LOGICALLY AND HIERARCHICALLY DELINEATED VAULTS
A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method begins by receiving an access request from a requesting entity. The method continues by determining a vault ID (identifier) based on the access request, identifying a vault configuration based on the vault ID, identifying a vault access range associated with the vault ID, and identifying a group associated with the requesting entity. The method continues by determining permissions for the group based on the vault configuration and the vault access range and authorizing the access request based on the permissions. When favorably authorized, the method continues by facilitating access to the DSN utilizing the vault configuration.
1 . A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:
receiving an access request from a requesting entity;
determining a vault ID (identifier) based on the access request;
identifying a vault configuration based on the vault ID;
identifying a vault access range associated with the vault ID;
identifying a group associated with the requesting entity;
determining permissions for the group based on the vault configuration and the vault access range; and
authorizing the access request based on the permissions; and
when favorably authorized, facilitating access to the DSN utilizing the vault configuration.
2 . The method of claim 1 , wherein the access request includes one or more of: a requesting entity identifier (ID), a data ID, or a request type.
3 . The method of claim 1 , wherein the determining a vault ID includes accessing at least one of a directory or an index to obtain a vault ID based on the access request.
4 . The method of claim 3 , wherein the determining a vault ID includes retrieving a DSN address from the index and extracting the vault ID from the DSN address.
5 . The method of claim 1 , wherein the identifying a vault configuration includes partitioning the vault ID to produce a vault configuration field and a vault access field, and performing a vault configuration look up based on an entry of the vault configuration field.
6 . The method of claim 5 , wherein the vault configuration entry provides access to a vault configuration table to retrieve configuration parameters for the vault.
7 . The method of claim 6 , wherein the facilitating includes one or more of: executing the request using the configuration parameters, forwarding the request to one or more other executing entities, or issuing a response to the requesting entity based on the execution of the access request.
8 . The method of claim 1 , wherein the determining permissions for the group includes performing a lookup in an access control list for the group based on the vault ID.
9 . The method of claim 1 , wherein the determining permissions for the group includes receiving permissions from a managing unit.
10 . The method of claim 1 , wherein the authorizing includes indicating authorized when the permissions compare favorably to the access request.
11 . The method of claim 1 , wherein the processing module is configured to indicate authorized when the access request includes a write access request and the permissions indicate that the group is authorized to perform the write access request for the vault ID.
12 . The method of claim 6 , wherein the executing the request includes encoding data of a write access request using a dispersed storage error coding function of the configuration parameters to produce a set of slices and issuing a set of write slice requests to a set of dispersed storage units of the configuration parameters where the set of write slice requests includes a set of slices.
13 . A computing device of a group of computing devices of a dispersed storage network (DSN), the computing device comprises:
an interface;
a local memory; and
a processing module operably coupled to the interface and the local memory, wherein the processing module functions to:
receive an access request from a requesting entity;
determine a vault ID (identifier) based on the access request;
identify a vault configuration based on the vault ID;
identify a vault access range associated with the vault ID;
identify a group associated with the requesting entity;
determine permissions for the group based on the vault configuration and the vault access range; and
authorize the access request based on the permissions; and
when favorably authorized, facilitate access to the DSN utilizing the vault configuration.
14 . The computing device of claim 13 , wherein the access request includes one or more of: a requesting entity identifier (ID), a data ID, or a request type.
15 . The computing device of claim 13 , wherein the determine a vault ID includes accessing at least one of a directory or an index to obtain a vault ID based on the access request.
16 . The computing device of claim 15 , wherein the determine a vault ID includes retrieving a DSN address from the index and extracting the vault ID from the DSN address.
17 . The computing device of claim 13 , wherein the identify a vault configuration includes partitioning the vault ID to produce a vault configuration field and a vault access field, and performing a vault configuration look up based on an entry of the vault configuration field.
18 . The computing device of claim 17 , wherein the vault configuration entry provides access to a vault configuration table to retrieve configuration parameters for the vault.
19 . The computing device of claim 13 , wherein the determine permissions for the group includes performing a lookup in an access control list for the group based on the vault ID.
20 . The computing device of claim 13 , wherein the authorize includes indicating authorized when the permissions compare favorably to the access request.