IP Library Granted Patent US 10,506,045
Granted Patent B2
US 10,506,045 · App. 15/836,450 · Granted Dec 10, 2019

Memory access using deterministic function and secure seed

Inventors: Ilya Volvovski (Chicago, IL); Jason K. Resch (Chicago, IL)
Assignee: PURE STORAGE, INC.
H04L67/1097H03M13/3761H03M13/09H03M13/1515
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,506,045
App. No.
15/836,450
Granted
Dec 10, 2019
Kind
B2
Abstract

A processing device implementing a storage unit is included in a distributed storage network (DSN) that uses employing one or more storage units to store encoded data slices. The storage unit receives an access request that includes a slice identifier associated with an encoded data slice stored in a particular distributed storage (DS) memory of the storage unit. The storage unit obtains a secure seed, and determines a memory range associated with the slice identifier by performing a deterministic function on the slice identifier using the secure seed as an input to the deterministic function. The storage unit identifies the particular DS memory as being associated with the memory range, and performs the access request using the particular DS memory.

Claims (71)

1. A method for use in a processing device configured to implement a storage unit, the storage unit included in a distributed storage network (DSN) employing one or more storage units to store encoded data slices, the method comprising:

receiving, by the storage unit, an access request, the access request including a slice identifier associated with an encoded data slice stored in a particular distributed storage (DS) memory of the storage unit;

obtaining, by the storage unit, a secure seed;

determining, by the storage unit, a memory range associated with the slice identifier by performing a deterministic function on the slice identifier using the secure seed as an input to the deterministic function;

identifying, by the storage unit, the particular DS memory as being associated with the memory range; and

performing the access request using the particular DS memory.

2. The method of claim 1 , wherein obtaining the secure seed includes:

retrieving a previously generated secure seed from a secure memory in response to receiving the access request.

3. The method of claim 1 , wherein obtaining the secure seed includes:

generating the secure seed in response to receiving the access request; and

storing the secure seed in a secure memory.

4. The method of claim 1 , wherein obtaining the secure seed includes:

recovering the secure seed from a DS memory.

5. The method of claim 1 , further comprising:

performing the deterministic function on the slice identifier includes performing one of a hash based message authentication code function, a mask generating function, or a sponge function.

6. The method of claim 1 , further comprising:

selecting the deterministic function from a plurality of potential deterministic functions based on one or more of a predetermination, the slice identifier, a lookup, or a function identifier associated with the access request.

7. The method of claim 1 , wherein identifying the particular DS memory includes:

combining the memory range with a memory constant to produce a memory identifier identifying the particular DS memory.

8. A storage unit for use in a distributed storage network (DSN) employing one or more storage units to store encoded data slices, the storage unit comprising:

a processor and associated memory configured to implement a deterministic function module;

a plurality of distributed storage (DS) memories configured to store the encoded data slices;

an interface configured to receive an access request, the access request including a slice identifier associated with an encoded data slice stored in a particular DS memory of the storage unit;

the deterministic function module configured to:

obtain a secure seed;

determine a memory range associated with the slice identifier by performing a deterministic function on the slice identifier using the secure seed as an input to the deterministic function;

identify the particular DS memory as being associated with the memory range; and

the processor and associated memory further configured to:

perform the access request using the particular DS memory.

9. The storage unit of claim 8 , further comprising:

a secure memory; and

the deterministic function module being further configured to retrieve a previously generated secure seed from the secure memory.

10. The storage unit of claim 8 , further comprising:

a secure memory;

the deterministic function module being further configured to:

generate the secure seed in response to the access request; and

store the secure seed in a secure memory.

11. The storage unit of claim 8 , further comprising:

a secure memory; and

the deterministic function module being further configured to recover the secure seed from a DS memory included in the plurality of distributed storage (DS) memories.

12. The storage unit of claim 8 , the deterministic function module being further configured to:

perform the deterministic function on the slice identifier by using one of a hash based message authentication code function, a mask generating function, or a sponge function.

13. The storage unit of claim 8 , the deterministic function module being further configured to:

select the deterministic function from a plurality of potential deterministic functions based on one or more of a predetermination, the slice identifier, a lookup, or a function identifier associated with the access request.

14. The storage unit of claim 8 , wherein the deterministic function module is further configured to:

identify the particular DS memory by combining the memory range with a memory constant to produce a memory identifier identifying the particular DS memory.

15. A distributed storage network (DSN) memory for use in a distributed storage network (DSN), the DSN memory including:

a set of storage units storing encoded data slices, at least one storage unit included in a set of storage units includes:

a processor and associated memory configured to implement a deterministic function module;

a plurality of distributed storage (DS) memories configured to store the encoded data slices;

an interface configured to receive an access request, the access request including a slice identifier associated with an encoded data slice stored in a particular DS memory;

the deterministic function module configured to:

obtain a secure seed;

determine a memory range associated with the slice identifier by performing a deterministic function on the slice identifier using the secure seed as an input to the deterministic function;

identify the particular DS memory as being associated with the memory range; and

the processor and associated memory further configured to:

perform the access request using the particular DS memory.

16. The distributed storage network (DSN) memory of claim 15 , the at least one storage unit included in a set of storage units further including:

a secure memory;

the deterministic function module being further configured to:

generate the secure seed in response to the access request; and

store the secure seed in a secure memory.

17. The distributed storage network (DSN) memory of claim 15 , the at least one storage unit included in a set of storage units further including:

a secure memory; and

the deterministic function module being further configured to recover the secure seed from a DS memory included in the plurality of distributed storage (DS) memories.

18. The distributed storage network (DSN) memory of claim 15 , the deterministic function module being further configured to:

perform the deterministic function on the slice identifier by using one of a hash based message authentication code function, a mask generating function, or a sponge function.

19. The distributed storage network (DSN) memory of claim 15 , the deterministic function module being further configured to:

select the deterministic function from a plurality of potential deterministic functions based on one or more of a predetermination, the slice identifier, a lookup, or a function identifier associated with the access request.

20. The distributed storage network (DSN) memory of claim 15 , wherein the deterministic function module is further configured to:

identify the particular DS memory by combining the memory range with a memory constant to produce a memory identifier identifying the particular DS memory.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DELETE 15/174/279 AND 15/174/596 PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 49555 FRAME: 530. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 7, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 051495/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049555/0530 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2017
From: VOLVOVSKI, ILYA; RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044361/0159 →
Continuity (4)
Continuation In Part 15812706 · Nov 14, 2017
Continuation 14956818 · Dec 2, 2015
Provisional Application 62109712 · Jan 30, 2015
Related Publication 20180103101A1 · Apr 12, 2018