IP Library Granted Patent US 10,505,947
Granted Patent B2
US 10,505,947 · App. 16/128,941 · Granted Dec 10, 2019

Policy-based access in a dispersed storage network

Inventors: Gary W. Grube (Barrington Hills, IL); Jason K. Resch (Chicago, IL)
Assignee: PURE STORAGE, INC.
H04L63/108G06F11/00G06F11/1076G06F16/182G06F21/60G06F21/62H04L29/08549H04L67/1097G06F2211/1028G06F2221/2137G06F2221/2141H04L2012/6467
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,947
App. No.
16/128,941
Granted
Dec 10, 2019
Kind
B2
Abstract

A method for execution by a computing device begins by receiving from a requester a read request regarding a set of encoded data slices stored in a set of storage units. The method continues by obtaining an access policy for the read request that includes time varying availability patterns for the set of storage units. The method continues by retrieving from a first group of storage units, during a first time varying availability pattern, first encoded data slices of the set of encoded data slices. The method continues by retrieving from a second group of storage units, during a second time varying availability pattern, second encoded data slices of the set of encoded data slices. The method continues by determining whether the decode threshold number of encoded data slices has been retrieved. When yes, the method continues by decoding the encoded data slices to recover the data segment.

Claims (45)

1. A method comprises:

receiving from a requester, by a computing device of a dispersed storage network (DSN), a read request regarding a set of encoded data slices stored in a set of storage units of the DSN, wherein a data segment of data is dispersed storage error encoded to produce the set of encoded data slices;

obtaining, by the computing device, an access policy for the read request, wherein the access policy includes time varying availability patterns for the set of storage units, wherein less than a decode threshold number of storage units of the set of storage units are available for read requests during any one time varying availability pattern of the time varying availability patterns;

retrieving from a first group of storage units of the set of storage units, by the computing device and during a first time varying availability pattern of the time varying availability patterns, first encoded data slices of the set of encoded data slices available in the first time varying availability pattern;

retrieving from a second group of storage units the set of storage units, by the computing device and during a second time varying availability pattern of the time varying availability patterns, second encoded data slices of the set of encoded data slices available in the second time varying availability pattern;

determining, by the computing device based on a number of the first and second encoded data slices retrieved from the first and second groups of storage units, whether the decode threshold number of encoded data slices of the set of encoded data slices has been retrieved; and

when the decode threshold number of encoded data slices has been retrieved:

decoding, by the computing device, the decode threshold number of encoded data slices to recover the data segment.

2. The method of claim 1 further comprises:

when the decode threshold number of encoded data slices has not been retrieved, continuing the retrieving in accordance with the time varying availability patterns by:

retrieving from a third group of storage units of the set of storage units, by the computing device and during a third time varying availability pattern of the time varying availability patterns, third encoded data slices of the set of encoded data slices.

3. The method of claim 2 further comprises:

determining, by the computing device based on a second number of the first, second and third encoded data slices retrieved from the first, second, and third groups of storage units, whether the decode threshold number of the encoded data slices has been retrieved; and

when the decode threshold number of encoded data slices has been retrieved:

decoding, by the computing device, the first, second and third encoded data slices to recover the data segment.

4. The method of claim 1 , wherein the read request includes one or more of: a requester identifier (ID), a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

5. The method of claim 1 , wherein the obtaining the access policy for the read request includes obtaining one or more of: a previously received access policy, a requester ID, a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

6. The method of claim 1 , wherein the obtaining the access policy to apply to the read request is based on a stored access policy associated with at least one slice name of the set of encoded data slices.

7. The method of claim 1 further comprises:

sending an unavailable message to the requester when the set of encoded data slices is unable to be retrieved after a number of time varying availability patterns.

8. The method of claim 1 , wherein the requester is at least one of: a user device, a dispersed storage (DS) processing unit, a storage integrity processing unit, and a managing unit.

9. A computing device a dispersed storage network (DSN) comprises:

an interface;

a memory; and

a processing module operably coupled to the memory and the interface, wherein the processing module is operable to:

receive from a requester, via the interface, a read request regarding a set of encoded data slices stored in a set of storage units of the DSN, wherein a data segment of data is dispersed storage error encoded to produce the set of encoded data slices;

obtain an access policy for the read request, wherein the access policy includes time varying availability patterns for the set of storage units, wherein less than a decode threshold number of storage units of the set of storage units are available for read requests during any one time varying availability pattern of the time varying availability patterns;

retrieve from a first group of storage units of the set of storage units, during a first time varying availability pattern of the time varying availability patterns, first encoded data slices of the set of encoded data slices available in the first time varying availability pattern;

retrieve from a second group of storage units the set of storage units, during a second time varying availability pattern of the time varying availability patterns, second encoded data slices of the set of encoded data slices available in the second time varying availability pattern;

determine, based on a number of the first and second encoded data slices retrieved from the first and second groups of storage units, whether the decode threshold number of encoded data slices of the set of encoded data slices has been retrieved; and

when the decode threshold number of encoded data slices has been retrieved:

decode the decode threshold number of encoded data slices to recover the data segment.

10. The computing device of claim 9 , wherein the processing module is further operable to:

when the decode threshold number of encoded data slices has not been retrieved, continue the retrieving in accordance with the time varying availability patterns by:

retrieving from a third group of storage units of the set of storage units, by the computing device and during a third time varying availability pattern of the time varying availability patterns, third encoded data slices of the set of encoded data slices.

11. The computing device of claim 10 , wherein the processing module is further operable to:

determine, based on a second number of the first, second and third encoded data slices retrieved from the first, second, and third groups of storage units, whether the decode threshold number of the encoded data slices has been retrieved; and

when the decode threshold number of encoded data slices has been retrieved:

decode the first, second and third encoded data slices to recover the data segment.

12. The computing device of claim 9 , wherein the read request includes one or more of: a requester identifier (ID), a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

13. The computing device of claim 9 , wherein the processing module is operable to obtain the access policy for the read request by obtaining one or more of: a previously received access policy, a requester ID, a command, an access policy update, a data object ID, a source name, a data type, a data size indicator, a priority indicator, a security indicator, or a performance indicator.

14. The computing device of claim 9 , wherein the processing module is operable to obtain the access policy to apply to the read request by obtaining a stored access policy associated with at least one slice name of the set of encoded data slices.

15. The computing device of claim 9 , wherein the processing module is further operable to:

send, via the interface, an unavailable message to the requester when the set of encoded data slices is unable to be retrieved after a number of time varying availability patterns.

16. The computing device of claim 9 , wherein the requester is at least one of: a user device, a dispersed storage (DS) processing unit, a storage integrity processing unit, and a managing unit.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DELETE 15/174/279 AND 15/174/596 PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 49555 FRAME: 530. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 7, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 051495/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049555/0530 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2018
From: GRUBE, GARY W.; RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 046852/0208 →
Cited By (1)
US 12,481,557