IP Library Granted Patent US 10,325,110
Granted Patent B2
US 10,325,110 · App. 15/721,093 · Granted Jun 18, 2019

Distributing registry information in a dispersed storage network

Inventor: Wesley Leggette (Chicago, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/6218G06F21/6254G06F21/6272H04L63/0823H04L63/101H04L63/104H04L63/12H04L63/20H04L67/1097G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,325,110
App. No.
15/721,093
Granted
Jun 18, 2019
Kind
B2
Abstract

A method begins by a processing module of a dispersed storage network (DSN) generating a signed registry information packet, dispersed storage error encoding the signed registry information packet to produce a set of encoded registry information slices, and generating a set of signed encoded registry information slice packets for storage in storage units of the DSN. The method continues with the processing module retrieving a decode threshold number of signed encoded registry information slice packets. For each of the decode threshold number of signed encoded registry information slice packets, the method continues with the processing module recovering an encoded registry information slice. The method continues with the processing module dispersed storage error decoding a decode threshold number of recovered encoded registry information slices to reproduce the signed registry information packet, validating the signed registry information packet, and extracting registry information when the signed registry information packet is valid.

Claims (56)

1. A method for distributing registry information to computing devices of a dispersed storage network (DSN), the method comprises:

signing, by a managing unit of the DSN, the registry information with a certificate authority (CA) certificate to produce a signed registry information;

dispersed storage error encoding, by the managing unit, the signed registry information to produce a set of encoded registry information slices, wherein a decode threshold number of encoded registry information slices is needed to recover the signed registry information packet;

signing, by the managing unit, each encoded registry information slice with the CA certificate to produce a set of signed encoded registry information slices;

sending, by the managing unit, the set of signed encoded registry information slices to a set of storage units of the DSN for storage therein;

sending, by the managing unit, the CA certificate to a computing device of the computing devices;

retrieving, by the computing device, the decode threshold number of signed encoded registry information slices from at least some of the storage units of the set of storage units;

verifying, by the computing device, the CA certificate to produce a verified CA certificate;

verifying, by the computing device, each signed encoded registry information slice of the decode threshold number of signed encoded registry information slices based on the verified CA certificate to produce the decode threshold number of verified encoded registry information slices;

decoding, by the computing device, the decode threshold number of verified encoded registry information slices to recover the signed registry information; and

verifying, by the computing device, the signed registry information based on the verified CA certificate to recover the registry information.

2. The method of claim 1 , wherein the registry information comprises one or more of:

hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.

3. The method of claim 1 , wherein the CA certificate comprises:

an identifier of the CA;

an identifier of the managing unit; and

a public key of the CA.

4. The method of claim 1 further comprises:

signing, by the managing unit, the registry information with a registry information certificate that includes one or more of:

an identifier of the managing unit;

an identifier of the registry information; and

a public key of the managing unit.

5. The method of claim 1 further comprises:

signing, by the managing unit, each encoded registry information slice with a encoded registry information slice certificate that includes one or more of:

an identifier of the managing unit;

an identifier of the encoded registry information slice; and

a public key of the managing unit.

6. A computer readable storage device for storing operational instructions that enable distributing registry information to computing devices of a dispersed storage network (DSN), the computer readable storage device comprises:

a first memory section that stores operational instructions that, when executed by a managing unit of the DSN, causes the managing unit to:

sign the registry information with a certificate authority (CA) certificate to produce a signed registry information;

dispersed storage error encode the signed registry information to produce a set of encoded registry information slices, wherein a decode threshold number of encoded registry information slices is needed to recover the signed registry information packet;

sign each encoded registry information slice with the CA certificate to produce a set of signed encoded registry information slices;

send the set of signed encoded registry information slices to a set of storage units of the DSN for storage therein; and

send the CA certificate to a computing device of the computing devices;

a second memory section that stores operational instructions that, when executed by the computing device, causes the computing device to:

retrieve the decode threshold number of signed encoded registry information slices from at least some of the storage units of the set of storage units;

verify the CA certificate to produce a verified CA certificate;

verify each signed encoded registry information slice of the decode threshold number of signed encoded registry information slices based on the verified CA certificate to produce the decode threshold number of verified encoded registry information slices;

decode the decode threshold number of verified encoded registry information slices to recover the signed registry information; and

verify the signed registry information based on the verified CA certificate to recover the registry information.

7. The computer readable storage device of claim 6 , wherein the registry information comprises one or more of:

hardware configuration information, software version information, software, software configuration information, user group affiliation information, an access control list, system namespace information, and vault information.

8. The computer readable storage device of claim 6 , wherein the CA certificate comprises:

an identifier of the CA;

an identifier of the managing unit; and

a public key of the CA.

9. The computer readable storage device of claim 6 , wherein the first memory section further stores operational instructions that, when executed by the managing unit, causes the managing unit to:

sign the registry information with a registry information certificate that includes one or more of:

an identifier of the managing unit;

an identifier of the registry information; and

a public key of the managing unit.

10. The computer readable storage device of claim 6 , wherein the first memory section further stores operational instructions that, when executed by the managing unit, causes the managing unit to:

sign each encoded registry information slice with an encoded registry information slice certificate that includes one or more of:

an identifier of the managing unit;

an identifier of the encoded registry information slice; and

a public key of the managing unit.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0288 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2017
From: LEGGETTE, WESLEY
To: CLEVERSAFE, INC.
Reel/Frame 043745/0394 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2017
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044062/0222 →
Continuity (3)
Continuation 14610220 · Jan 30, 2015
Provisional Application 61974142 · Apr 2, 2014
Related Publication 20180039788A1 · Feb 8, 2018