IP Library Granted Patent US 11,243,839
Granted Patent B1
US 11,243,839 · App. 16/860,222 · Granted Feb 8, 2022

Audit file generation in a dispersed storage network

Inventors: Jason K. Resch (Chicago, IL); Wesley B. Leggette (Chicago, IL)
Assignee: PURE STORAGE, INC.
G06F11/1076G06F3/06G06F3/0604G06F3/067G06F11/00G06F11/1612G06F15/17331G06F21/6272G06F21/64H04L9/085H04L9/0863H04L9/0869H04L9/0877H04L9/0894H04L9/32H04L9/321H04L9/3263H04L63/123G06F11/1446G06F2211/1028H04L9/00H04L67/1097H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,243,839
App. No.
16/860,222
Granted
Feb 8, 2022
Kind
B1
Abstract

A method for execution by a dispersed storage and task (DST) processing unit includes obtaining audit records for an audit object and determining when the audit object is complete. When the audit object is complete, aggregating the audit records of the audit object within the audit object by generating the audit object to include the audit records; generating identifier (ID) information and generating integrity information. Fields of the audit object are populated with the audit records, the ID information, and the integrity information and a name of the audit object is determined for storage of the audit object and the name of the audit object in a dispersed storage network (DSN).

Claims (32)

1. A method for execution by a storage processing unit that includes a processor, the method comprises:

obtaining audit records, each of the audit records corresponding to an audit message, each of the audit records identifying a storage network entity and each of the audit records including a time and date, and at least one type code selected from a plurality of type codes, wherein the plurality of type codes include a storage access event type code and an authentication audit type code;

generating an audit file that include the audit records, system ID information, and integrity information; and

facilitating storage of the audit file in a storage network utilizing a corresponding name of the audit file.

2. The method of claim 1 , wherein the name of the audit file is determined based on a virtual storage network address associated with accessing the audit file when stored as a plurality of audit file slices in the storage network.

3. The method of claim 1 , wherein the corresponding name of the audit file includes at least one of: a text string name or a sequence number or a timestamp when created or a timestamp associated with when the audit file may be deleted.

4. The method of claim 1 , wherein the corresponding name of the audit file includes at least one of: a timestamp when created or a timestamp associated with when the audit file may be deleted.

5. The method of claim 1 , wherein the integrity information is generated based on at least one of: utilizing an ID associated with the storage processing unit, querying another device of the storage network for the ID information or receiving the ID information.

6. The method of claim 1 , wherein the integrity information is generated based on at least one of obtaining a certificate, generating a signature of the certificate, or calculating a hash of the audit file.

7. The method of claim 1 , wherein facilitating storage of the audit file utilizing the corresponding name of the audit file includes at least one of: sending the audit file and the name of the audit file to the storage network for storage or storing the audit file and the name of the audit file in the storage network.

8. A processing system of a storage network comprises:

at least one processor;

a memory that stores operational instructions, that when executed by the at least one processor cause the processing system to perform operations that include:

obtaining audit records, each of the audit records corresponding to an audit message, each of the audit records identifying a storage network entity and each of the audit records including a time and date, and at least one type code selected from a plurality of type codes, wherein the plurality of type codes include a storage access event type code and an authentication audit type code;

generating an audit file that include the audit records, system ID information, and integrity information; and

facilitating storage of the audit file in a storage network utilizing a corresponding name of the audit file.

9. The processing system of claim 8 , wherein the name of the audit file is determined based on a virtual storage network address associated with accessing the audit file when stored as a plurality of audit file slices in the storage network.

10. The processing system of claim 8 , wherein the corresponding name of the audit file includes at least one of: a text string name or a sequence number or a timestamp when created or a timestamp associated with when the audit file may be deleted.

11. The processing system of claim 8 , wherein the corresponding name of the audit file includes at least one of: a timestamp when created or a timestamp associated with when the audit file may be deleted.

12. The processing system of claim 8 , wherein the integrity information is generated based on at least one of: utilizing an ID associated with the processing system, querying another device of the storage network for the ID information or receiving the ID information.

13. The processing system of claim 8 , wherein the integrity information is generated based on at least one of obtaining a certificate, generating a signature of the certificate, or calculating a hash of the audit file.

14. The processing system of claim 8 , wherein facilitating storage of the audit file utilizing the corresponding name of the audit file includes at least one of: sending the audit file and the name of the audit file to the storage network for storage or storing the audit file and the name of the audit file in the storage network.

15. A non-transitory computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by a processing system of a storage network that includes a processor and a memory, causes the processing system to perform operations that include:

obtaining audit records, each of the audit records corresponding to an audit message, each of the audit records identifying a storage network entity and each of the audit records including a time and date, and at least one type code selected from a plurality of type codes, wherein the plurality of type codes include a storage access event type code and an authentication audit type code;

generating an audit file that include the audit records, system ID information, and integrity information; and

facilitating storage of the audit file in a storage network utilizing a corresponding name of the audit file.

16. The non-transitory computer readable storage medium of claim 15 , wherein the name of the audit file is determined based on a virtual storage network address associated with accessing the audit file when stored as a plurality of audit file slices in the storage network.

17. The non-transitory computer readable storage medium of claim 15 , wherein the corresponding name of the audit file includes at least one of: a text string name or a sequence number or a timestamp when created or a timestamp associated with when the audit file may be deleted.

18. The non-transitory computer readable storage medium of claim 15 , wherein the corresponding name of the audit file includes at least one of: a timestamp when created or a timestamp associated with when the audit file may be deleted.

19. The non-transitory computer readable storage medium of claim 15 , wherein the integrity information is generated based on at least one of: utilizing an ID associated with the processing system, querying another device of the storage network for the ID information or receiving the ID information.

20. The non-transitory computer readable storage medium of claim 15 , wherein the integrity information is generated based on at least one of obtaining a certificate, generating a signature of the certificate, or calculating a hash of the audit file.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2020
From: RESCH, JASON K.; LEGGETTE, WESLEY B.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 052533/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052533/0766 →
Continuity (5)
Continuation 16050920 · Jul 31, 2018
Continuation 15217585 · Jul 22, 2016
Continuation 14954527 · Nov 30, 2015
Division 13587277 · Aug 16, 2012
Provisional Application 61524521 · Aug 17, 2011