IP Library Granted Patent US 10,127,402
Granted Patent B2
US 10,127,402 · App. 15/341,456 · Granted Nov 13, 2018

Systematic erasure code encoding of data packages

Inventor: Jason K. Resch (Chicago, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/6227G06F3/0604G06F3/067G06F3/0644G06F11/10G06F11/1076G06F11/2089G06F12/1408G06F21/602G06F21/6218G06F21/64H04L9/085H04L9/0861G06F15/17331G06F17/30283G06F2212/263G06F2221/2107H04L2209/24H04L2209/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,127,402
App. No.
15/341,456
Granted
Nov 13, 2018
Kind
B2
Abstract

A method begins by combining integrity information and a data segment to produce a data package. The data package is encrypted using a secret key to produce an encrypted data package, which is dispersed storage error encoded using a systematic erasure code, to produce a set of encoded encrypted slices. The secret key is encoded utilizing a secret sharing algorithm to produce a set of secret shares. The set of encoded encrypted slices is sent to a distributed storage network (DSN) memory for storage; and the set of secret shares is sent to the DSN memory for storage.

Claims (57)

1. A method of storing a data segment in a distributed storage (DS) processing unit, the method comprising:

combining integrity information and a data segment to produce a data package;

encrypting the data package using a secret key to produce an encrypted data package;

dispersed storage error encoding the encrypted data package, using a systematic erasure code employing first dispersed storage error coding parameters, to produce a set of encoded encrypted slices;

encoding the secret key utilizing a secret sharing algorithm to produce a set of secret shares, wherein the secret sharing algorithm employs second dispersed storage error coding parameters, and at least one parameter of the second dispersed storage error coding parameters is different from a corresponding parameter of the first dispersed storage error coding parameters;

sending the set of encoded encrypted slices to a distributed storage network (DSN) memory for storage; and

sending the set of secret shares to the DSN memory for storage.

2. The method of claim 1 , further comprising:

generating the integrity information for the data segment.

3. The method of claim 1 , wherein combining the integrity information includes:

interlacing the integrity information and the data segment.

4. The method of claim 1 , further comprising:

generating the secret key based on a deterministic function.

5. The method of claim 1 , wherein using the systematic erasure code includes:

matrix multiplying a data matrix of an encrypted data package with an encoding matrix including a unity matrix portion to produce a matrix of encoded codes.

6. The method of claim 5 , further comprising:

combining the matrix of encoded codes to produce the set of encoded encrypted slices.

7. The method of claim 1 , wherein encoding the secret key further comprises:

encoding the secret key utilizing a different decode threshold than used for encoding other data types.

8. A non-transitory computer readable medium tangibly embodying a program of computer executable instructions, the program of computer executable instructions including:

at least one instruction to combine integrity information and a data segment to produce a data package;

at least one instruction to encrypt the data package using a secret key to produce an encrypted data package;

at least one instruction to dispersed storage error encode the encrypted data package, using a systematic erasure code employing first dispersed storage error coding parameters, to produce a set of encoded encrypted slices;

at least one instruction to encode the secret key utilizing a secret sharing algorithm to produce a set of secret shares, wherein the secret sharing algorithm employs second dispersed storage error coding parameters, and at least one parameter of the second dispersed storage error coding parameters is different from a corresponding parameter of the first dispersed storage error coding parameters;

at least one instruction to send the set of encoded encrypted slices to a distributed storage network (DSN) memory for storage; and

at least one instruction to send the set of secret shares to the DSN memory for storage.

9. The non-transitory computer readable medium of claim 8 , further comprising:

at least one instruction to generate the integrity information for the data segment.

10. The non-transitory computer readable medium of claim 8 , wherein the at least one instruction to combine the integrity information includes:

at least one instruction to interlace the integrity information and the data segment.

11. The non-transitory computer readable medium of claim 8 , further comprising:

at least one instruction to generate the secret key based on a deterministic function.

12. The non-transitory computer readable medium of claim 8 , further comprising:

at least one instruction to matrix multiply a data matrix of an encrypted data package with an encoding matrix including a unity matrix portion to produce a matrix of encoded codes.

13. The non-transitory computer readable medium of claim 12 , further comprising:

at least one instruction to combine the matrix of encoded codes to produce the set of encoded encrypted slices.

14. The non-transitory computer readable medium of claim 8 , further comprising:

at least one instruction to encode the secret key utilizing a different decode threshold than used for encoding other data types.

15. A distributed storage (DS) processing unit comprising:

a processing unit;

memory coupled to the processing unit and configured to store a program of computer executable instructions, the program of computer executable instructions including:

at least one instruction to combine integrity information and a data segment to produce a data package;

at least one instruction to encrypt the data package using a secret key to produce an encrypted data package;

at least one instruction to dispersed storage error encode the encrypted data package, using a systematic erasure code employing first dispersed storage error coding parameters, to produce a set of encoded encrypted slices;

at least one instruction to encode the secret key utilizing a secret sharing algorithm to produce a set of secret shares, wherein the secret sharing algorithm employs second dispersed storage error coding parameters, and at least one parameter of the second dispersed storage error coding parameters is different from a corresponding parameter of the first dispersed storage error coding parameters;

at least one instruction to send the set of encoded encrypted slices to a distributed storage network (DSN) memory for storage; and

at least one instruction to send the set of secret shares to the DSN memory for storage.

16. The DS processing unit of claim 15 , the program of computer executable instructions further comprising:

at least one instruction to generate the integrity information for the data segment.

17. The DS processing unit of claim 15 , wherein the at least one instruction to combine the integrity information includes:

at least one instruction to append the integrity information to the data segment.

18. The DS processing unit of claim 15 , the program of computer executable instructions further comprising:

at least one instruction to generate the secret key based on a deterministic function.

19. The DS processing unit of claim 15 , the program of computer executable instructions further comprising:

at least one instruction to matrix multiply a data matrix of an encrypted data package with an encoding matrix including a unity matrix portion to produce a matrix of encoded codes.

20. The DS processing unit of claim 15 , the program of computer executable instructions further comprising:

at least one instruction to encode the secret key utilizing a different width and decode threshold than used for encoding other data slices.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2016
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 040198/0456 →
Continuity (3)
Continuation In Part 13463991 · May 4, 2012
Provisional Application 61493820 · Jun 6, 2011
Related Publication 20170053132A1 · Feb 23, 2017
Cited By (1)
US 12,677,438