IP Library Patent Application 15795636
Patent Application
App. No. 15/795,636

LOGICALLY AND HIERARCHICALLY DELINEATED VAULTS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/795,636
Abstract

A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method begins by receiving an access request from a requesting entity. The method continues by determining a vault ID (identifier) based on the access request, identifying a vault configuration based on the vault ID, identifying a vault access range associated with the vault ID, and identifying a group associated with the requesting entity. The method continues by determining permissions for the group based on the vault configuration and the vault access range and authorizing the access request based on the permissions. When favorably authorized, the method continues by facilitating access to the DSN utilizing the vault configuration.

Claims (39)

1 . A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:

receiving an access request from a requesting entity;

determining a vault ID (identifier) based on the access request;

identifying a vault configuration based on the vault ID;

identifying a vault access range associated with the vault ID;

identifying a group associated with the requesting entity;

determining permissions for the group based on the vault configuration and the vault access range; and

authorizing the access request based on the permissions; and

when favorably authorized, facilitating access to the DSN utilizing the vault configuration.

2 . The method of claim 1 , wherein the access request includes one or more of: a requesting entity identifier (ID), a data ID, or a request type.

3 . The method of claim 1 , wherein the determining a vault ID includes accessing at least one of a directory or an index to obtain a vault ID based on the access request.

4 . The method of claim 3 , wherein the determining a vault ID includes retrieving a DSN address from the index and extracting the vault ID from the DSN address.

5 . The method of claim 1 , wherein the identifying a vault configuration includes partitioning the vault ID to produce a vault configuration field and a vault access field, and performing a vault configuration look up based on an entry of the vault configuration field.

6 . The method of claim 5 , wherein the vault configuration entry provides access to a vault configuration table to retrieve configuration parameters for the vault.

7 . The method of claim 6 , wherein the facilitating includes one or more of: executing the request using the configuration parameters, forwarding the request to one or more other executing entities, or issuing a response to the requesting entity based on the execution of the access request.

8 . The method of claim 1 , wherein the determining permissions for the group includes performing a lookup in an access control list for the group based on the vault ID.

9 . The method of claim 1 , wherein the determining permissions for the group includes receiving permissions from a managing unit.

10 . The method of claim 1 , wherein the authorizing includes indicating authorized when the permissions compare favorably to the access request.

11 . The method of claim 1 , wherein the processing module is configured to indicate authorized when the access request includes a write access request and the permissions indicate that the group is authorized to perform the write access request for the vault ID.

12 . The method of claim 6 , wherein the executing the request includes encoding data of a write access request using a dispersed storage error coding function of the configuration parameters to produce a set of slices and issuing a set of write slice requests to a set of dispersed storage units of the configuration parameters where the set of write slice requests includes a set of slices.

13 . A computing device of a group of computing devices of a dispersed storage network (DSN), the computing device comprises:

an interface;

a local memory; and

a processing module operably coupled to the interface and the local memory, wherein the processing module functions to:

receive an access request from a requesting entity;

determine a vault ID (identifier) based on the access request;

identify a vault configuration based on the vault ID;

identify a vault access range associated with the vault ID;

identify a group associated with the requesting entity;

determine permissions for the group based on the vault configuration and the vault access range; and

authorize the access request based on the permissions; and

when favorably authorized, facilitate access to the DSN utilizing the vault configuration.

14 . The computing device of claim 13 , wherein the access request includes one or more of: a requesting entity identifier (ID), a data ID, or a request type.

15 . The computing device of claim 13 , wherein the determine a vault ID includes accessing at least one of a directory or an index to obtain a vault ID based on the access request.

16 . The computing device of claim 15 , wherein the determine a vault ID includes retrieving a DSN address from the index and extracting the vault ID from the DSN address.

17 . The computing device of claim 13 , wherein the identify a vault configuration includes partitioning the vault ID to produce a vault configuration field and a vault access field, and performing a vault configuration look up based on an entry of the vault configuration field.

18 . The computing device of claim 17 , wherein the vault configuration entry provides access to a vault configuration table to retrieve configuration parameters for the vault.

19 . The computing device of claim 13 , wherein the determine permissions for the group includes performing a lookup in an access control list for the group based on the vault ID.

20 . The computing device of claim 13 , wherein the authorize includes indicating authorized when the permissions compare favorably to the access request.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE DELETE 15/174/279 AND 15/174/596 PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 49555 FRAME: 530. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 7, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 051495/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049555/0530 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2017
From: VOLVOVSKI, ILYA; GLADWIN, S. CHRISTOPHER; GRUBE, GARY W.; MARKISON, TIMOTHY W.; RESCH, JASON K.; SHIRLEY, THOMAS F., JR.; DHUSE, GREG R.; MOTWANI, MANISH; BAPTIST, ANDREW D.; LEGGETTE, WESLEY B.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 043969/0283 →