IP Library Granted Patent US 9,940,195
Granted Patent B2
US 9,940,195 · App. 15/718,200 · Granted Apr 10, 2018

Encryption of slice partials

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,940,195
App. No.
15/718,200
Granted
Apr 10, 2018
Kind
B2
Abstract

A method for use in a distributed storage network (DSN) including a plurality of distributed storage (DS) units includes receiving, at a DS unit, a rebuilding request indicating that the DS unit is to provide an encrypted partial slice to a requesting DS unit included in the DS network. Key pairing requirements associated with the rebuilding request are determined, and an even number of key pairing entities are selected based on the key pairing requirements. The even number of key pairing entities being fewer than a decode threshold number of key pairing entities. The DS unit generates shared secret keys corresponding to each of the even number of key pairing entities, uses those keys to generate an encrypted partial slice, and transmits the encrypted partial slice to the requesting DS unit in accordance with a rebuilding topology.

Claims (56)

1. A method for use in a distributed storage network (DSN) including a plurality of distributed storage (DS) units, the method comprising:

receiving, at a DS unit, a rebuilding request indicating that the DS unit is to provide an encrypted partial slice to a requesting DS unit included in the DS network;

determining key pairing requirements associated with the rebuilding request;

selecting an even number of key pairing entities based on the key pairing requirements, the even number of key pairing entities being fewer than a decode threshold number of key pairing entities, wherein the selecting an even number of key pairing entities includes optimizing a match of the key pairing requirements to an estimated performance and estimated security associated with a desired number of candidate key pairing entities;

generating shared secret keys corresponding to each of the even number of key pairing entities;

generating an encrypted partial slice by encrypting a partial slice associated with the DS unit using the shared secret keys corresponding to each of the even number of key pairing entities; and

transmitting the encrypted partial slice to the requesting DS unit in accordance with a rebuilding topology.

2. The method of claim 1 , further comprising:

determining candidate key pairing entities; and

selecting the even number of key pairing entities from among the candidate key pairing entities.

3. The method of claim 2 , further comprising:

determining candidate key pairing entities based on a rebuilding topology.

4. The method of claim 3 , further including:

selecting, as the even number of key pairing entities, a node ahead of the DS unit and a node behind the DS unit.

5. The method of claim 2 , further comprising:

determining candidate key pairing entities based on rebuilding participants.

6. The method of claim 1 , further comprising:

determining the key pairing requirements based on at least one of the following: the rebuilding request, a predetermination, a message, a DSN performance indicator, a DSN security indicator, a vault ID, or a requester ID.

7. A distributed storage (DS) unit included in a distributed storage network (DSN) including a plurality of DS units, the DS unit comprising:

a computing core including a processor and associated memory;

a communications interface, coupled to the computing core, and configured to receive a rebuilding request indicating that the DS unit is to provide an encrypted partial slice to a requesting DS unit included in the DS network;

the computing core configured to:

determine key pairing requirements associated with the rebuilding request;

select an even number of key pairing entities based on the key pairing requirements, the even number of key pairing entities being fewer than a decode threshold number of key pairing entities, wherein the selecting an even number of key pairing entities includes optimizing a match of the key pairing requirements to an estimated performance and estimated security associated with a desired number of candidate key pairing entities;

generate shared secret keys corresponding to each of the even number of key pairing entities;

generate an encrypted partial slice by encrypting a partial slice associated with the DS unit using the shared secret keys corresponding to each of the even number of key pairing entities; and

transmit the encrypted partial slice to the requesting DS unit in accordance with a rebuilding topology.

8. The distributed storage (DS) unit of claim 7 , further comprising:

determining candidate key pairing entities; and

selecting the even number of key pairing entities from among the candidate key pairing entities.

9. The distributed storage (DS) unit of claim 8 , further comprising:

determining candidate key pairing entities based on a rebuilding topology.

10. The distributed storage (DS) unit of claim 9 , further including:

selecting, as the even number of key pairing entities, a node ahead of the DS unit and a node behind the DS unit.

11. The distributed storage (DS) unit of claim 8 , further comprising:

determining candidate key pairing entities based on rebuilding participants.

12. The distributed storage (DS) unit of claim 7 , further comprising:

determining the key pairing requirements based on at least one of the following: the rebuilding request, a predetermination, a message, a DSN performance indicator, a DSN security indicator, a vault ID, or a requester ID.

13. A distributed storage network (DSN) comprising:

a plurality of distributed storage (DS) units each of the plurality of DS units including a processor and associated memory;

a requesting DS unit configured to transmit a rebuilding request to at least one other DS unit, the rebuilding request indicating that the at least one other DS unit is to provide an encrypted partial slice to the requesting DS unit;

the at least one other DS unit configured to respond to the rebuilding request by:

determining key pairing requirements associated with the rebuilding request;

selecting an even number of key pairing entities based on the key pairing requirements, the even number of key pairing entities being fewer than a decode threshold number of key pairing entities, wherein the selecting an even number of key pairing entities includes optimizing a match of the key pairing requirements to an estimated performance and estimated security associated with a desired number of candidate key pairing entities;

generating shared secret keys corresponding to each of the even number of key pairing entities;

generating an encrypted partial slice by encrypting a partial slice associated with the at least one other DS unit using the shared secret keys corresponding to each of the even number of key pairing entities; and

transmitting the encrypted partial slice to the requesting DS unit in accordance with a rebuilding topology.

14. The distributed storage network (DSN) of claim 13 , further comprising:

determining candidate key pairing entities; and

selecting the even number of key pairing entities from among the candidate key pairing entities.

15. The distributed storage network (DSN) of claim 14 , further comprising:

determining candidate key pairing entities based on at least one of a rebuilding topology or rebuilding participants.

16. The distributed storage network (DSN) of claim 15 , further including:

selecting, as the even number of key pairing entities, a node ahead of the at least one other DS unit and a node behind the at least one other DS unit.

17. The distributed storage network (DSN) of claim 13 , further comprising:

determining the key pairing requirements based on at least one of the following: the rebuilding request, a predetermination, a message, a DSN performance indicator, a DSN security indicator, a vault ID, or a requester ID.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2017
From: RESCH, JASON K.; DHUSE, GREG R.; LEGGETTE, WESLEY B.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 043724/0125 →