SECURE MESSAGE DELIVERY IN A DISPERSED STORAGE NETWORK
A method for sending a secure message within a dispersed storage network (DSN). The method begins with a source computing device sending a notice of a write communication operation to a destination computing device regarding the secure message and sending a set of write communication requests to a set of storage units, wherein the secure message is dispersed storage error encoded into a set of encoded data slices. The method continues by at least some storage units storing at least some encoded data slices in a communication vault. The method continues with the destination computing device sending at least a decode threshold number of write commit communication requests to at least a decode threshold number of storage units of the at some storage units. The method continues by the at least the decode threshold number of storage units sending encoded data slices to the destination computing device.
1 . A method for sending a secure message within a dispersed storage network (DSN), the method comprises:
sending, by a source computing device of the DSN, a notice of a write communication operation to a destination computing device of the DSN regarding the secure message;
sending, by the source computing device, a set of write communication requests to a set of storage units of the DSN, wherein the secure message is dispersed storage error encoded into a set of encoded data slices and wherein a first write communication request of the set of write communication requests includes a first encoded data slice of the set of encoded data slices and a secure code regarding the destination computing device;
storing, by at least some storage units of the set of storage units, at least some encoded data slices of the set of encoded data slices in a communication vault;
sending, by the destination computing device, at least a decode threshold number of write commit communication requests to the at least a decode threshold number of storage units of the set of storage units, wherein a write commit communication request of the at least the decode threshold number of write commit communication requests includes a slice name of one of the set of encoded data slices and the secure code; and
when the at least the decode threshold number of storage units has authenticated the destination computing device, sending, by the at least the decode threshold number of storage units, at least a decode threshold number of encoded data slices of the set of encoded data slices to the destination computing device.
2 . The method of claim 1 further comprises:
sending, by the source computing device, the notice of the write communication operation to include a source name of the secure message and an indication of a dispersed storage error encoding function, wherein the source name, when converted to a set of slice names for the set of encoded data slices, corresponds to DSN logical addresses within the communication vault.
3 . The method of claim 2 , wherein the storing, by a storage unit of the at least some storage units comprises:
receiving a write communication request of the set of write communication requests, wherein the write communication requests includes a slice name of the set of slice names and an encoded data slice of the set of encoded data slices;
interpreting the slice name to identify the communication vault and to forego conventional DSN write operation in favor of the write communication operation; and
storing the encoded data slice in the communication vault.
4 . The method of claim 2 further comprises:
generating, by the destination computing device, the set of slice names based on the source name;
identifying, by the destination computing device, the set of storage units based on the set of slice names; and
interpreting, by the destination computing device, the decode threshold number based on the indication of the dispersed storage error encoding function.
5 . The method of claim 1 , wherein the secure code comprises one or more of:
a user name;
a subject name;
a certificate;
a public key;
a secret key;
a fingerprint; and
a universally unique identifier (UUID).
6 . The method of claim 1 further comprises:
storing, by the at least some storage units, the at least some encoded data slices in the communication vault in a non-readable manner without transmitting write responses to the source computing device.
7 . The method of claim 1 further comprises:
decoding, by the destination computing device, the at least the decode threshold number of encoded data slices to recover the secure message.
8 . The method of claim 1 further comprises:
deleting the at least some encoded data slices of the set of encoded data slices in the communication vault after sending the at least some encoded data slices to the destination computing device.
9 . The method of claim 1 further comprises:
when the destination computing device is unable to recover the secure message, sending, by the destination computing device, a message to the source computing device to resend the secure message.
10 . A computer readable memory comprises:
a first memory section for storing operational instructions that, when executed by a source computing device, causes the source computing device to send a secure message within a dispersed storage network (DSN) by:
sending a notice of a write communication operation to a destination computing device of the DSN regarding the secure message;
sending a set of write communication requests to a set of storage units of the DSN, wherein the secure message is dispersed storage error encoded into a set of encoded data slices and wherein a first write communication request of the set of write communication requests includes a first encoded data slice of the set of encoded data slices and a secure code regarding the destination computing device;
a second memory section that stores operational instructions that, when executed by at least some storage units of the set of storage units, causes at least some storage units to:
store at least some encoded data slices of the set of encoded data slices in a communication vault;
a third memory section that stores operational instructions that, when executed by the destination computing device, causes the destination computing device to:
send at least a decode threshold number of write commit communication requests to the at least a decode threshold number of storage units of the set of storage units, wherein a write commit communication request of the at least the decode threshold number of write commit communication requests includes a slice name of one of the set of encoded data slices and the secure code; and
a fourth memory section that stores operational instructions that, when executed by the at least the decode threshold number of storage units, causes the at least the decode threshold number of storage units to:
when the at least the decode threshold number of storage units has authenticated the destination computing device, send at least a decode threshold number of encoded data slices of the set of encoded data slices to the destination computing device.
11 . The computer readable memory of claim 10 , wherein the first memory section further stores operational instructions that, when executing by the source computing device, causes the source computing device to:
send the notice of the write communication operation to include a source name of the secure message and an indication of a dispersed storage error encoding function, wherein the source name, when converted to a set of slice names for the set of encoded data slices, corresponds to DSN logical addresses within the communication vault.
12 . The computer readable memory of claim 11 , wherein the second memory section further stores operational instructions that, when executing by a storage unit of the at least some storage units, causes the storage unit to:
receive a write communication request of the set of write communication requests, wherein the write communication requests includes a slice name of the set of slice names and an encoded data slice of the set of encoded data slices;
interpret the slice name to identify the communication vault and to forego conventional DSN write operation in favor of the write communication operation; and
store the encoded data slice in the communication vault.
13 . The computer readable memory of claim 11 , wherein the third memory section further stores operational instructions that, when executing by the destination computing device, causes the destination computing device to:
generate the set of slice names based on the source name;
identify the set of storage units based on the set of slice names; and
interpret the decode threshold number based on the indication of the dispersed storage error encoding function.
14 . The computer readable memory of claim 10 , wherein the secure code comprises one or more of:
a user name;
a subject name;
a certificate;
a public key;
a secret key;
a fingerprint; and
a universally unique identifier (UUID).
15 . The computer readable memory of claim 10 , wherein the second memory section further stores operational instructions that, when executed by the at least some storage units, causes the at least some storage units to:
store the at least some encoded data slices in the communication vault in a non-readable manner without transmitting write responses to the source computing device.
16 . The computer readable memory of claim 10 , wherein the third memory section further stores operational instructions that, when executed by the destination computing device, causes the destination computing device to:
decode the at least the decode threshold number of encoded data slices to recover the secure message.
17 . The computer readable memory of claim 10 , wherein the fourth memory section further stores operational instructions that, when executed by the at least some storage units, causes the at least some storage units to:
delete the at least some encoded data slices of the set of encoded data slices in the communication vault after sending the at least some encoded data slices to the destination computing device.
18 . The computer readable memory of claim 10 , wherein the third memory section that further stores operational instructions that, when executed by the destination computing device, causes the destination computing device to:
when the destination computing device is unable to recover the secure message, send a message to the source computing device to resend the secure message.