IP Library Granted Patent US 10,223,213
Granted Patent B2
US 10,223,213 · App. 15/804,081 · Granted Mar 5, 2019

Salted zero expansion all or nothing transformation

Inventor: Jason K. Resch (Chicago, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F11/1469G06F11/1092G06F11/1448G06F17/30194G06F17/30227H04L67/1097G06F2211/1028H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,223,213
App. No.
15/804,081
Granted
Mar 5, 2019
Kind
B2
Abstract

A method for execution by a dispersed storage network (DSN), the method begins by injecting generated data into a data segment to produce mixed data, partitioning the mixed data to produce first and second data partitions, performing a deterministic function on the first data partition to produce a first key, encrypting the second data partition using the first key to produce an encrypted second data partition, performing the deterministic function on the encrypted second data partition to produce a second key, encrypting the first data partition using the second key to produce an encrypted first data partition, performing the deterministic function on the encrypted first data partition to produce a third key, encrypting the encrypted second data partition to produce a re-encrypted second data partition, aggregating the encrypted first data partition and the re-encrypted second data partition to produce a secure package, and encoding the secure package and storing.

Claims (79)

1. A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:

facilitating retrieving a set of encoded data slices from a dispersed storage network (DSN) memory;

facilitating decoding the set of encoded data slices using a dispersed storage error encoding function to reproduce a secure package;

de-aggregating the secure package in accordance with an aggregation scheme to reproduce an encrypted first data partition and a re-encrypted second data partition;

performing a deterministic function on the encrypted first data partition to reproduce a third key, where the deterministic function is substantially the same as a deterministic function utilized by a transforming data function to produce the third key;

decrypting the re-encrypted second data partition using the third key to reproduce an encrypted second data partition;

performing the deterministic function on the encrypted second data partition to reproduce a second key, where the deterministic function is substantially the same as a deterministic function utilized by the transforming data function to produce the second key;

decrypting the encrypted first data partition using the second key to reproduce a first data partition;

performing the deterministic function on the first data partition to reproduce a first key, where the deterministic function is substantially the same as a deterministic function utilized by the transforming data function to produce the first key;

decrypting the encrypted second data partition using the first key to reproduce a second data partition;

de-partitioning the first and second data partitions in accordance with a partitioning approach to reproduce mixed data, where the partitioning approach is substantially the same as a partitioning approach utilized by the transforming data function to reproduce the mixed data; and

extracting a data segment from the mixed data in accordance with a data injection scheme, where the data injection scheme is substantially the same as a data injection scheme utilized by the transforming data function inject generated data into the data segment to produce the mixed data.

2. The method of claim 1 further comprising validating the data segment by comparing extracted check bytes of the mixed data to expected check bytes.

3. The method of claim 2 , wherein the validating includes retrieving the expected check bytes from a local memory, extracting the check bytes in accordance with the data injection scheme from the mixed data, comparing the extracted check bytes to the expected check bytes, and indicating that the data segment is valid when the comparison is favorable.

4. The method of claim 3 , wherein the data segment is valid when not tampered with.

5. The method of claim 3 , wherein the comparison is favorable when the extracted check bytes to the expected check bytes are substantially the same.

6. The method of claim 1 , wherein the facilitating includes at least one of:

issuing slice retrieval requests or receiving at least a decode threshold number of encoded data slices of the set of encoded data slices from the DSN memory.

7. The method of claim 1 , wherein the facilitating includes decoding at least a decode threshold number of encoded data slices of the set of encoded data slices using the dispersed storage error coding function to reproduce the secure package.

8. A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:

injecting generated data into a data segment to produce mixed data in accordance with a data injection scheme;

partitioning the mixed data in accordance with a partitioning approach to produce first and second data partitions;

performing a deterministic function on the first data partition to produce a first key;

encrypting the second data partition using the first key to produce an encrypted second data partition;

performing the deterministic function on the encrypted second data partition to produce a second key;

encrypting the first data partition using the second key to produce an encrypted first data partition;

performing the deterministic function on the encrypted first data partition to produce a third key;

encrypting the encrypted second data partition using the third key to produce a re-encrypted second data partition;

aggregating the encrypted first data partition and the re-encrypted second data partition in accordance with an aggregation scheme to produce a secure package;

facilitating encoding the secure package using a dispersed storage error coding function to produce a set of encoded data slices; and

facilitating storing the set of encoded data slices in a dispersed storage network (DSN) memory.

9. The method of claim 8 , wherein the injecting includes generating the generated data by one or more of: retrieving, generating a plurality of random bytes, or generating a plurality of check bytes.

10. The method of claim 8 , wherein the partitioning is at a ratio of 50/50 or 60/40.

11. The method of claim 8 , wherein the performing a deterministic function on the first data partition includes performing a hashing function on the first data partition to produce an interim result and truncating the interim result to produce the first key with a desired number of bits.

12. The method of claim 8 , wherein the aggregating includes at least one of: interleaving or appending.

13. The method of claim 8 , wherein the facilitating encoding encodes the secure package using the dispersed storage error coding function to produce the set of encoded data slices.

14. The method of claim 8 , wherein the facilitating storing includes at least one of: sending the set of encoded data slices to an output module or outputting the set of encoded data slices to the DSN memory.

15. The method of claim 8 further comprises:

facilitating retrieving a set of encoded data slices from a dispersed storage network (DSN) memory;

facilitating decoding the set of encoded data slices using a dispersed storage error encoding function to reproduce a secure package;

de-aggregating the secure package in accordance with an aggregation scheme to reproduce an encrypted first data partition and a re-encrypted second data partition;

performing a deterministic function on the encrypted first data partition to reproduce a third key, where the deterministic function is substantially the same as a deterministic function utilized by a transforming data function to produce the third key;

decrypting the re-encrypted second data partition using the third key to reproduce an encrypted second data partition;

performing the deterministic function on the encrypted second data partition to reproduce a second key, where the deterministic function is substantially the same as a deterministic function utilized by the transforming data function to produce the second key;

decrypting the encrypted first data partition using the second key to reproduce a first data partition;

performing the deterministic function on the first data partition to reproduce a first key, where the deterministic function is substantially the same as a deterministic function utilized by the transforming data function to produce the first key;

decrypting the encrypted second data partition using the first key to reproduce a second data partition;

de-partitioning the first and second data partitions in accordance with a partitioning approach to reproduce mixed data, where the partitioning approach is substantially the same as a partitioning approach utilized by the transforming data function to reproduce the mixed data; and

extracting a data segment from the mixed data in accordance with a data injection scheme, where the data injection scheme is substantially the same as a data injection scheme utilized by the transforming data function inject generated data into the data segment to produce the mixed data.

16. A computing device of a group of computing devices of a dispersed storage network (DSN), the computing device comprises:

an interface;

a local memory; and

a processing module operably coupled to the interface and the local memory, wherein the processing module functions to:

inject generated data into a data segment to produce mixed data in accordance with a data injection scheme;

partition the mixed data in accordance with a partitioning approach to produce first and second data partitions;

perform a deterministic function on the first data partition to produce a first key;

encrypt the second data partition using the first key to produce an encrypted second data partition;

perform the deterministic function on the encrypted second data partition to produce a second key;

encrypt the first data partition using the second key to produce an encrypted first data partition;

perform the deterministic function on the encrypted first data partition to produce a third key;

encrypt the encrypted second data partition using the third key to produce a re-encrypted second data partition;

aggregate the encrypted first data partition and the re-encrypted second data partition in accordance with an aggregation scheme to produce a secure package;

facilitate encoding the secure package using a dispersed storage error coding function to produce a set of encoded data slices; and

facilitate storing the set of encoded data slices in a dispersed storage network (DSN) memory.

17. The computing device of claim 16 further comprises:

facilitating retrieving a set of encoded data slices from a dispersed storage network (DSN) memory;

facilitating decoding the set of encoded data slices using a dispersed storage error encoding function to reproduce a secure package;

de-aggregating the secure package in accordance with an aggregation scheme to reproduce an encrypted first data partition and a re-encrypted second data partition;

performing a deterministic function on the encrypted first data partition to reproduce a third key, where the deterministic function is substantially the same as a deterministic function utilized by a transforming data function to produce the third key;

decrypting the re-encrypted second data partition using the third key to reproduce an encrypted second data partition;

performing the deterministic function on the encrypted second data partition to reproduce a second key, where the deterministic function is substantially the same as a deterministic function utilized by the transforming data function to produce the second key;

decrypting the encrypted first data partition using the second key to reproduce a first data partition;

performing the deterministic function on the first data partition to reproduce a first key, where the deterministic function is substantially the same as a deterministic function utilized by the transforming data function to produce the first key;

decrypting the encrypted second data partition using the first key to reproduce a second data partition;

de-partitioning the first and second data partitions in accordance with a partitioning approach to reproduce mixed data, where the partitioning approach is substantially the same as a partitioning approach utilized by the transforming data function to reproduce the mixed data; and

extracting a data segment from the mixed data in accordance with a data injection scheme, where the data injection scheme is substantially the same as a data injection scheme utilized by the transforming data function to inject generated data into the data segment to produce the mixed data.

18. The computing device of claim 16 , wherein the data injection scheme includes generating the generated data by one or more of: retrieving, generating a plurality of random bytes, or generating a plurality of check bytes.

19. The computing device of claim 16 , wherein the performing the deterministic function on the first data partition to reproduce a first key includes a hashing function on the first data partition to produce an interim result and truncation of the interim result to produce the first key with a desired number of bits.

20. The computing device of claim 16 , wherein the aggregation scheme includes at least one of interleaving or appending.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2017
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044038/0937 →
Continuity (4)
Continuation In Part 15276077 · Sep 26, 2016
Continuation 14215542 · Mar 17, 2014
Provisional Application 61819039 · May 3, 2013
Related Publication 20180060186A1 · Mar 1, 2018