IP Library Patent Application 15728276
Patent Application
App. No. 15/728,276

MULTIPLE CREDENTIALS FOR MITIGATING IMPACT OF DATA ACCESS UNDER DURESS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/728,276
Abstract

A method includes generating a first plurality of representations of data. The method further includes encrypting the representations of the data using a plurality of access credentials to produce a plurality of encrypted representations of the data. The method further includes dispersed storage error encoding the encrypted representations of the data to produce set(s) of encoded data slices. The method further includes generating integrity data from the plurality of access credentials. The method further includes appending the integrity data to each encoded data slice of the set(s) of encoded data slices to produce set(s) of appended encoded data slices. The method further includes encrypting the set(s) of appended encoded data slices using a password to produce set(s) of encrypted encoded data slices. The method further includes sending the set(s) of encrypted encoded data slices to a set of storage units for storage therein.

Claims (68)

1 . A method comprises:

generating, by a computing device of a dispersed storage network (DSN), a first plurality of representations of data;

encrypting, by the computing device, the plurality of representations of the data using a plurality of access credentials to produce a plurality of encrypted representations of the data, wherein a first access credential of the plurality of access credentials is used to encrypt a first representation of the data of the plurality of representations of the data;

dispersed storage error encoding, by the computing device, the plurality of encrypted representations of the data to produce at least one set of encoded data slices;

generating, by the computing device, a plurality of integrity data from the plurality of access credentials, wherein a first integrity data of the plurality of integrity data is generated from the first access credential;

appending, by the computing device, the plurality of integrity data to each encoded data slice of each of the at least one set of encoded data slices to produce at least one set of appended encoded data slices;

encrypting, by the computing device, the at least one set of appended encoded data slices using a password to produce at least one set of encrypted encoded data slices; and

sending, by the computing device, the at least one set of encrypted encoded data slices to a set of storage units for storage therein.

2 . The method of claim 1 , wherein the plurality of representations of the data comprises two or more of:

a full version of the data;

a limited version of the data;

null data; and

false data.

3 . The method of claim 1 further comprises:

receiving, by a device of the DSN, a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;

interpreting, by the device, the access credential to determine that the request has been submitted under duress; and

providing, by the device, an indication that the request has been submitted under duress to an authority device of the DSN.

4 . The method of claim 3 further comprises:

recovering, by the device or another device, the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;

utilizing, by the device of the other device, the access credential to decrypt one of the plurality of encrypted representations of the data to recover a particular representation of the data; and

providing, by the device or the other device, the particular representation of the data to the requesting entity.

5 . The method of claim 3 , wherein the interpreting the access credential to determine that the request has been submitted under duress comprises:

interpreting, by the device or the other device, integrity data of the plurality of integrity data that corresponds to the access credential, wherein the integrity data includes an indication that the access credential corresponds to a credential for use when an operator of the computing device is under duress to access data.

6 . The method of claim 1 further comprises:

receiving, by a device of the DSN, a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;

recovering, by the device, the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;

decrypting, by the device, the plurality of encrypted representations using the access credential to produce a plurality of decrypted data representations;

selecting, by the device, one of the plurality decrypted data representations based on a desired decryption processing of the plurality of encrypted representations using the access credential; and

sending, by the device, the one of the plurality decrypted data representations to the requesting device.

7 . The method of claim 1 further comprises:

selecting, by the computing device, the password from a plurality of passwords.

8 . A computer readable storage device comprises:

a first storage section that stores operational instructions that, when executed by a computing device of a dispersed storage network (DSN), causes the computing device to:

generate a first plurality of representations of data;

encrypt the plurality of representations of the data using a plurality of access credentials to produce a plurality of encrypted representations of the data, wherein a first access credential of the plurality of access credentials is used to encrypt a first representation of the data of the plurality of representations of the data;

dispersed storage error encode the plurality of encrypted representations of the data to produce at least one set of encoded data slices;

a second storage section that stores operational instructions that, when executed by the computing device, causes the computing device to:

generate a plurality of integrity data from the plurality of access credentials, wherein a first integrity data of the plurality of integrity data is generated from the first access credential;

append the plurality of integrity data to each encoded data slice of each of the at least one set of encoded data slices to produce at least one set of appended encoded data slices;

encrypt the at least one set of appended encoded data slices using a password to produce at least one set of encrypted encoded data slices; and

send the at least one set of encrypted encoded data slices to a set of storage units for storage therein.

9 . The computer readable storage device of claim 8 , wherein the plurality of representations of the data comprises two or more of:

a full version of the data;

a limited version of the data;

null data; and

false data.

10 . The computer readable storage device of claim 8 further comprises:

a third storage section that stores operational instructions that, when executed by a device of the DSN, causes the device to:

receive a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;

interpret the access credential to determine that the request has been submitted under duress; and

provide an indication that the request has been submitted under duress to an authority device of the DSN.

11 . The computer readable storage device of claim 10 further comprises:

a fourth storage section that stores operational instructions that, when executed by the device or another device of the DSN, causes the device or the other device to:

recover the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;

utilize the access credential to decrypt one of the plurality of encrypted representations of the data to recover a particular representation of the data; and

provide the particular representation of the data to the requesting entity.

12 . The computer readable storage device of claim 10 , wherein the third storage section further stores operational instructions that, when executed by the device, causes the device to interpret the access credential to determine that the request has been submitted under duress by:

interpreting, by the device or the other device, integrity data of the plurality of integrity data that corresponds to the access credential, wherein the integrity data includes an indication that the access credential corresponds to a credential for use when an operator of the computing device is under duress to access data.

13 . The computer readable storage device of claim 8 further comprises:

a third storage section that stores operational instructions that, when executed by a device of the DSN, causes the device to:

receive a request to retrieve the data from a requesting entity, wherein the request is accompanied with an access credential of the plurality of access credentials;

recover the plurality of encrypted representations of the data from at least a portion of the at least one set of encrypted encoded data slices;

decrypt the plurality of encrypted representations using the access credential to produce a plurality of decrypted data representations;

select one of the plurality decrypted data representations based on a desired decryption processing of the plurality of encrypted representations using the access credential; and

send the one of the plurality decrypted data representations to the requesting device.

14 . The computer readable storage device of claim 8 further comprises:

a third storage section that stores operational instructions that, when executed by the computing device, causes the computing device to:

select the password from a plurality of passwords.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE DELETE 15/174/279 AND 15/174/596 PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 49555 FRAME: 530. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 7, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 051495/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049555/0530 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2017
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 043817/0209 →