IP Library Granted Patent US 9,740,730
Granted Patent B2
US 9,740,730 · App. 15/249,800 · Granted Aug 22, 2017

Authorizing distributed task processing in a distributed storage network

Inventors: Ilya Volvovski (Chicago, IL); Jason K. Resch (Chicago, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F17/30371G06F9/50G06F9/5083G06F11/1044G06F11/1076G06F11/1092G06F21/6218H04L67/1097G06F2211/1028H03M13/09H03M13/13H03M13/1515
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,740,730
App. No.
15/249,800
Granted
Aug 22, 2017
Kind
B2
Abstract

A method begins by a distributed storage (DS) processing module transmitting a set of requests to a set of DS units regarding a set of data elements and receiving a set of respective requests from the set of DS units. When the set of respective requests is in accordance with a current distributed task/data responsibility allocation period, the method continues with the DS processing module issuing a set of responses to the set of DS units. The method continues with the DS processing module receiving a set of respective responses from the set of DS units. When the set of received respective responses is in accordance with the current distributed task/data responsibility allocation period, the method continues with the DS processing module processing the set of received respective responses in accordance with the current distributed task/data responsibility allocation period to produce one of a set of results.

Claims (41)

1. A method comprises:

receiving an encoded data slice integrity status request, wherein the encoded data slice integrity status request includes an identifier (ID) of a requesting entity and a requested dispersed storage network (DSN) address range;

determining whether the requesting entity is authorized to send the encoded data slice integrity status request in accordance with a current authorized data integrity verification allocation period;

when the requesting entity is authorized to send the encoded data slice integrity status request, determining whether the requested DSN address range is in accordance with the current authorized data integrity verification allocation period;

when the requested DSN address range is in accordance with the current authorized data integrity verification allocation period:

performing an encoded data slice integrity status evaluation operation in accordance with the encoded data slice integrity status request to produce an encoded data slice integrity status response; and

outputting the encoded data slice integrity status response to the requesting entity; and

when either the requesting entity is not authorized or the requested DSN address range is not in accordance with the current authorized data integrity verification allocation period, indicating that the requesting entity may be compromised.

2. The method of claim 1 further comprises:

after performing the encoded data slice integrity status evaluation operation, indicating that the encoded data slice integrity status evaluation operation was performed on the requested DSN address range in accordance with the current authorized data integrity verification allocation period such that a second request from the requesting entity while the current authorized data integrity verification allocation period is active would be determined to be unauthorized.

3. The method of claim 1 , wherein the performing the encoded data slice integrity status evaluation operation in accordance with the encoded data slice integrity status request comprises at least one of:

when the encoded data slice integrity status request includes a slice list request, generating a list of slice names associated with the requested DSN address range to produce the encoded data slice integrity status response;

when the encoded data slice integrity status request includes a slice list digest request, generating the list of slice names associated with the requested DSN address range and generating a digest of the list of slice names to produce the encoded data slice integrity status response; and

when the encoded data slice integrity status request includes a slice integrity request:

generating at least one slice digest for at least one slice associated with the requested DSN address range;

for each slice digest of the at least one slice digest, comparing a retrieved slice digest to the slice digest to produce comparing results; and

generating the encoded data slice integrity status response to include the comparing results.

4. The method of claim 1 further comprises:

obtaining the current authorized data integrity verification allocation period from a trusted source, wherein the current authorized data integrity verification allocation period is a currently active version of one of a plurality of authorized data integrity verification allocation scenarios.

5. A dispersed storage (DS) module comprises:

a first module, when operable within a computing device, causes the computing device to:

receive an encoded data slice integrity status request, wherein the encoded data slice integrity status request includes an identifier (ID) of a requesting entity and a requested dispersed storage network (DSN) address range;

determine whether the requesting entity is authorized to send the encoded data slice integrity status request in accordance with a current authorized data integrity verification allocation period; and

when the requesting entity is authorized to send the encoded data slice integrity status request, determine whether the requested DSN address range is in accordance with the current authorized data integrity verification allocation period;

a second module, when operable within the computing device, causes the computing device to:

when the requested DSN address range is in accordance with the current authorized data integrity verification allocation period:

perform an encoded data slice integrity status evaluation operation in accordance with the encoded data slice integrity status request to produce an encoded data slice integrity status response; and

output the encoded data slice integrity status response to the requesting entity; and

a third module, when operable within the computing device, causes the computing device to:

when either the requesting entity is not authorized or the requested DSN address range is not in accordance with the current authorized data integrity verification allocation period, indicate that the requesting entity may be compromised.

6. The DS module of claim 5 further comprises:

after performing the encoded data slice integrity status evaluation operation, the second module further functions to indicate that the encoded data slice integrity status evaluation operation was performed on the requested DSN address range in accordance with the current authorized data integrity verification allocation period such that a second request from the requesting entity while the current authorized data integrity verification allocation period is active would be determined to be unauthorized.

7. The DS module of claim 5 , wherein the second module functions to perform the encoded data slice integrity status evaluation operation in accordance with the encoded data slice integrity status request by at least one of:

when the encoded data slice integrity status request includes a slice list request, generating a list of slice names associated with the requested DSN address range to produce the encoded data slice integrity status response;

when the encoded data slice integrity status request includes a slice list digest request, generating the list of slice names associated with the requested DSN address range and generating a digest of the list of slice names to produce the encoded data slice integrity status response; and

when the encoded data slice integrity status request includes a slice integrity request:

generating at least one slice digest for at least one slice associated with the requested DSN address range;

for each slice digest of the at least one slice digest, comparing a retrieved slice digest to the slice digest to produce comparing results; and

generating the encoded data slice integrity status response to include the comparing results.

8. The DS module of claim 5 further comprises:

the first module further functions to obtain the current authorized data integrity verification allocation period from a trusted source, wherein the current authorized data integrity verification allocation period is a currently active version of one of a plurality of authorized data integrity verification allocation scenarios.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2017
From: VOLVOVSKI, ILYA; RESCH, JASON K.
To: CLEVERSAFE, INC.
Reel/Frame 041159/0699 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2017
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041597/0573 →
Continuity (4)
Division 13865659 · Apr 18, 2013
Continuation In Part 13707490 · Dec 6, 2012
Provisional Application 61569387 · Dec 12, 2011
Related Publication 20160364438A1 · Dec 15, 2016