IP Library Granted Patent US 10,198,199
Granted Patent B2
US 10,198,199 · App. 15/353,166 · Granted Feb 5, 2019

Applying multiple hash functions to generate multiple masked keys in a secure slice implementation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,198,199
App. No.
15/353,166
Granted
Feb 5, 2019
Kind
B2
Abstract

Methods and apparatus for efficiently storing and accessing secure data are disclosed. The method of storing includes encrypting data utilizing an encryption key to produce encrypted data, performing deterministic functions on the encrypted data to produce deterministic function values, masking the encryption key utilizing the deterministic function values to produce masked keys and combining the encrypted data and the masked keys to produce a secure package. The method of accessing includes de-combining a secure package to reproduce encrypted data and masked keys, selecting a deterministic function, performing the selected deterministic function on the reproduced encrypted data to reproduce a deterministic function value, de-masking a corresponding masked key utilizing the reproduced deterministic function value to reproduce an encryption key, and decrypting the reproduced encrypted data utilizing the reproduced encryption key to reproduce data.

Claims (22)

1. A dispersed storage processing unit for use in a dispersed storage network, the dispersed storage processing unit comprising:

a communications interface;

a memory; and

a computer processor operably coupled to the memory and the communications interface, where the memory includes instructions for causing the computer processor to:

encrypt first data utilizing a first encryption key to produce first encrypted data;

perform a first plurality of deterministic functions on the first encrypted data to produce a first plurality of deterministic function values;

mask the first encryption key utilizing the first plurality of deterministic function values to produce a first plurality of masked keys;

combine the first encrypted data and the first plurality of masked keys to produce a first secure package;

receive, via the communications interface, a second secure package that differs from the first secure package;

de-combine the second secure package to reproduce second encrypted data and a second plurality of masked keys;

select a selected deterministic function of a second plurality of deterministic functions based on one or more characteristics of the second plurality of deterministic functions;

perform the selected deterministic function of the second plurality of deterministic functions on the second encrypted data to reproduce a reproduced deterministic function value;

de-mask a masked key of the second plurality of masked keys corresponding to the selected deterministic function of the second plurality of deterministic functions using the reproduced deterministic function value to produce a second encryption key; and

decrypt the second encrypted data utilizing the second encryption key to produce second data.

2. The dispersed storage processing unit of claim 1 , wherein the first plurality of deterministic function values each includes a number of bits that is equal to a number of bits of the first encryption key.

3. The dispersed storage processing unit of claim 1 , wherein the memory further comprises instructions for causing the computer processor to perform an exclusive OR function on first the encryption key and the first plurality of deterministic function values.

4. The dispersed storage processing unit of claim 1 , wherein combining the first encrypted data and the first plurality of masked keys to produce a first secure packages includes appending each of the first plurality of masked keys to the first encrypted data.

5. The dispersed storage processing unit of claim 1 , wherein the memory further comprises instructions for causing the computer processor to dispersed storage error encode the first secure package.

6. The dispersed storage processing unit of claim 1 , wherein de-combining the second secure package to reproduce second encrypted data and a second plurality of masked keys includes de-appending the second plurality of masked keys from the second encrypted data.

7. The dispersed storage processing unit of claim 1 , wherein the one or more characteristics of the second plurality of deterministic functions includes speed of execution.

8. The dispersed storage processing unit of claim 1 , wherein the one or more characteristics of the second plurality of deterministic functions includes processing efficiency of operation.

9. The dispersed storage processing unit of claim 1 , wherein the memory further comprises instructions for causing the computer processor to perform an exclusive OR function on the masked key of the second plurality of masked keys corresponding to the selected deterministic function of the second plurality of deterministic functions utilizing the reproduced deterministic function value.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 050451/0549 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2016
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 040345/0573 →