IP Library Granted Patent US 10,372,357
Granted Patent B2
US 10,372,357 · App. 16/102,940 · Granted Aug 6, 2019

Securely recovering stored data in a dispersed storage network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,372,357
App. No.
16/102,940
Granted
Aug 6, 2019
Kind
B2
Abstract

A method for execution by a dispersed storage and task (DST) execution unit that includes a processor includes receiving a slice pre-image request from a computing device via a network that indicates a data slice, a requesting entity and a plurality of storage units. A data pre-image is generated by performing a pre-image function on the data slice based on the plurality of storage units. An encrypted data pre-image is generated for transmission to the computing device by performing an encryption function on the data pre-image based on a key associated with the requesting entity.

Claims (39)

1. A method for execution by a dispersed storage and task (DST) execution unit that includes a hardware processor, the method comprises:

generating, based on a slice pre-image request from a computing device, a data pre-image by performing a pre-image function on a data slice based on a plurality of storage units indicated in the request; and

generating an encrypted data pre-image for transmission to the computing device by performing an encryption function on the data pre-image based on a key associated with a requesting entity;

wherein the computing device receives a plurality of encrypted data pre-images from a plurality of storage units that includes the DST execution unit for transmission to the requesting entity for decoding;

wherein the requesting entity receives a plurality of storage unit identifiers corresponding to the plurality of storage units from the computing device, and wherein the requesting entity decodes the plurality of encrypted data pre-images by utilizing a plurality of unique keys, each associated with one of the plurality of storage units; and

wherein the requesting entity receives a sum of the encrypted data pre-images from the computing device, and wherein decoding includes subtracting each of the plurality of unique keys from the sum of the encrypted data pre-images.

2. The method of claim 1 , wherein the slice pre-image request indicates the data slice, the requesting entity, and the plurality of storage units.

3. The method of claim 1 , wherein the pre-image function includes creating a vector that includes the data slice.

4. The method of claim 3 , wherein the pre-image function further includes creating a decode matrix based on the plurality of storage units.

5. The method of claim 4 , wherein the pre-image function further includes performing matrix multiplication on the vector and the decode matrix.

6. The method of claim 1 , wherein generating the encryption function includes applying the key additively to the data pre-image.

7. The method of claim 1 , further comprising generating a message authentication code based on the data slice for transmission to the computing device.

8. The method of claim 1 , wherein the key is established based on at least one of: a public-key system or a key agreement protocol.

9. A processing system of a dispersed storage and task (DST) execution unit comprises:

at least one hardware processor;

a memory that stores operational instructions, that when executed by the at least one hardware processor cause the processing system to perform operations including:

generating, based on a slice pre-image request from a computing device, a data pre-image by performing a pre-image function on a data slice based on a plurality of storage units indicated in the request; and

generating an encrypted data pre-image for transmission to the computing device by performing an encryption function on the data pre-image based on a key associated with a requesting entity;

wherein the computing device receives a plurality of encrypted data pre-images from a plurality of storage units that includes the DST execution unit for transmission to the requesting entity for decoding;

wherein the requesting entity receives a plurality of storage unit identifiers corresponding to the plurality of storage units from the computing device, and wherein the requesting entity decodes the plurality of encrypted data pre-images by utilizing a plurality of unique keys, each associated with one of the plurality of storage units; and

wherein the requesting entity receives a sum of the encrypted data pre-images from the computing device, and wherein decoding includes subtracting each of the plurality of unique keys from the sum of the encrypted data pre-images.

10. The processing system of claim 9 , wherein the pre-image function includes creating a vector that includes the data slice, creating a decode matrix based on the plurality of storage units, and performing matrix multiplication on the vector and the decode matrix.

11. The processing system of claim 9 , wherein generating the encryption function includes applying the key additively to the data pre-image.

12. The processing system of claim 9 , wherein the operations further include:

generating a message authentication code based on the data slice for transmission to the computing device.

13. The processing system of claim 9 , wherein the key is established based on at least one of: a public-key system or a key agreement protocol.

14. The processing system of claim 9 , wherein the slice pre-image request indicates the data slice, the requesting entity, and the plurality of storage units.

15. A non-transitory computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by a processing system of a dispersed storage and task (DST) execution unit that includes a hardware processor and a memory, causes the processing system to perform operations including:

generating, based on a slice pre-image request from a computing device, a data pre-image by performing a pre-image function on a data slice based on a plurality of storage units indicated in the request; and

generating an encrypted data pre-image for transmission to the computing device by performing an encryption function on the data pre-image based on a Key associated with a requesting entity;

wherein the computing device receives a plurality of encrypted data pre-images from a plurality of storage units that includes the DST execution unit for transmission to the requesting entity for decoding;

wherein the requesting entity receives a plurality of storage unit identifiers corresponding to the plurality of storage units from the computing device, and wherein the requesting entity decodes the plurality of encrypted data pre-images by utilizing a plurality of unique keys, each associated with one of the plurality of storage units; and

wherein the requesting entity receives a sum of the encrypted data pre-images from the computing device, and wherein decoding includes subtracting each of the plurality of unique keys from the sum of the encrypted data pre-images.

16. The computer readable storage medium of claim 15 , wherein the pre-image function includes creating a vector that includes the data slice.

17. The computer readable storage medium of claim 16 , wherein the pre-image function further includes creating a decode matrix based on the plurality of storage units, and performing matrix multiplication on the vector and the decode matrix.

18. The computer readable storage medium of claim 15 , wherein generating the encryption function includes applying the key additively to the data pre-image.

19. The computer readable storage medium of claim 15 , wherein the operations further include generating a message authentication code based on the data slice for transmission to the computing device.

20. The computer readable storage medium of claim 15 , wherein the slice pre-image request indicates the data slice, the requesting entity, and the plurality of storage units.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0288 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2018
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 046792/0051 →