one or more slice names.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2016
From: GRUBE, GARY W.; RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039279/0036 →
Continuity (4)
Continuation In Part 14612422 · Feb 3, 2015
Continuation 12886368 · Sep 20, 2010
Provisional Application 61290757 · Dec 29, 2009
Related Publication 20160337377A1 · Nov 17, 2016