IP Library Granted Patent US 9,798,467
Granted Patent B2
US 9,798,467 · App. 15/259,764 · Granted Oct 24, 2017

Security checks for proxied requests

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,798,467
App. No.
15/259,764
Granted
Oct 24, 2017
Kind
B2
Abstract

A method begins by a storage unit of a dispersed storage network (DSN) executing transitioning storage of one or more groups of encoded data slices. The method continues while transitioning storage of the one or more groups of encoded data slices with the storage unit receiving a proxied data access request regarding an encoded data slice from another storage unit of the DSN. The method continues by the storage unit determining whether the other storage unit is an authentic storage unit of the DSN based on at least one of the encoded data slice, a previous version of the distributed agreement protocol, and a new version of the distributed agreement protocol. The method continues by when the other storage unit is the authentic storage unit, processing the proxied data access request to produce a data access response and sending the data access response to the other storage unit.

Claims (59)

1. A method for execution by a storage unit of a dispersed storage network (DSN), the method comprises:

transitioning storage of one or more groups of encoded data slices from storage based on a previous version of a distributed agreement protocol to storage based on a new version of the distributed agreement protocol; and

while transitioning storage of the one or more groups of encoded data slices:

receiving a proxied data access request regarding an encoded data slice from another storage unit of the DSN;

determining whether the other storage unit is an authentic storage unit of the DSN based on at least one of: the encoded data slice, the previous version of the distributed agreement protocol, and the new version of the distributed agreement protocol;

when the other storage unit is the authentic storage unit, processing the proxied data access request to produce a data access response; and

sending the data access response to the other storage unit.

2. The method of claim 1 , wherein the determining whether the other storage unit is the authentic storage unit comprises:

determining the other storage unit is part of the same vault as the storage unit.

3. The method of claim 1 , wherein the determining whether the other storage unit is the authentic storage unit comprises:

determining the encoded data slice is mapped to the other storage unit based on the previous version of the distributed agreement protocol.

4. The method of claim 1 , wherein the determining whether the other storage unit is the authentic storage unit comprises:

determining that an ongoing migration task from the other storage unit to the storage unit is active.

5. The method of claim 4 , wherein determining the ongoing migration task comprises one or more of:

querying a DSN managing unit;

determining the storage unit is concurrently using both the previous and new distributed agreement protocol; and

receiving a message indicating to use the new distributed agreement protocol for data access requests.

6. The method of claim 1 , wherein the determining whether the other storage unit is the authentic storage unit comprises:

determining the encoded data slice is mapped to the storage unit based on the new version of the distributed agreement protocol.

7. The method of claim 1 further comprises one of:

when the other storage unit is not the authentic storage unit, denying the proxied data access request;

when the other storage unit is not the authentic storage unit:

identifying a second storage unit based on the encoded data slice and the previous distributed agreement protocol;

sending a request to the second storage unit to verify the proxied data access request; and

when verified, process the request and sending a response to the second storage unit.

8. The method of claim 1 further comprises:

receiving the new version of the distributed agreement protocol and maintaining the previous version of a distributed agreement protocol for processing data access requests regarding the one or more groups of encoded data slices during the transition of storage; and

when the transition of storage is complete, utilizing the new version of a distributed agreement protocol for processing data access requests regarding the one or more groups of encoded data slices.

9. A storage unit comprises:

an interface;

memory; and

a processing module operably coupled to the memory and the interface, wherein the processing module is operable to:

transition storage of one or more groups of encoded data slices from storage based on a previous version of a distributed agreement protocol to storage based on a new version of the distributed agreement protocol; and

while transitioning storage of the one or more groups of encoded data slices:

receive, via the interface, a proxied data access request regarding an encoded data slice from another storage unit of a dispersed storage network (DSN);

determine whether the other storage unit is an authentic storage unit of the DSN based on at least one of: the encoded data slice, the previous version of the distributed agreement protocol, and the new version of the distributed agreement protocol;

when the other storage unit is the authentic storage unit, process the proxied data access request to produce a data access response; and

send, via the interface, the data access response to the other storage unit.

10. The storage unit of claim 9 , wherein the processing module determines whether the other storage unit is the authentic storage unit by:

determining the other storage unit is part of the same vault as the storage unit.

11. The storage unit of claim 9 , wherein the processing module determines whether the other storage unit is the authentic storage unit by:

determining the encoded data slice is mapped to the other storage unit based on the previous version of the distributed agreement protocol.

12. The storage unit of claim 9 , wherein the processing module determines whether the other storage unit is the authentic storage unit by:

determining that an ongoing migration task from the other storage unit to the storage unit is active.

13. The storage unit of claim 12 , wherein the processing module determines the ongoing migration task by one or more of:

querying a DSN managing unit;

determining the storage unit is concurrently using both the previous and new distributed agreement protocol; and

receiving, via the interface, a message indicating to use the new distributed agreement protocol for data access requests.

14. The storage unit of claim 9 , wherein the processing module determines whether the other storage unit is the authentic storage unit by:

determining the encoded data slice is mapped to the storage unit based on the new version of the distributed agreement protocol.

15. The storage unit of claim 9 , wherein the processing module further functions to perform one of:

when the other storage unit is not the authentic storage unit, denying the proxied data access request;

when the other storage unit is not the authentic storage unit:

identifying a second storage unit based on the encoded data slice and the previous distributed agreement protocol;

sending, via the interface, a request to the second storage unit to verify the proxied data access request; and

when verified, processing the request and sending, via the interface, a response to the second storage unit.

16. The storage unit of claim 9 , wherein the processing module further functions to:

receive, via the interface, the new version of the distributed agreement protocol and maintain the previous version of a distributed agreement protocol for processing data access requests regarding the one or more groups of encoded data slices during the transition of storage; and

when the transition of storage is complete, utilize the new version of a distributed agreement protocol for processing data access requests regarding the one or more groups of encoded data slices.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2016
From: MOTWANI, MANISH; RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039678/0255 →