MULTIPLE CREDENTIALS FOR MITIGATING IMPACT OF DATA ACCESS UNDER DURESS
A method includes generating a first plurality of representations of data. The method further includes encrypting the representations of the data using a plurality of access credentials to produce a plurality of encrypted representations of the data. The method further includes dispersed storage error encoding the encrypted representations of the data to produce set(s) of encoded data slices. The method further includes generating integrity data from the plurality of access credentials. The method further includes appending the integrity data to each encoded data slice of the set(s) of encoded data slices to produce set(s) of appended encoded data slices. The method further includes encrypting the set(s) of appended encoded data slices using a password to produce set(s) of encrypted encoded data slices. The method further includes sending the set(s) of encrypted encoded data slices to a set of storage units for storage therein.
1 . A method comprises:
generating, by a computing device of a dispersed storage network (DSN), a first plurality of representations of data;
encrypting, by the computing device, the plurality of representations of the data using a plurality of access credentials to produce a plurality of encrypted representations of the data, wherein a first access credential of the plurality of access credentials is used to encrypt a first representation of the data of the plurality of representations of the data;
dispersed storage error encoding, by the computing device, the plurality of encrypted representations of the data to produce at least one set of encoded data slices;
generating, by the computing device, a plurality of integrity data from the plurality of access credentials, wherein a first integrity data of the plurality of integrity data is generated from the first access credential;
appending, by the computing device, the plurality of integrity data to each encoded data slice of each of the at least one set of encoded data slices to produce at least one set of appended encoded data slices;
encrypting, by the computing device, the at least one set of appended encoded data slices using a password to produce at least one set of encrypted encoded data slices; and
sending, by the computing device, the at least one set of encrypted encoded data slices to a set of storage units for storage therein.
2 . The method of claim 1 , wherein the plurality of representations of the data comprises two or more of:
a full version of the data;
a limited version of the data;
null data; and
false data.
3 . The method of claim 1 further comprises:
receiving, by a device of the DSN, a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;
interpreting, by the device, the access credential to determine that the request has been submitted under duress; and
providing, by the device, an indication that the request has been submitted under duress to an authority device of the DSN.
4 . The method of claim 3 further comprises:
recovering, by the device or another device, the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;
utilizing, by the device of the other device, the access credential to decrypt one of the plurality of encrypted representations of the data to recover a particular representation of the data; and
providing, by the device or the other device, the particular representation of the data to the requesting entity.
5 . The method of claim 3 , wherein the interpreting the access credential to determine that the request has been submitted under duress comprises:
interpreting, by the device or the other device, integrity data of the plurality of integrity data that corresponds to the access credential, wherein the integrity data includes an indication that the access credential corresponds to a credential for use when an operator of the computing device is under duress to access data.
6 . The method of claim 1 further comprises:
receiving, by a device of the DSN, a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;
recovering, by the device, the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;
decrypting, by the device, the plurality of encrypted representations using the access credential to produce a plurality of decrypted data representations;
selecting, by the device, one of the plurality decrypted data representations based on a desired decryption processing of the plurality of encrypted representations using the access credential; and
sending, by the device, the one of the plurality decrypted data representations to the requesting device.
7 . The method of claim 1 further comprises:
selecting, by the computing device, the password from a plurality of passwords.
8 . A computer readable storage device comprises:
a first storage section that stores operational instructions that, when executed by a computing device of a dispersed storage network (DSN), causes the computing device to:
generate a first plurality of representations of data;
encrypt the plurality of representations of the data using a plurality of access credentials to produce a plurality of encrypted representations of the data, wherein a first access credential of the plurality of access credentials is used to encrypt a first representation of the data of the plurality of representations of the data;
dispersed storage error encode the plurality of encrypted representations of the data to produce at least one set of encoded data slices;
a second storage section that stores operational instructions that, when executed by the computing device, causes the computing device to:
generate a plurality of integrity data from the plurality of access credentials, wherein a first integrity data of the plurality of integrity data is generated from the first access credential;
append the plurality of integrity data to each encoded data slice of each of the at least one set of encoded data slices to produce at least one set of appended encoded data slices;
encrypt the at least one set of appended encoded data slices using a password to produce at least one set of encrypted encoded data slices; and
send the at least one set of encrypted encoded data slices to a set of storage units for storage therein.
9 . The computer readable storage device of claim 8 , wherein the plurality of representations of the data comprises two or more of:
a full version of the data;
a limited version of the data;
null data; and
false data.
10 . The computer readable storage device of claim 8 further comprises:
a third storage section that stores operational instructions that, when executed by a device of the DSN, causes the device to:
receive a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;
interpret the access credential to determine that the request has been submitted under duress; and
provide an indication that the request has been submitted under duress to an authority device of the DSN.
11 . The computer readable storage device of claim 10 further comprises:
a fourth storage section that stores operational instructions that, when executed by the device or another device of the DSN, causes the device or the other device to:
recover the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;
utilize the access credential to decrypt one of the plurality of encrypted representations of the data to recover a particular representation of the data; and
provide the particular representation of the data to the requesting entity.
12 . The computer readable storage device of claim 10 , wherein the third storage section further stores operational instructions that, when executed by the device, causes the device to interpret the access credential to determine that the request has been submitted under duress by:
interpreting, by the device or the other device, integrity data of the plurality of integrity data that corresponds to the access credential, wherein the integrity data includes an indication that the access credential corresponds to a credential for use when an operator of the computing device is under duress to access data.
13 . The computer readable storage device of claim 8 further comprises:
a third storage section that stores operational instructions that, when executed by a device of the DSN, causes the device to:
receive a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;
recover the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;
decrypt the plurality of encrypted representations using the access credential to produce a plurality of decrypted data representations;
select one of the plurality decrypted data representations based on a desired decryption processing of the plurality of encrypted representations using the access credential; and
send the one of the plurality decrypted data representations to the requesting device.
14 . The computer readable storage device of claim 8 further comprises:
a third storage section that stores operational instructions that, when executed by the computing device, causes the computing device to:
select the password from a plurality of passwords.