IP Library Granted Patent US 9,842,063
Granted Patent B2
US 9,842,063 · App. 15/345,262 · Granted Dec 12, 2017

Encrypting data for storage in a dispersed storage network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,842,063
App. No.
15/345,262
Granted
Dec 12, 2017
Kind
B2
Abstract

A method includes retrieving a plurality of secure data packages from storage units. The method further includes separating the secure data packages into masked keys and encrypted data units in accordance with a data intermingling pattern. The method further includes generating deterministic values from the encrypted data units and generating encryption keys based on the masked keys and the deterministic values. The method further includes decrypting the encrypted data units using the encryption keys to produce data units. The method further includes recovering a first portion of the data from a threshold number of the data units.

Claims (61)

1. A method for retrieving data, the method comprises:

retrieving, by a computing device of a dispersed storage network (DSN), a plurality of secure data packages from storage units of the DSN;

separating, by the computing device, the plurality of secure data packages into a plurality of masked keys and a plurality of encrypted data units in accordance with a data intermingling pattern, wherein the data intermingling pattern insures that, when a threshold number of encrypted data units are available, the plurality of masked keys is retrievable regardless of which encrypted data units of the plurality of encrypted data units are included in the threshold number of encrypted data units;

generating, by the computing device, a plurality of deterministic values from the plurality of encrypted data units;

generating, by the computing device, a plurality of encryption keys based on the plurality of masked keys and the plurality of deterministic values;

decrypting, by the computing device, the plurality of encrypted data units using the plurality of encryption keys to produce a plurality of data units; and

recovering, by the computing device, a first portion of the data from a threshold number of the plurality of data units.

2. The method of claim 1 , wherein the retrieving the plurality of secure data packages comprises:

retrieving a plurality of sets of encoded data slices; and

performing a dispersed storage error decoding function on the plurality of sets of encoded data slices to produce the plurality of secure data packages.

3. The method of claim 1 , wherein the generating the plurality of encryption keys comprises:

selecting one or more of the plurality of deterministic values in accordance with the data intermingling pattern; and

selecting one or more of the plurality of masked keys in accordance with the data intermingling pattern.

4. The method of claim 1 further comprises:

separating a first secure data package of the plurality of secure data packages into a first masked key of the plurality of masked keys and a first encrypted data unit of the plurality of encrypted data units;

generating a first deterministic value of the plurality of deterministic values from the first encrypted data unit;

generating a first encryption key of the plurality of encryption keys based on the first deterministic value; and

decrypting the first encrypted data unit using the first encryption key to produce a first data unit of the plurality of data units.

5. The method of claim 4 , wherein the generating the first encryption key comprises:

selecting a first masked key of the plurality of masked keys in accordance with a decode selecting approach; and

exclusive ORing the first masked key with the first deterministic value to produce the first encryption key.

6. The method of claim 1 further comprises:

separating a second secure data package of the plurality of secure data packages into a second masked key of the plurality of masked keys and a second encrypted data unit of the plurality of encrypted data units;

generating a second deterministic value of the plurality of deterministic values from the second encrypted data unit;

generating a second encryption key of the plurality of encryption keys based on the plurality of masked keys and the second deterministic value; and

decrypting the second encrypted data unit using the second encryption key to produce a second data unit of the plurality of data units.

7. The method of claim 6 , wherein the generating the second encryption key comprises:

selecting a second masked key of the plurality of masked keys in accordance with a decode selecting approach; and

exclusive ORing the second masked key with the second deterministic value to produce the second encryption key.

8. A computing device of a dispersed storage network (DSN), wherein the computing device comprises:

an interface;

memory; and

a processing module operably coupled to the interface and the memory, wherein the processing module is configured to:

retrieve, via the interface, a plurality of secure data packages from storage units of the DSN;

separate the plurality of secure data packages into a plurality of masked keys and a plurality of encrypted data units in accordance with a data intermingling pattern, wherein the data intermingling pattern insures that, when a threshold number of encrypted data units are available, the plurality of masked keys is retrievable regardless of which encrypted data units of the plurality of encrypted data units are included in the threshold number of encrypted data units;

generate a plurality of deterministic values from the plurality of encrypted data units;

generate a plurality of encryption keys based on the plurality of masked keys and the plurality of deterministic values;

decrypt the plurality of encrypted data units using the plurality of encryption keys to produce a plurality of data units; and

recover a first portion of the data from a threshold number of the plurality of data units.

9. The computing device of claim 8 , wherein the processing module is further configured to retrieve the plurality of secure data packages by:

retrieving a plurality of sets of encoded data slices; and

performing a dispersed storage error decoding function on the plurality of sets of encoded data slices to produce the plurality of secure data packages.

10. The computing device of claim 8 , wherein the processing module is further configured to generate the plurality of encryption keys by:

selecting one or more of the plurality of deterministic values in accordance with the data intermingling pattern; and

selecting one or more of the plurality of masked keys in accordance with the data intermingling pattern.

11. The computing device of claim 8 , wherein the processing module is further configured to:

separate a first secure data package of the plurality of secure data packages into a first masked key of the plurality of masked keys and a first encrypted data unit of the plurality of encrypted data units;

generate a first deterministic value of the plurality of deterministic values from the first encrypted data unit;

generate a first encryption key of the plurality of encryption keys based on the first deterministic value; and

decrypt the first encrypted data unit using the first encryption key to produce a first data unit of the plurality of data units.

12. The computing device of claim 11 , wherein the processing module is further configured to generate the first encryption key by:

selecting a first masked key of the plurality of masked keys in accordance with a decode selecting approach; and

exclusive ORing the first masked key with the first deterministic value to produce the first encryption key.

13. The computing device of claim 8 , wherein the processing module is further configured to:

separate a second secure data package of the plurality of secure data packages into a second masked key of the plurality of masked keys and a second encrypted data unit of the plurality of encrypted data units;

generate a second deterministic value of the plurality of deterministic values from the second encrypted data unit;

generate a second encryption key of the plurality of encryption keys based on the plurality of masked keys and the second deterministic value; and

decrypt the second encrypted data unit using the second encryption key to produce a second data unit of the plurality of data units.

14. The computing device of claim 13 , wherein the processing module is further configured to generate the second encryption key by:

selecting a second masked key of the plurality of masked keys in accordance with a decode selecting approach; and

exclusive ORing the second masked key with the second deterministic value to produce the second encryption key.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2017
From: GRUBE, GARY W.; MARKISON, TIMOTHY W.
To: CLEVERSAFE, INC.
Reel/Frame 041784/0923 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2017
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 042110/0957 →